diff --git a/document/design/assets/Modeling.svg b/document/design/assets/Modeling.svg index f38be3b3..1ac60ee1 100644 --- a/document/design/assets/Modeling.svg +++ b/document/design/assets/Modeling.svg @@ -11,65 +11,62 @@ - limitations under the License. --> -https://github.com/Ahoo-Wang/CoSecCoSec Modeling Class Diagramtenantpolicyroleprincipalpolicyprincipaljava.securitycontextauthorizationauthenticationcontextauthorizationauthenticationTenantval tenantId: Stringval isPlatform: BooleanTenantCapableval tenant: TenantIs it a root platform tenant?PolicyTypeSYSTEMCUSTOMGLOBALPolicyval id: Stringval name: Stringval type: PolicyTypeval description: Stringval tenantId:Stringval statements: Set<Statement>EffectALLOWDENYPolicyTypeSYSTEMCUSTOMGLOBALPolicyval id: Stringval name: Stringval type: PolicyTypeval description: Stringval tenantId:Stringval statements: Set<Statement>EffectALLOWDENYRequestMatchermatch(Request,SecurityContext): BooleanActionMatcherConditionMatcherActionMatcherConditionMatcherVerifyResultALLOWEXPLICIT_DENYIMPLICIT_DENYStatementval effect: Effectval actions: Set<ActionMatcher>val conditions: Set<ConditionMatcher>PermissionVerifierverify(Request,SecurityContext): VerifyResultStatementval effect: Effectval actions: Set<ActionMatcher>val conditions: Set<ConditionMatcher>PermissionVerifierverify(Request,SecurityContext): VerifyResultPolicyEvaluatorevaluate(Policy)PolicyCapableval policies: Set<String>Used to evaluate the effectiveness of the PolicyRoleval id: Stringval name: Stringval description: Stringval tenantId:StringRoleCapableval roles: Set<String>CoSecPrincipalval id: Stringval attributes: Map<String, String>anonymous(): Booleanauthenticated(): BooleanTenantPrincipalA set of rolesPrincipalgetName():StringSecurityContextval principal: CoSecPrincipalsetAttribute(String, Object): SecurityContextgetAttribute(String): T?getRequiredAttribute(String): TRequestval path: Stringval method: Stringval remoteIp: Stringval origin: Stringval referer: StringgetHeader(key: String): StringAuthorizeResultval authorized: Booleanval reason: StringAuthorizationauthorize(Request,SecurityContext): Mono<AuthorizeResult>CredentialsAuthenticationC:Credentials,P:CoSecPrincipalsupportCredentials: Class<C>authenticate(C): Mono<P>AuthenticationProviderget(Class<Credentials>): A?getRequired(Class<Credentials>): Aregister(A): Unitregister(Class<C>, A): Unitregister(A): UnitgetRequired(Class<Credentials>): APolicyCapableval policies: Set<String>Used to evaluate the effectiveness of the PolicyRoleCapableval roles: Set<String>CoSecPrincipalval id: Stringval attributes: Map<String, String>anonymous(): Booleanauthenticated(): BooleanTenantPrincipalA set of rolesPrincipalgetName():StringSecurityContextval principal: CoSecPrincipalsetAttribute(String, Object): SecurityContextgetAttribute(String): T?getRequiredAttribute(String): TRequestval path: Stringval method: Stringval remoteIp: Stringval origin: Stringval referer: StringgetHeader(key: String): StringAuthorizeResultval authorized: Booleanval reason: StringAuthorizationauthorize(Request,SecurityContext): Mono<AuthorizeResult>CredentialsAuthenticationC:Credentials,P:CoSecPrincipalsupportCredentials: Class<C>authenticate(C): Mono<P>AuthenticationProviderget(Class<Credentials>): A?getRequired(Class<Credentials>): Aregister(A): Unitregister(Class<C>, A): Unitregister(A): UnitgetRequired(Class<Credentials>): ANamedname: Stringhttps://github.com/Ahoo-Wang/CoSechttps://github.com/Ahoo-Wang/CoSec