Skip to content
This repository has been archived by the owner on Dec 3, 2023. It is now read-only.

feat: support conditional policies #110

Merged
merged 36 commits into from Feb 27, 2020
Merged
Show file tree
Hide file tree
Changes from 6 commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
67e52ce
Base implementation
frankyn Dec 17, 2019
84fcfea
Update with unit tests
frankyn Dec 20, 2019
145f7a0
lint
frankyn Dec 20, 2019
ac1fd6e
correct copyright date
frankyn Jan 7, 2020
2c8724b
lint
frankyn Jan 7, 2020
c90dbb0
Revert removal of helper functions
frankyn Jan 8, 2020
b0a617f
use auto-value
frankyn Jan 22, 2020
9dbfc2d
Merge branch 'master' into conditional-policy
frankyn Jan 22, 2020
54ad076
reformat Binding.java and Condition.java
frankyn Jan 22, 2020
ff49620
remove unnecessary dep
frankyn Jan 22, 2020
298b2be
code format
frankyn Jan 22, 2020
aaebba4
add dep on com.google.code.findbugs in google-cloud-core
frankyn Jan 22, 2020
a5f63ea
address comments
frankyn Feb 6, 2020
4873b73
Merge branch 'master' into conditional-policy
frankyn Feb 11, 2020
c853a84
Clean up
frankyn Feb 11, 2020
c64e55a
Merge branch 'conditional-policy' of github.com:frankyn/java-core int…
frankyn Feb 11, 2020
d2fab21
respond to comments
frankyn Feb 19, 2020
86cd863
Merge branch 'master' into conditional-policy
frankyn Feb 19, 2020
085959d
address comments
frankyn Feb 20, 2020
174e8c4
format
frankyn Feb 20, 2020
14e1aac
address feedback
frankyn Feb 21, 2020
fdb040a
remove unnecessary null check
frankyn Feb 21, 2020
42199d1
lint
frankyn Feb 21, 2020
bbb708a
address feedback
frankyn Feb 21, 2020
7f0e33e
remove ImmutableList from Binding AutoValue surface
frankyn Feb 21, 2020
108faec
address feedback
frankyn Feb 25, 2020
79126b5
split up unit test
frankyn Feb 25, 2020
505f9bc
use guava beta annotation
frankyn Feb 25, 2020
a89ef0c
surface ImmutableList<> for Binding class.
frankyn Feb 25, 2020
f0b5085
use BetaApi from api.core
frankyn Feb 25, 2020
9f5e600
return as expected
frankyn Feb 26, 2020
8580f5a
partial addressing of feedback
frankyn Feb 26, 2020
9fe4358
address feedback pt2
frankyn Feb 26, 2020
8f48a15
address remaining feedback
frankyn Feb 26, 2020
615ba06
Merge branch 'master' into conditional-policy
frankyn Feb 26, 2020
2b56641
address one last feedback
frankyn Feb 26, 2020
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
64 changes: 47 additions & 17 deletions google-cloud-core/src/main/java/com/google/cloud/Binding.java
Expand Up @@ -16,64 +16,94 @@

package com.google.cloud;

import static com.google.common.base.Predicates.in;
import static com.google.common.base.Predicates.not;

import com.google.api.core.BetaApi;
import com.google.auto.value.AutoValue;
import com.google.common.base.Predicate;
import com.google.common.base.Predicates;
import com.google.common.collect.Collections2;
import com.google.common.collect.ImmutableList;
import com.google.common.collect.Lists;
import java.util.Arrays;
import java.util.Collection;
import java.util.List;
import javax.annotation.Nullable;

/**
* Class for Identity and Access Management (IAM) policies. IAM policies are used to specify access
* settings for Cloud Platform resources. A policy is a list of bindings. A binding assigns a set of
* identities to a role, where the identities can be user accounts, Google groups, Google domains,
* and service accounts. A role is a named list of permissions defined by IAM.
*
* @see <a href="https://cloud.google.com/iam/docs/reference/rest/v1/Policy">Policy</a>
*/
@BetaApi("This is a Beta API is not stable yet and may change in the future.")
@AutoValue
public abstract class Binding {
chingor13 marked this conversation as resolved.
Show resolved Hide resolved
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd very much recommend Javadoc for public types and public methods that aren't obvious.

/** Get IAM Policy Binding Role */
public abstract String getRole();

/** Get IAM Policy Binding Members */
public abstract ImmutableList<String> getMembers();

/** Get IAM Policy Binding Condition */
@Nullable
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why @Nullable instead of a non-nullable Optional<Condition>?

Either is okay, but it's interesting that you're using both patterns in the same class.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I picked Nullable because it made more sense to me in this case. I'm not well versed in Optional's. Both patterns? Not sure I understand.

