1 /*
2 * Copyright 2012-2025 CodeLibs Project and the Others.
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
13 * either express or implied. See the License for the specific language
14 * governing permissions and limitations under the License.
15 */
16 package org.codelibs.fess.app.web.api.admin;
17
18 import org.apache.logging.log4j.LogManager;
19 import org.apache.logging.log4j.Logger;
20 import org.codelibs.fess.app.web.api.FessApiAction;
21 import org.codelibs.fess.exception.InvalidAccessTokenException;
22
23 /**
24 * Abstract base class for admin API actions in Fess.
25 * This class extends FessApiAction to provide admin-specific functionality
26 * including enhanced access control for administrative operations.
27 *
28 * <p>Admin API actions require special permissions and access tokens
29 * that are validated against the admin role configuration.</p>
30 */
31 public abstract class FessApiAdminAction extends FessApiAction {
32
33 /** Logger instance for this class. */
34 private static final Logger logger = LogManager.getLogger(FessApiAdminAction.class);
35
36 /**
37 * Default constructor.
38 */
39 public FessApiAdminAction() {
40 super();
41 }
42
43 /**
44 * Determines whether the current request is authorized to access admin API endpoints.
45 * This method validates the access token and checks if the associated permissions
46 * allow admin access according to the Fess configuration.
47 *
48 * @return true if admin access is allowed, false otherwise
49 */
50 @Override
51 protected boolean isAccessAllowed() {
52 try {
53 return accessTokenService.getPermissions(request)
54 .map(permissions -> fessConfig.isApiAdminAccessAllowed(permissions))
55 .orElse(false);
56 } catch (final InvalidAccessTokenException e) {
57 if (logger.isDebugEnabled()) {
58 logger.debug("Invalid access token.", e);
59 }
60 return false;
61 }
62 }
63 }