MySQL 9.3.0
Source Code Documentation
www_authentication_handler.h
Go to the documentation of this file.
1/*
2 Copyright (c) 2021, 2025, Oracle and/or its affiliates.
3
4 This program is free software; you can redistribute it and/or modify
5 it under the terms of the GNU General Public License, version 2.0,
6 as published by the Free Software Foundation.
7
8 This program is designed to work with certain software (including
9 but not limited to OpenSSL) that is licensed under separate terms,
10 as designated in a particular file or component or in included license
11 documentation. The authors of MySQL hereby grant you an additional
12 permission to link the program and your derivative works with the
13 separately licensed software that they have either included with
14 the program or referenced in the documentation.
15
16 This program is distributed in the hope that it will be useful,
17 but WITHOUT ANY WARRANTY; without even the implied warranty of
18 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 GNU General Public License for more details.
20
21 You should have received a copy of the GNU General Public License
22 along with this program; if not, write to the Free Software
23 Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
24 */
25
26#ifndef ROUTER_SRC_REST_MRS_SRC_MRS_AUTHENTICATION_WWW_AUTHENTICATION_HANDLER_H_
27#define ROUTER_SRC_REST_MRS_SRC_MRS_AUTHENTICATION_WWW_AUTHENTICATION_HANDLER_H_
28
30
31#include <optional>
32
36
38#include "secure_string.h" // NOLINT(build/include_subdir)
39
40namespace mrs {
41namespace authentication {
42
44 protected:
49
52
53 struct Credentials {
54 std::string user;
56 };
57
58 protected:
59 bool validate_redirection_url(const std::optional<std::string> &url);
60 std::optional<Credentials> authorize_method_get(RequestContext &ctxt,
61 Session *session);
62 std::optional<Credentials> authorize_method_post(RequestContext &ctxt,
63 Session *session);
64
65 virtual bool verify_credential(const Credentials &credentials,
66 SqlSessionCached *out_cache,
67 AuthUser *out_user) = 0;
68
69 void throw_add_www_authenticate(const char *schema);
70
71 bool redirects(RequestContext &ctxt) const override;
72 bool authorize(RequestContext &ctxt, const SessionPtr &session,
73 AuthUser *out_user) override;
74 std::optional<std::string> get_session_id_from_request_data(
75 RequestContext &) override;
76
77 const AuthApp &get_entry() const override;
78
79 public:
81 : entry_{entry},
82 um_{entry_.limit_to_registered_users, entry_.default_role_id, qf} {}
83 UserManager &get_user_manager() override { return um_; }
84
85 constexpr static char kAuthorization[] = "Authorization";
86 constexpr static char kWwwAuthenticate[] = "WWW-Authenticate";
87};
88
89} // namespace authentication
90} // namespace mrs
91
92#endif // ROUTER_SRC_REST_MRS_SRC_MRS_AUTHENTICATION_WWW_AUTHENTICATION_HANDLER_H_
Definition: cache_manager.h:41
Definition: www_authentication_handler.h:43
UserManager & get_user_manager() override
Definition: www_authentication_handler.h:83
std::optional< Credentials > authorize_method_post(RequestContext &ctxt, Session *session)
Definition: www_authentication_handler.cc:249
AuthApp entry_
Definition: www_authentication_handler.h:50
constexpr static char kAuthorization[]
Definition: www_authentication_handler.h:85
virtual bool verify_credential(const Credentials &credentials, SqlSessionCached *out_cache, AuthUser *out_user)=0
const AuthApp & get_entry() const override
Definition: www_authentication_handler.cc:261
WwwAuthenticationHandler(const AuthApp &entry, QueryFactory *qf)
Definition: www_authentication_handler.h:80
std::optional< Credentials > authorize_method_get(RequestContext &ctxt, Session *session)
Definition: www_authentication_handler.cc:180
bool redirects(RequestContext &ctxt) const override
Definition: www_authentication_handler.cc:89
bool validate_redirection_url(const std::optional< std::string > &url)
Definition: www_authentication_handler.cc:139
std::optional< std::string > get_session_id_from_request_data(RequestContext &) override
Definition: www_authentication_handler.cc:126
void throw_add_www_authenticate(const char *schema)
Definition: www_authentication_handler.cc:263
bool authorize(RequestContext &ctxt, const SessionPtr &session, AuthUser *out_user) override
Definition: www_authentication_handler.cc:95
constexpr static char kWwwAuthenticate[]
Definition: www_authentication_handler.h:86
UserManager um_
Definition: www_authentication_handler.h:51
Definition: session_manager.h:64
Definition: session_manager.h:48
Definition: authorize_handler.h:53
mrs::database::entry::AuthUser AuthUser
Definition: authorize_handler.h:56
http::SessionManager::SessionPtr SessionPtr
Definition: authorize_handler.h:60
mrs::database::entry::AuthApp AuthApp
Definition: authorize_handler.h:57
Definition: query_factory.h:55
Definition: user_manager.h:41
Null-terminated string which is securely wiped on destruction.
Definition: secure_string.h:59
AuthorizeManager::Session Session
Definition: authorize_manager.cc:75
Definition: authorize_manager.h:48
Definition: completion_hash.h:35
Definition: www_authentication_handler.h:53
std::string user
Definition: www_authentication_handler.h:54
mysql_harness::SecureString password
Definition: www_authentication_handler.h:55
Definition: request_context.h:47