Class ImpersonationAuthorizer
- java.lang.Object
-
- org.apache.storm.security.auth.authorizer.ImpersonationAuthorizer
-
- All Implemented Interfaces:
IAuthorizer
public class ImpersonationAuthorizer extends Object implements IAuthorizer
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description protected static class
ImpersonationAuthorizer.ImpersonationACL
-
Field Summary
Fields Modifier and Type Field Description protected IGroupMappingServiceProvider
groupMappingProvider
protected IPrincipalToLocal
ptol
protected Map<String,ImpersonationAuthorizer.ImpersonationACL>
userImpersonationACL
protected static String
WILD_CARD
-
Constructor Summary
Constructors Constructor Description ImpersonationAuthorizer()
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description boolean
permit(ReqContext context, String operation, Map<String,Object> topoConf)
permit() method is invoked for each incoming Thrift request.void
prepare(Map<String,Object> conf)
Invoked once immediately after construction.
-
-
-
Field Detail
-
WILD_CARD
protected static final String WILD_CARD
- See Also:
- Constant Field Values
-
userImpersonationACL
protected Map<String,ImpersonationAuthorizer.ImpersonationACL> userImpersonationACL
-
ptol
protected IPrincipalToLocal ptol
-
groupMappingProvider
protected IGroupMappingServiceProvider groupMappingProvider
-
-
Method Detail
-
prepare
public void prepare(Map<String,Object> conf)
Description copied from interface:IAuthorizer
Invoked once immediately after construction.- Specified by:
prepare
in interfaceIAuthorizer
- Parameters:
conf
- Storm cluster configuration
-
permit
public boolean permit(ReqContext context, String operation, Map<String,Object> topoConf)
Description copied from interface:IAuthorizer
permit() method is invoked for each incoming Thrift request.- Specified by:
permit
in interfaceIAuthorizer
- Parameters:
context
- request context includes info aboutoperation
- operation nametopoConf
- configuration of targeted topology- Returns:
- true if the request is authorized, false if reject
-
-