Package org.italiangrid.voms.util
Class FilePermissionHelper
java.lang.Object
org.italiangrid.voms.util.FilePermissionHelper
A helper class for performing basic Unix file permission checks.
This class is intended to provide simple permission validation and modification for specific files, such as private keys and proxy certificates. It relies on executing system commands to fetch and update file permissions.
Note: This implementation is a workaround until proper support for POSIX file permissions is available in Java.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic enumEnumeration representing POSIX file permissions. -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe command used to set file permissions on a given filestatic final StringThe command used to retrieve file permissions for a given filestatic final EnumSet<FilePermissionHelper.PosixFilePermission> Required file permissions for the private key filestatic final StringString representation of private key required permissions. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionstatic voidcheckPKCS12Permissions(String pkcs12File) Checks whether a pkcs12 file has the 'right' permissionsstatic voidcheckPrivateKeyPermissions(String privateKeyFile) Checks whether a private key file has the 'right' permissionsstatic voidcheckProxyPermissions(String proxyFile) Checks whether a proxy file has the right permissionsprivate static voidfilenameSanityChecks(String filename) private static StringgetFilePermissions(String filename) static voidmatchesFilePermissions(String filename, FilePermissionHelper.PosixFilePermission expectedPerm) Checks that a given file has the appropriate unix permissions.static voidsetFilePermissions(String filename, FilePermissionHelper.PosixFilePermission perm) Sets the specified POSIX permissions on a file.static voidsetPKCS12Permissions(String filename) Sets the default POSIX permissions on a p12 identified by filename.static voidsetPrivateKeyPermissions(String filename) Sets the default POSIX permissions on a private key identified by filename.static voidsetProxyPermissions(String filename) Sets the default POSIX permissions on a proxy identified by filename.
-
Field Details
-
PRIVATE_KEY_PERMS
Required file permissions for the private key file -
PRIVATE_KEY_PERMS_STR
String representation of private key required permissions. -
LS_CMD_TEMPLATE
The command used to retrieve file permissions for a given file- See Also:
-
CHMOD_CMD_TEMPLATE
The command used to set file permissions on a given file- See Also:
-
-
Constructor Details
-
FilePermissionHelper
public FilePermissionHelper()
-
-
Method Details
-
checkProxyPermissions
Checks whether a proxy file has the right permissions- Parameters:
proxyFile- the file to be checked- Throws:
IOException- if an error occurs checking file attributesFilePermissionError- if permissions are not as expected
-
checkPrivateKeyPermissions
Checks whether a private key file has the 'right' permissions- Parameters:
privateKeyFile- the file to be checked- Throws:
IOException- if an error occurs checking file attributesFilePermissionError- if the permissions are not correct
-
checkPKCS12Permissions
Checks whether a pkcs12 file has the 'right' permissions- Parameters:
pkcs12File- the file to be checked- Throws:
IOException- if an error occurs checking file attributesFilePermissionError- if the permissions are not correct
-
matchesFilePermissions
public static void matchesFilePermissions(String filename, FilePermissionHelper.PosixFilePermission expectedPerm) throws IOException Checks that a given file has the appropriate unix permissions. This naive implementation just fetches the output of ls -al on a given file and matches the resulting string with the permissionString passed as argument. So the permissionString must be something like:-rw-------
- Parameters:
filename- the filename to be checkedexpectedPerm- the permission string that must be matched- Throws:
IOException- if an error occurs checking file attributesFilePermissionError- if file permissions are not as requested
-
filenameSanityChecks
-
getFilePermissions
-
setProxyPermissions
Sets the default POSIX permissions on a proxy identified by filename.- Parameters:
filename- the file to modify
-
setPKCS12Permissions
Sets the default POSIX permissions on a p12 identified by filename.- Parameters:
filename- the file to modify
-
setPrivateKeyPermissions
Sets the default POSIX permissions on a private key identified by filename.- Parameters:
filename- the file to modify
-
setFilePermissions
public static void setFilePermissions(String filename, FilePermissionHelper.PosixFilePermission perm) Sets the specified POSIX permissions on a file.- Parameters:
filename- the file to modifyperm- the permissions to apply
-