|
| 1 | +/* |
| 2 | + * Licensed to the Apache Software Foundation (ASF) under one or more |
| 3 | + * contributor license agreements. See the NOTICE file distributed with |
| 4 | + * this work for additional information regarding copyright ownership. |
| 5 | + * The ASF licenses this file to You under the Apache License, Version 2.0 |
| 6 | + * (the "License"); you may not use this file except in compliance with |
| 7 | + * the License. You may obtain a copy of the License at |
| 8 | + * |
| 9 | + * http://www.apache.org/licenses/LICENSE-2.0 |
| 10 | + * |
| 11 | + * Unless required by applicable law or agreed to in writing, software |
| 12 | + * distributed under the License is distributed on an "AS IS" BASIS, |
| 13 | + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 14 | + * See the License for the specific language governing permissions and |
| 15 | + * limitations under the License. |
| 16 | + */ |
| 17 | + |
| 18 | +package org.apache.uniffle.coordinator.access.checker; |
| 19 | + |
| 20 | +import java.util.regex.Matcher; |
| 21 | +import java.util.regex.Pattern; |
| 22 | + |
| 23 | +import org.slf4j.Logger; |
| 24 | +import org.slf4j.LoggerFactory; |
| 25 | + |
| 26 | +import org.apache.uniffle.common.util.Constants; |
| 27 | +import org.apache.uniffle.coordinator.AccessManager; |
| 28 | +import org.apache.uniffle.coordinator.CoordinatorConf; |
| 29 | +import org.apache.uniffle.coordinator.access.AccessCheckResult; |
| 30 | +import org.apache.uniffle.coordinator.access.AccessInfo; |
| 31 | +import org.apache.uniffle.coordinator.metric.CoordinatorMetrics; |
| 32 | + |
| 33 | +/** |
| 34 | + * AccessBannedChecker maintain a list of banned id and update it periodically, it checks the banned |
| 35 | + * id in the access request and reject if the id is in the banned list. |
| 36 | + */ |
| 37 | +public class AccessBannedChecker extends AbstractAccessChecker { |
| 38 | + private static final Logger LOG = LoggerFactory.getLogger(AccessBannedChecker.class); |
| 39 | + private final AccessManager accessManager; |
| 40 | + private final String bannedIdProviderKey; |
| 41 | + private final Pattern bannedIdProviderPattern; |
| 42 | + |
| 43 | + public AccessBannedChecker(AccessManager accessManager) throws Exception { |
| 44 | + super(accessManager); |
| 45 | + this.accessManager = accessManager; |
| 46 | + CoordinatorConf conf = accessManager.getCoordinatorConf(); |
| 47 | + bannedIdProviderKey = conf.get(CoordinatorConf.COORDINATOR_ACCESS_BANNED_ID_PROVIDER); |
| 48 | + String bannedIdProviderRegex = |
| 49 | + conf.get(CoordinatorConf.COORDINATOR_ACCESS_BANNED_ID_PROVIDER_REG_PATTERN); |
| 50 | + bannedIdProviderPattern = Pattern.compile(bannedIdProviderRegex); |
| 51 | + |
| 52 | + LOG.info( |
| 53 | + "Construct BannedChecker. BannedIdProviderKey is {}, pattern is {}", |
| 54 | + bannedIdProviderKey, |
| 55 | + bannedIdProviderRegex); |
| 56 | + } |
| 57 | + |
| 58 | + @Override |
| 59 | + public AccessCheckResult check(AccessInfo accessInfo) { |
| 60 | + if (accessInfo.getExtraProperties() != null |
| 61 | + && accessInfo.getExtraProperties().containsKey(bannedIdProviderKey)) { |
| 62 | + String bannedIdPropertyValue = accessInfo.getExtraProperties().get(bannedIdProviderKey); |
| 63 | + Matcher matcher = bannedIdProviderPattern.matcher(bannedIdPropertyValue); |
| 64 | + if (matcher.find()) { |
| 65 | + String bannedId = matcher.group(1); |
| 66 | + if (accessManager.getBannedManager() != null |
| 67 | + && accessManager.getBannedManager().checkBanned(bannedId)) { |
| 68 | + String msg = String.format("Denied by BannedChecker, accessInfo[%s].", accessInfo); |
| 69 | + if (LOG.isDebugEnabled()) { |
| 70 | + LOG.debug("BannedIdPropertyValue is {}, {}", bannedIdPropertyValue, msg); |
| 71 | + } |
| 72 | + CoordinatorMetrics.counterTotalBannedDeniedRequest.inc(); |
| 73 | + return new AccessCheckResult(false, msg); |
| 74 | + } |
| 75 | + } |
| 76 | + } |
| 77 | + |
| 78 | + return new AccessCheckResult(true, Constants.COMMON_SUCCESS_MESSAGE); |
| 79 | + } |
| 80 | + |
| 81 | + @Override |
| 82 | + public void close() {} |
| 83 | +} |
0 commit comments