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I thought for some reason that you were also using Optional. Don't know why I thought that.

public abstract Condition getCondition();

/** Create a Binding.Builder from an existing Binding */
public abstract Builder toBuilder();

/** Create a new Binding.Builder */
public static Builder newBuilder() {
return new AutoValue_Binding.Builder();
List<String> emptyMembers = ImmutableList.of();
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could just inline emptyMembers into setMembers(ImmutableList.of()).

return new AutoValue_Binding.Builder().setMembers(emptyMembers);
}

@AutoValue.Builder
public abstract static class Builder {
/**
* Set IAM Role for Policy Binding
*
* @throws NullPointerException if the role is null.
*/
public abstract Builder setRole(String role);

public abstract Builder setMembers(List<String> members);
/**
* Set IAM Members for Policy Binding
*
* @throws NullPointerException if a member is null.
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You don't really need to repeat this everywhere. It's better to use @Nullable for the hopefully few cases where null is accepted.

*/
public abstract Builder setMembers(Iterable<String> members);

/** Set IAM Condition for Policy Binding */
public abstract Builder setCondition(Condition condition);

public abstract String getRole();

public abstract ImmutableList<String> getMembers();

public abstract Condition getCondition();
/** Internal use to getMembers() in addMembers() and removeMembers() */
abstract ImmutableList<String> getMembers();

// Members property must be initialized before this method can be used.
public Builder addMembers(String... members) {
/**
* Add members to Policy Binding.
*
* @throws NullPointerException if a member is null.
*/
public Builder addMembers(String member, String... moreMembers) {
ImmutableList.Builder<String> membersBuilder = ImmutableList.builder();
membersBuilder.addAll(getMembers());
for (String member : members) {
membersBuilder.add(member);
}
membersBuilder.addAll(Lists.asList(member, moreMembers));
setMembers(membersBuilder.build());
return this;
}

// Members property must be initialized before this method can be used.
/**
* Remove members to Policy Binding.
*
* @throws NullPointerException if a member is null.
*/
public Builder removeMembers(String... members) {
Predicate<String> selectMembersNotInList =
Predicates.not(Predicates.in(Arrays.asList(members)));
Predicate<String> selectMembersNotInList = not(in(Arrays.asList(members)));
Collection<String> filter = Collections2.filter(getMembers(), selectMembersNotInList);
setMembers(ImmutableList.copyOf(filter));
setMembers(filter);
return this;
}

Expand Down
22 changes: 18 additions & 4 deletions google-cloud-core/src/main/java/com/google/cloud/Condition.java
Expand Up @@ -18,34 +18,48 @@

import com.google.api.core.BetaApi;
import com.google.auto.value.AutoValue;
import javax.annotation.Nullable;

/**
* Class for Identity and Access Management (IAM) policies. IAM policies are used to specify access
* settings for Cloud Platform resources. A policy is a list of bindings. A binding assigns a set of
* identities to a role, where the identities can be user accounts, Google groups, Google domains,
* and service accounts. A role is a named list of permissions defined by IAM.
*
* @see <a href="https://cloud.google.com/iam/docs/reference/rest/v1/Policy">Policy</a>
* @see <a href="https://cloud.google.com/iam/docs/conditions-overview">IAM Conditions</a>
*/
@BetaApi("This is a Beta API is not stable yet and may change in the future.")
@AutoValue
public abstract class Condition {
@Nullable
/** Get IAM Policy Binding Condition Title */
public abstract String getTitle();

@Nullable
/** Get IAM Policy Binding Condition Description */
public abstract String getDescription();

@Nullable
/** Get IAM Policy Binding Condition Expression */
public abstract String getExpression();

/** Create a new Condition.Builder from an existing Condition */
public abstract Builder toBuilder();

/** Create a new Condition.Builder */
public static Builder newBuilder() {
return new AutoValue_Condition.Builder();
}

@AutoValue.Builder
public abstract static class Builder {
/** Set IAM Policy Binding Condition Title */
public abstract Builder setTitle(String title);

/** Set IAM Policy Binding Condition Description */
public abstract Builder setDescription(String description);

/** Set IAM Policy Binding Condition Expression */
public abstract Builder setExpression(String expression);

/** Build Builder which creates a Condition instance */
public abstract Condition build();
}
}
37 changes: 19 additions & 18 deletions google-cloud-core/src/main/java/com/google/cloud/Policy.java
Expand Up @@ -43,12 +43,12 @@
* identities to a role, where the identities can be user accounts, Google groups, Google domains,
* and service accounts. A role is a named list of permissions defined by IAM.
*
* @see <a href="https://cloud.google.com/iam/reference/rest/v1/Policy">Policy</a>
* @see <a href="https://cloud.google.com/iam/docs/reference/rest/v1/Policy">Policy</a>
*/
public final class Policy implements Serializable {

private static final long serialVersionUID = -3348914530232544290L;
private final List<Binding> bindingsList;
private final ImmutableList<Binding> bindingsList;
private final String etag;
private final int version;

