View Javadoc
1   /*
2    * Copyright 2012-2017 CodeLibs Project and the Others.
3    *
4    * Licensed under the Apache License, Version 2.0 (the "License");
5    * you may not use this file except in compliance with the License.
6    * You may obtain a copy of the License at
7    *
8    *     http://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS,
12   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
13   * either express or implied. See the License for the specific language
14   * governing permissions and limitations under the License.
15   */
16  package org.codelibs.fess.app.web.api.admin;
17  
18  import org.codelibs.fess.app.web.api.FessApiAction;
19  import org.codelibs.fess.exception.InvalidAccessTokenException;
20  import org.slf4j.Logger;
21  import org.slf4j.LoggerFactory;
22  
23  public abstract class FessApiAdminAction extends FessApiAction {
24  
25      private static final Logger logger = LoggerFactory.getLogger(FessApiAdminAction.class);
26  
27      @Override
28      protected boolean isAccessAllowed() {
29          try {
30              return accessTokenService.getPermissions(request).map(permissions -> {
31                  return fessConfig.isApiAdminAccessAllowed(permissions);
32              }).orElse(false);
33          } catch (final InvalidAccessTokenException e) {
34              if (logger.isDebugEnabled()) {
35                  logger.debug("Invalid access token.", e);
36              }
37              return false;
38          }
39      }
40  }