1   /*
2    * Copyright 2018 LINE Corporation
3    *
4    * LINE Corporation licenses this file to you under the Apache License,
5    * version 2.0 (the "License"); you may not use this file except in compliance
6    * with the License. You may obtain a copy of the License at:
7    *
8    *   https://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12   * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13   * License for the specific language governing permissions and limitations
14   * under the License.
15   */
16  
17  package com.linecorp.centraldogma.server.internal.api.auth;
18  
19  import java.util.function.Function;
20  
21  import com.linecorp.armeria.common.HttpRequest;
22  import com.linecorp.armeria.common.HttpResponse;
23  import com.linecorp.armeria.common.HttpStatus;
24  import com.linecorp.armeria.server.HttpService;
25  import com.linecorp.armeria.server.ServiceRequestContext;
26  import com.linecorp.armeria.server.SimpleDecoratingHttpService;
27  import com.linecorp.armeria.server.annotation.Decorator;
28  import com.linecorp.armeria.server.annotation.DecoratorFactoryFunction;
29  import com.linecorp.centraldogma.server.internal.admin.auth.AuthUtil;
30  import com.linecorp.centraldogma.server.internal.api.HttpApiUtil;
31  import com.linecorp.centraldogma.server.metadata.User;
32  
33  /**
34   * A {@link Decorator} to allow a request from an administrator only.
35   */
36  public final class RequiresAdministratorDecorator extends SimpleDecoratingHttpService {
37  
38      RequiresAdministratorDecorator(HttpService delegate) {
39          super(delegate);
40      }
41  
42      @Override
43      public HttpResponse serve(ServiceRequestContext ctx, HttpRequest req) throws Exception {
44          final User user = AuthUtil.currentUser(ctx);
45          if (user.isAdmin()) {
46              return unwrap().serve(ctx, req);
47          }
48          return HttpApiUtil.throwResponse(
49                  ctx, HttpStatus.FORBIDDEN,
50                  "You must be an administrator to perform this operation.");
51      }
52  
53      /**
54       * A {@link DecoratorFactoryFunction} which creates a {@link RequiresAdministratorDecorator}.
55       */
56      public static final class RequiresAdministratorDecoratorFactory
57              implements DecoratorFactoryFunction<RequiresAdministrator> {
58          @Override
59          public Function<? super HttpService, ? extends HttpService>
60          newDecorator(RequiresAdministrator parameter) {
61              return RequiresAdministratorDecorator::new;
62          }
63      }
64  }