001package ca.uhn.fhir.rest.server.interceptor.auth;
002
003/*
004 * #%L
005 * HAPI FHIR - Server Framework
006 * %%
007 * Copyright (C) 2014 - 2019 University Health Network
008 * %%
009 * Licensed under the Apache License, Version 2.0 (the "License");
010 * you may not use this file except in compliance with the License.
011 * You may obtain a copy of the License at
012 * 
013 *      http://www.apache.org/licenses/LICENSE-2.0
014 * 
015 * Unless required by applicable law or agreed to in writing, software
016 * distributed under the License is distributed on an "AS IS" BASIS,
017 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
018 * See the License for the specific language governing permissions and
019 * limitations under the License.
020 * #L%
021 */
022
023import ca.uhn.fhir.rest.api.RestOperationTypeEnum;
024import ca.uhn.fhir.rest.api.server.RequestDetails;
025import ca.uhn.fhir.rest.server.interceptor.auth.AuthorizationInterceptor.Verdict;
026import org.hl7.fhir.instance.model.api.IBaseResource;
027import org.hl7.fhir.instance.model.api.IIdType;
028
029import java.util.Set;
030
031public class RuleImplConditional extends BaseRule implements IAuthRule {
032
033        private AppliesTypeEnum myAppliesTo;
034        private Set<?> myAppliesToTypes;
035        private RestOperationTypeEnum myOperationType;
036
037        RuleImplConditional(String theRuleName) {
038                super(theRuleName);
039        }
040
041        @Override
042        public Verdict applyRule(RestOperationTypeEnum theOperation, RequestDetails theRequestDetails, IBaseResource theInputResource, IIdType theInputResourceId, IBaseResource theOutputResource,
043                                                                         IRuleApplier theRuleApplier, Set<AuthorizationFlagsEnum> theFlags) {
044
045                if (isOtherTenant(theRequestDetails)) {
046                        return null;
047                }
048
049                if (theInputResourceId != null) {
050                        return null;
051                }
052
053                if (theOperation == myOperationType) {
054                        switch (myAppliesTo) {
055                                case ALL_RESOURCES:
056                                case INSTANCES:
057                                        break;
058                                case TYPES:
059                                        if (theInputResource == null || !myAppliesToTypes.contains(theInputResource.getClass())) {
060                                                return null;
061                                        }
062                                        break;
063                        }
064
065                        if (theRequestDetails.getConditionalUrl(myOperationType) == null) {
066                                return null;
067                        }
068
069                        if (getTenantApplicabilityChecker() != null) {
070                                if (!getTenantApplicabilityChecker().applies(theRequestDetails)) {
071                                        return null;
072                                }
073                        }
074
075                        if (!applyTesters(theOperation, theRequestDetails, theInputResourceId, theInputResource, theOutputResource)) {
076                                return null;
077                        }
078
079                        return newVerdict();
080                }
081
082                return null;
083        }
084
085        void setAppliesTo(AppliesTypeEnum theAppliesTo) {
086                myAppliesTo = theAppliesTo;
087        }
088
089        void setAppliesToTypes(Set<?> theAppliesToTypes) {
090                myAppliesToTypes = theAppliesToTypes;
091        }
092
093        void setOperationType(RestOperationTypeEnum theOperationType) {
094                myOperationType = theOperationType;
095        }
096
097}