@InterfaceAudience.Private public class DefaultVisibilityLabelServiceImpl extends Object implements VisibilityLabelService
Constructor and Description |
---|
DefaultVisibilityLabelServiceImpl() |
Modifier and Type | Method and Description |
---|---|
OperationStatus[] |
addLabels(List<byte[]> labels)
Adds the set of labels into the system.
|
protected void |
addSystemLabel(HRegion region,
Map<String,Integer> labels,
Map<String,List<Integer>> userAuths) |
OperationStatus[] |
clearAuths(byte[] user,
List<byte[]> authLabels)
Removes given labels from user's globally authorized list of labels.
|
List<Tag> |
createVisibilityExpTags(String visExpression,
boolean withSerializationFormat,
boolean checkAuths)
Creates tags corresponding to given visibility expression.
|
protected Pair<Map<String,Integer>,Map<String,List<Integer>>> |
extractLabelsAndAuths(List<List<Cell>> labelDetails) |
List<String> |
getAuths(byte[] user,
boolean systemCall) |
org.apache.hadoop.conf.Configuration |
getConf() |
protected List<List<Cell>> |
getExistingLabelsWithAuths() |
protected List<String> |
getSystemAndSuperUsers() |
VisibilityExpEvaluator |
getVisibilityExpEvaluator(Authorizations authorizations)
Creates VisibilityExpEvaluator corresponding to given Authorizations.
|
boolean |
havingSystemAuth(byte[] user)
System checks for user auth during admin operations.
|
void |
init(RegionCoprocessorEnvironment e)
System calls this after opening of regions.
|
protected boolean |
isReadFromSuperUser() |
boolean |
matchVisibility(List<Tag> putVisTags,
Byte putTagsFormat,
List<Tag> deleteVisTags,
Byte deleteTagsFormat)
System uses this for deciding whether a Cell can be deleted by matching visibility expression
in Delete mutation and the cell in consideration.
|
OperationStatus[] |
setAuths(byte[] user,
List<byte[]> authLabels)
Sets given labels globally authorized for the user.
|
void |
setConf(org.apache.hadoop.conf.Configuration conf) |
protected void |
updateZk(boolean labelAddition) |
public void setConf(org.apache.hadoop.conf.Configuration conf)
setConf
in interface org.apache.hadoop.conf.Configurable
public org.apache.hadoop.conf.Configuration getConf()
getConf
in interface org.apache.hadoop.conf.Configurable
public void init(RegionCoprocessorEnvironment e) throws IOException
VisibilityLabelService
init
in interface VisibilityLabelService
e
- the region coprocessor envIOException
protected List<List<Cell>> getExistingLabelsWithAuths() throws IOException
IOException
protected Pair<Map<String,Integer>,Map<String,List<Integer>>> extractLabelsAndAuths(List<List<Cell>> labelDetails)
protected void addSystemLabel(HRegion region, Map<String,Integer> labels, Map<String,List<Integer>> userAuths) throws IOException
IOException
protected List<String> getSystemAndSuperUsers() throws IOException
IOException
public OperationStatus[] addLabels(List<byte[]> labels) throws IOException
VisibilityLabelService
addLabels
in interface VisibilityLabelService
labels
- Labels to add to the system.IOException
public OperationStatus[] setAuths(byte[] user, List<byte[]> authLabels) throws IOException
VisibilityLabelService
setAuths
in interface VisibilityLabelService
user
- The authorizing userauthLabels
- Labels which are getting authorized for the userIOException
public OperationStatus[] clearAuths(byte[] user, List<byte[]> authLabels) throws IOException
VisibilityLabelService
clearAuths
in interface VisibilityLabelService
user
- The user whose authorization to be removedauthLabels
- Labels which are getting removed from authorization setIOException
public List<String> getAuths(byte[] user, boolean systemCall) throws IOException
getAuths
in interface VisibilityLabelService
user
- Name of the user whose authorization to be retrievedsystemCall
- Whether a system or user originated call.IOException
public List<Tag> createVisibilityExpTags(String visExpression, boolean withSerializationFormat, boolean checkAuths) throws IOException
VisibilityLabelService
createVisibilityExpTags
in interface VisibilityLabelService
visExpression
- The Expression for which corresponding Tags to be created.withSerializationFormat
- specifies whether a tag, denoting the serialization version
of the tags, to be added in the list. When this is true make sure to add the
serialization format Tag also. The format tag value should be byte type.checkAuths
- denotes whether to check individual labels in visExpression against user's
global auth label.IOException
protected void updateZk(boolean labelAddition) throws IOException
IOException
public VisibilityExpEvaluator getVisibilityExpEvaluator(Authorizations authorizations) throws IOException
VisibilityLabelService
getVisibilityExpEvaluator
in interface VisibilityLabelService
authorizations
- Authorizations for the read requestIOException
protected boolean isReadFromSuperUser() throws IOException
IOException
public boolean havingSystemAuth(byte[] user) throws IOException
VisibilityLabelService
havingSystemAuth
in interface VisibilityLabelService
user
- User for whom system auth check to be done.IOException
public boolean matchVisibility(List<Tag> putVisTags, Byte putTagsFormat, List<Tag> deleteVisTags, Byte deleteTagsFormat) throws IOException
VisibilityLabelService
matchVisibility
in interface VisibilityLabelService
putVisTags
- The visibility tags present in the Put mutationputTagsFormat
- The serialization format for the Put visibility tags. A null
value for
this format means the tags are written with unsorted label ordinalsdeleteVisTags
- - The visibility tags in the delete mutation (the specified Cell Visibility)deleteTagsFormat
- The serialization format for the Delete visibility tags. A null
value for
this format means the tags are written with unsorted label ordinalsIOException
VisibilityConstants.SORTED_ORDINAL_SERIALIZATION_FORMAT
Copyright © 2014 The Apache Software Foundation. All rights reserved.