ClickHouse/src/Access/ExternalAuthenticators.h

63 lines
1.8 KiB
C++
Raw Normal View History

2020-05-27 21:06:33 +00:00
#pragma once
#include <Access/LDAPClient.h>
#include <Access/Credentials.h>
#include <Access/GSSAcceptor.h>
2021-10-02 07:13:14 +00:00
#include <base/types.h>
2020-05-27 21:06:33 +00:00
#include <chrono>
2020-05-27 21:06:33 +00:00
#include <map>
#include <mutex>
#include <optional>
#include <unordered_map>
2020-05-27 21:06:33 +00:00
namespace Poco
{
class Logger;
namespace Util
{
class AbstractConfiguration;
}
}
2020-05-27 21:06:33 +00:00
namespace DB
{
class ExternalAuthenticators
{
public:
void reset();
void setConfiguration(const Poco::Util::AbstractConfiguration & config, Poco::Logger * log);
// The name and readiness of the credentials must be verified before calling these.
bool checkLDAPCredentials(const String & server, const BasicCredentials & credentials,
const LDAPClient::RoleSearchParamsList * role_search_params = nullptr, LDAPClient::SearchResultsList * role_search_results = nullptr) const;
bool checkKerberosCredentials(const String & realm, const GSSAcceptorContext & credentials) const;
GSSAcceptorContext::Params getKerberosParams() const;
private:
struct LDAPCacheEntry
{
2020-12-24 23:46:08 +00:00
std::size_t last_successful_params_hash = 0;
std::chrono::steady_clock::time_point last_successful_authentication_timestamp;
LDAPClient::SearchResultsList last_successful_role_search_results;
};
using LDAPCache = std::unordered_map<String, LDAPCacheEntry>; // user name -> cache entry
using LDAPCaches = std::map<String, LDAPCache>; // server name -> cache
using LDAPParams = std::map<String, LDAPClient::Params>; // server name -> params
2020-05-27 21:06:33 +00:00
mutable std::recursive_mutex mutex;
LDAPParams ldap_client_params_blueprint;
mutable LDAPCaches ldap_caches;
std::optional<GSSAcceptorContext::Params> kerberos_params;
2020-05-27 21:06:33 +00:00
};
void parseLDAPRoleSearchParams(LDAPClient::RoleSearchParams & params, const Poco::Util::AbstractConfiguration & config, const String & prefix);
2020-05-27 21:06:33 +00:00
}