View Javadoc
1   /*
2    * Copyright 2012-2021 CodeLibs Project and the Others.
3    *
4    * Licensed under the Apache License, Version 2.0 (the "License");
5    * you may not use this file except in compliance with the License.
6    * You may obtain a copy of the License at
7    *
8    *     http://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS,
12   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
13   * either express or implied. See the License for the specific language
14   * governing permissions and limitations under the License.
15   */
16  package org.codelibs.fess.app.web.api.admin;
17  
18  import org.apache.logging.log4j.LogManager;
19  import org.apache.logging.log4j.Logger;
20  import org.codelibs.fess.app.web.api.FessApiAction;
21  import org.codelibs.fess.exception.InvalidAccessTokenException;
22  
23  public abstract class FessApiAdminAction extends FessApiAction {
24  
25      private static final Logger logger = LogManager.getLogger(FessApiAdminAction.class);
26  
27      @Override
28      protected boolean isAccessAllowed() {
29          try {
30              return accessTokenService.getPermissions(request).map(permissions -> fessConfig.isApiAdminAccessAllowed(permissions))
31                      .orElse(false);
32          } catch (final InvalidAccessTokenException e) {
33              if (logger.isDebugEnabled()) {
34                  logger.debug("Invalid access token.", e);
35              }
36              return false;
37          }
38      }
39  }