From f4993218ce5204a3e8b4527e40f71d5fdc5d1de9 Mon Sep 17 00:00:00 2001 From: Einat Vinouze Date: Tue, 28 Jan 2020 17:29:10 +0200 Subject: RoleValidatorByOwningEntity permits by PermissionPropertiesOwningEntity PermissionPropertiesOwningEntity is sharing a parent interface with PermissionPropertiesServiceType: WithPermissionProperties. Issue-ID: VID-758 Change-Id: I90c04cb8d4331d68329f3a12329244f09c6bc184 Signed-off-by: Einat Vinouze Signed-off-by: Ittay Stern --- .../org/onap/vid/controller/AsyncInstantiationController.java | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'vid-app-common/src/main/java/org/onap/vid/controller/AsyncInstantiationController.java') diff --git a/vid-app-common/src/main/java/org/onap/vid/controller/AsyncInstantiationController.java b/vid-app-common/src/main/java/org/onap/vid/controller/AsyncInstantiationController.java index 4b03ea4d9..ce8bbb50c 100644 --- a/vid-app-common/src/main/java/org/onap/vid/controller/AsyncInstantiationController.java +++ b/vid-app-common/src/main/java/org/onap/vid/controller/AsyncInstantiationController.java @@ -33,7 +33,7 @@ import org.onap.vid.model.ServiceInfo; import org.onap.vid.model.serviceInstantiation.ServiceInstantiation; import org.onap.vid.mso.MsoResponseWrapper2; import org.onap.vid.properties.Features; -import org.onap.vid.roles.PermissionProperties; +import org.onap.vid.roles.AllPermissionProperties; import org.onap.vid.roles.RoleProvider; import org.onap.vid.roles.RoleValidator; import org.onap.vid.services.AsyncInstantiationBusinessLogic; @@ -169,7 +169,11 @@ public class AsyncInstantiationController extends VidRestrictedBaseController { private void throwExceptionIfAccessDenied(ServiceInstantiation request, HttpServletRequest httpServletRequest, String userId) { if (featureManager.isActive(Features.FLAG_1906_INSTANTIATION_API_USER_VALIDATION)) { RoleValidator roleValidator = roleProvider.getUserRolesValidator(httpServletRequest); - if (!roleValidator.isServicePermitted(new PermissionProperties(request.getGlobalSubscriberId(), request.getSubscriptionServiceType()))) { + if (!roleValidator.isServicePermitted(new AllPermissionProperties( + request.getGlobalSubscriberId(), + request.getSubscriptionServiceType(), + request.getOwningEntityId())) + ) { throw new AccessDeniedException(String.format("User %s is not allowed to make this request", userId)); } } -- cgit 1.2.3-korg