Expand Down Expand Up @@ -102,7 +102,7 @@ protected Policy fromPb(com.google.iam.v1.Policy policyPb) {
Binding.Builder convertedBinding =
Binding.newBuilder()
.setRole(bindingPb.getRole())
.setMembers(ImmutableList.copyOf(bindingPb.getMembersList()));
.setMembers(bindingPb.getMembersList());
if (bindingPb.hasCondition()) {
Expr expr = bindingPb.getCondition();
convertedBinding.setCondition(
Expand Down Expand Up @@ -131,7 +131,7 @@ protected com.google.iam.v1.Policy toPb(Policy policy) {
for (Binding binding : policy.getBindingsList()) {
com.google.iam.v1.Binding.Builder bindingBuilder = com.google.iam.v1.Binding.newBuilder();
bindingBuilder.setRole(binding.getRole());
bindingBuilder.addAllMembers(ImmutableList.copyOf(binding.getMembers()));
bindingBuilder.addAllMembers(binding.getMembers());
if (binding.getCondition() != null) {
Condition condition = binding.getCondition();
bindingBuilder.setCondition(
Expand Down Expand Up @@ -163,9 +163,7 @@ protected Builder() {}

@InternalApi("This class should only be extended within google-cloud-java")
protected Builder(Policy policy) {
for (Binding binding : policy.bindingsList) {
bindingsList.add(binding.toBuilder().build());
}
bindingsList.addAll(policy.bindingsList);
setEtag(policy.etag);
setVersion(policy.version);
}
Expand All @@ -175,7 +173,8 @@ protected Builder(Policy policy) {
*
* @throws NullPointerException if the given map is null or contains any null keys or values
* @throws IllegalArgumentException if any identities in the given map are null or if policy
* version is equal to 3 or has conditional bindings.
* version is equal to 3 or has conditional bindings because conditional policies are not
* supported
*/
public final Builder setBindings(Map<Role, Set<Identity>> bindings) {
checkNotNull(bindings, "The provided map of bindings cannot be null.");
Expand Down Expand Up @@ -207,7 +206,7 @@ public final Builder setBindings(Map<Role, Set<Identity>> bindings) {
* Replaces the builder's List of bindings with the given List of Bindings.
*
* @throws NullPointerException if the given list is null, role is null, or contains any null
* members in bindings.
* members in bindings
*/
public final Builder setBindings(List<Binding> bindings) {
this.bindingsList.clear();
Expand All @@ -221,7 +220,12 @@ public final Builder setBindings(List<Binding> bindings) {
return this;
}

/** Removes the role (and all identities associated with that role) from the policy. */
/**
* Removes the role (and all identities associated with that role) from the policy.
*
* @throws IllegalArgumentException if policy version is equal to 3 or has conditional bindings
* because conditional policies are not supported
*/
public final Builder removeRole(Role role) {
checkArgument(
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I still think all of these should use checkState instead of checkArgument so they throw IllegalStateException.

Throw IllegalArgumentException when the caller should have known that the arguments to this method are invalid.
Throw IllegalStateException when the caller should have known that this method cannot be called given the state of the object.

!isConditional(this.version, this.bindingsList),
Expand Down Expand Up @@ -283,7 +287,7 @@ public final Builder addIdentity(Role role, Identity first, Identity... others)
* Removes one or more identities from an existing binding. Does nothing if the binding
* associated with the provided role doesn't exist.
*
* @throws IllegalArgumentException if policy version is equal to 3 or has conditional bindings.
* @throws IllegalArgumentException if policy version is equal to 3 or has conditional bindings
*/
public final Builder removeIdentity(Role role, Identity first, Identity... others) {
checkArgument(
Expand Down Expand Up @@ -360,7 +364,7 @@ public Builder toBuilder() {
/**
* Returns the map of bindings that comprises the policy.
*
* @throws IllegalArgumentException if policy version is equal to 3 or has conditional bindings.
* @throws IllegalArgumentException if policy version is equal to 3 or has conditional bindings
*/
public Map<Role, Set<Identity>> getBindings() {
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could return an ImmutableSetMultimap instead.

checkArgument(
Expand All @@ -378,7 +382,7 @@ public Map<Role, Set<Identity>> getBindings() {
}

/** Returns the list of bindings that comprises the policy for version 3. */
public List<Binding> getBindingsList() {
public ImmutableList<Binding> getBindingsList() {
return bindingsList;
}

Expand Down Expand Up @@ -428,13 +432,10 @@ public boolean equals(Object obj) {
return false;
}
Policy other = (Policy) obj;
if (bindingsList.size() != other.getBindingsList().size()) {
if (!bindingsList.equals(other.getBindingsList())) {
return false;
}
for (int i = 0; i < bindingsList.size(); i++) {
bindingsList.get(i).equals(other.getBindingsList().get(i));
}
return Objects.equals(etag, other.getEtag()) && Objects.equals(version, other.getVersion());
return Objects.equals(etag, other.getEtag()) && version == other.getVersion();
}

/** Returns a builder for {@code Policy} objects. */
Expand Down