Class AuthorizationBroker

java.lang.Object
org.apache.activemq.broker.BrokerFilter
org.apache.activemq.security.AuthorizationBroker
All Implemented Interfaces:
Broker, Region, SecurityAdminMBean, org.apache.activemq.Service

public class AuthorizationBroker extends BrokerFilter implements SecurityAdminMBean
Verifies if a authenticated user can do an operation against the broker using an authorization map.
  • Constructor Details

  • Method Details

    • getAuthorizationMap

      public AuthorizationMap getAuthorizationMap()
    • setAuthorizationMap

      public void setAuthorizationMap(AuthorizationMap map)
    • checkSecurityContext

      protected SecurityContext checkSecurityContext(ConnectionContext context) throws SecurityException
      Throws:
      SecurityException
    • checkDestinationAdminAdd

      protected boolean checkDestinationAdminAdd(SecurityContext securityContext, org.apache.activemq.command.ActiveMQDestination destination)
    • checkDestinationAdminRemove

      protected boolean checkDestinationAdminRemove(SecurityContext securityContext, org.apache.activemq.command.ActiveMQDestination destination)
    • checkDestinationAdmin

      protected boolean checkDestinationAdmin(SecurityContext securityContext, org.apache.activemq.command.ActiveMQDestination destination)
    • addDestinationInfo

      public void addDestinationInfo(ConnectionContext context, org.apache.activemq.command.DestinationInfo info) throws Exception
      Description copied from interface: Broker
      Add and process a DestinationInfo object
      Specified by:
      addDestinationInfo in interface Broker
      Overrides:
      addDestinationInfo in class BrokerFilter
      Parameters:
      context - connection context
      info - destination info
      Throws:
      Exception - TODO
    • addDestination

      public Destination addDestination(ConnectionContext context, org.apache.activemq.command.ActiveMQDestination destination, boolean create) throws Exception
      Description copied from interface: Region
      Used to create a destination. Usually, this method is invoked as a side-effect of sending a message to a destination that does not exist yet.
      Specified by:
      addDestination in interface Region
      Overrides:
      addDestination in class BrokerFilter
      Parameters:
      context -
      destination - the destination to create.
      create -
      Returns:
      TODO
      Throws:
      Exception - TODO
    • removeDestination

      public void removeDestination(ConnectionContext context, org.apache.activemq.command.ActiveMQDestination destination, long timeout) throws Exception
      Description copied from interface: Region
      Used to destroy a destination. This should try to quiesce use of the destination up to the timeout allotted time before removing the destination. This will remove all persistent messages associated with the destination.
      Specified by:
      removeDestination in interface Region
      Overrides:
      removeDestination in class BrokerFilter
      Parameters:
      context - the environment the operation is being executed under.
      destination - what is being removed from the broker.
      timeout - the max amount of time to wait for the destination to quiesce
      Throws:
      Exception - TODO
    • removeDestinationInfo

      public void removeDestinationInfo(ConnectionContext context, org.apache.activemq.command.DestinationInfo info) throws Exception
      Description copied from interface: Broker
      Remove and process a DestinationInfo object
      Specified by:
      removeDestinationInfo in interface Broker
      Overrides:
      removeDestinationInfo in class BrokerFilter
      Parameters:
      context - connection context
      info - destination info
      Throws:
      Exception - TODO
    • addConsumer

      public Subscription addConsumer(ConnectionContext context, org.apache.activemq.command.ConsumerInfo info) throws Exception
      Description copied from interface: Region
      Adds a consumer.
      Specified by:
      addConsumer in interface Region
      Overrides:
      addConsumer in class BrokerFilter
      Parameters:
      context - the environment the operation is being executed under.
      Returns:
      TODO
      Throws:
      Exception - TODO
    • addProducer

      public void addProducer(ConnectionContext context, org.apache.activemq.command.ProducerInfo info) throws Exception
      Description copied from interface: Broker
      Adds a producer.
      Specified by:
      addProducer in interface Broker
      Specified by:
      addProducer in interface Region
      Overrides:
      addProducer in class BrokerFilter
      Parameters:
      context - the environment the operation is being executed under.
      Throws:
      Exception - TODO
    • send

      public void send(ProducerBrokerExchange producerExchange, org.apache.activemq.command.Message messageSend) throws Exception
      Description copied from interface: Region
      Send a message to the broker to using the specified destination. The destination specified in the message does not need to match the destination the message is sent to. This is handy in case the message is being sent to a dead letter destination.
      Specified by:
      send in interface Region
      Overrides:
      send in class BrokerFilter
      Parameters:
      producerExchange - the environment the operation is being executed under.
      messageSend -
      Throws:
      Exception - TODO
    • getReadACLs

      protected Set<?> getReadACLs(org.apache.activemq.command.ActiveMQDestination destination)
    • getWriteACLs

      protected Set<?> getWriteACLs(org.apache.activemq.command.ActiveMQDestination destination)
    • getAdminACLs

      protected Set<?> getAdminACLs(org.apache.activemq.command.ActiveMQDestination destination)
    • addQueueRole

      public void addQueueRole(String queue, String operation, String role)
      Specified by:
      addQueueRole in interface SecurityAdminMBean
    • addTopicRole

      public void addTopicRole(String topic, String operation, String role)
      Specified by:
      addTopicRole in interface SecurityAdminMBean
    • removeQueueRole

      public void removeQueueRole(String queue, String operation, String role)
      Specified by:
      removeQueueRole in interface SecurityAdminMBean
    • removeTopicRole

      public void removeTopicRole(String topic, String operation, String role)
      Specified by:
      removeTopicRole in interface SecurityAdminMBean
    • addDestinationRole

      public void addDestinationRole(jakarta.jms.Destination destination, String operation, String role)
    • removeDestinationRole

      public void removeDestinationRole(jakarta.jms.Destination destination, String operation, String role)
    • addRole

      public void addRole(String role)
      Specified by:
      addRole in interface SecurityAdminMBean
    • addUserRole

      public void addUserRole(String user, String role)
      Specified by:
      addUserRole in interface SecurityAdminMBean
    • removeRole

      public void removeRole(String role)
      Specified by:
      removeRole in interface SecurityAdminMBean
    • removeUserRole

      public void removeUserRole(String user, String role)
      Specified by:
      removeUserRole in interface SecurityAdminMBean