#ifndef __ABAC_HH__ #define __ABAC_HH__ #include #include namespace ABAC { extern "C" { #include "abac.h" } class Role { public: Role() : m_role(NULL), m_oset(NULL) { } // do not use: here for swig Role(abac_role_t *role): m_role(abac_role_dup(role)), m_oset(NULL) { } Role(abac_oset_t *oset): m_role(NULL), m_oset(abac_oset_dup(oset)) { } Role(char *role_name) : m_role(abac_role_from_string(role_name)), m_oset(NULL) { } Role(const Role &role) { if ( role.m_role ) { m_role = abac_role_dup(role.m_role); m_oset = NULL; } else { m_role = NULL; m_oset =abac_oset_dup(role.m_oset); } } ~Role() { if ( m_role) abac_role_free(m_role); if ( m_oset) abac_oset_free(m_oset); } bool is_principal() const { if (m_role) return abac_role_is_principal(m_role); else return abac_oset_is_principal(m_oset); } bool is_role() const { if (m_role) return abac_role_is_role(m_role); else return abac_oset_is_oset(m_oset); } bool is_linking() const { if (m_role) return abac_role_is_linking(m_role); else return abac_oset_is_linking(m_oset); } bool is_oset() const { return m_oset; } char *string() const { if ( m_role) return abac_role_string(m_role); else return abac_oset_string(m_oset); } char *linked_role() const { if (m_role) return abac_role_linked_role(m_role); else return abac_oset_linked_role(m_oset); } char *role_name() const { if (m_role) return abac_role_role_name(m_role); else return abac_oset_oset_name(m_oset); } char *principal() const { if (m_role) return abac_role_principal(m_role); else return abac_oset_principal(m_oset); } private: abac_role_t *m_role; abac_oset_t *m_oset; }; class Credential { public: Credential() : m_cred(NULL) { } // do not use: here for swig Credential(abac_credential_t *cred) : m_head(), m_tail(), m_cred(abac_credential_dup(cred)) { if ( abac_credential_holds_roles(cred)) { m_head = Role(abac_credential_head(cred)); m_tail = Role(abac_credential_tail(cred)); } else { m_head = Role(abac_credential_head_oset(cred)); m_tail = Role(abac_credential_tail_oset(cred)); } } Credential(const Credential &cred) : m_head(cred.m_head), m_tail(cred.m_tail), m_cred(abac_credential_dup(cred.m_cred)) { } ~Credential() { abac_credential_free(m_cred); } const Role &head() { return m_head; } const Role &tail() { return m_tail; } abac_chunk_t attribute_cert() { return abac_credential_attribute_cert(m_cred); } abac_chunk_t issuer_cert() { return abac_credential_issuer_cert(m_cred); } private: abac_credential_t *m_cred; Role m_head, m_tail; }; class Context { public: Context() { m_ctx = abac_context_new(); } Context(const Context &context) { m_ctx = abac_context_dup(context.m_ctx); } ~Context() { abac_context_free(m_ctx); } /* see abac.h for possible return values */ int load_id_file(char *filename) { return abac_context_load_id_file(m_ctx, filename); } int load_id_chunk(abac_chunk_t cert) { return abac_context_load_id_chunk(m_ctx, cert); } int load_attribute_file(char *filename) { return abac_context_load_attribute_file(m_ctx, filename); } int load_attribute_chunk(abac_chunk_t cert) { return abac_context_load_attribute_chunk(m_ctx, cert); } /* load an entire directory full of certs */ void load_directory(char *path) { abac_context_load_directory(m_ctx, path); } /* abac query, returns a vector of credentials on success, NULL on fail */ std::vector query(char *role, char *principal, bool &success) { abac_credential_t **creds, **end; int i, success_int; creds = abac_context_query(m_ctx, role, principal, &success_int); success = success_int; for (i = 0; creds[i] != NULL; ++i) ; end = &creds[i]; std::vector credentials = std::vector(creds, end); abac_context_credentials_free(creds); return credentials; } std::vector credentials() { abac_credential_t **creds, **end; int i; creds = abac_context_credentials(m_ctx); for (i = 0; creds[i] != NULL; ++i) ; end = &creds[i]; std::vector credentials = std::vector(creds, end); abac_context_credentials_free(creds); return credentials; } private: abac_context_t *m_ctx; }; } #endif /* __ABAC_HH__ */