QGIS API Documentation 3.41.0-Master (d2aaa9c6e02)
Loading...
Searching...
No Matches
qgsauthguiutils.cpp
Go to the documentation of this file.
1/***************************************************************************
2 qgsauthutils.cpp
3 ---------------------
4 begin : October 24, 2014
5 copyright : (C) 2014 by Boundless Spatial, Inc. USA
6 author : Larry Shaffer
7 email : lshaffer at boundlessgeo dot com
8 ***************************************************************************
9 * *
10 * This program is free software; you can redistribute it and/or modify *
11 * it under the terms of the GNU General Public License as published by *
12 * the Free Software Foundation; either version 2 of the License, or *
13 * (at your option) any later version. *
14 * *
15 ***************************************************************************/
16
17#include "qgsauthguiutils.h"
18
19#include <QFileDialog>
20#include <QInputDialog>
21#include <QLineEdit>
22#include <QMessageBox>
23#include <QTreeWidgetItem>
24
25#include "qgssettings.h"
26#include "qgsauthmanager.h"
28#include "qgslogger.h"
29#include "qgsmessagebar.h"
30#include "qgsapplication.h"
31
32
34{
35 return QColor( 0, 170, 0 );
36}
37
39{
40 return QColor( 255, 128, 0 );
41}
42
44{
45 return QColor( 200, 0, 0 );
46}
47
49{
50 return QColor( 255, 255, 125 );
51}
52
53QString QgsAuthGuiUtils::greenTextStyleSheet( const QString &selector )
54{
55 return QStringLiteral( "%1{color: %2;}" ).arg( selector, QgsAuthGuiUtils::greenColor().name() );
56}
57
58QString QgsAuthGuiUtils::orangeTextStyleSheet( const QString &selector )
59{
60 return QStringLiteral( "%1{color: %2;}" ).arg( selector, QgsAuthGuiUtils::orangeColor().name() );
61}
62
63QString QgsAuthGuiUtils::redTextStyleSheet( const QString &selector )
64{
65 return QStringLiteral( "%1{color: %2;}" ).arg( selector, QgsAuthGuiUtils::redColor().name() );
66}
67
69{
71 {
72 msgbar->clearWidgets();
73 msgbar->pushMessage( QObject::tr( "Authentication System" ), QObject::tr( "DISABLED. Resources authenticating via the system can not be accessed" ), Qgis::MessageLevel::Critical );
74 return true;
75 }
76 return false;
77}
78
79void QgsAuthGuiUtils::exportSelectedAuthenticationConfigs( QStringList authenticationConfigIds, QgsMessageBar *msgbar )
80{
81 const QString password = QInputDialog::getText( msgbar, QObject::tr( "Export Authentication Configurations" ), QObject::tr( "Enter a password encrypt the configuration file:" ), QLineEdit::Password );
82 if ( password.isEmpty() )
83 {
84 if ( QMessageBox::warning( msgbar, QObject::tr( "Export Authentication Configurations" ), QObject::tr( "Exporting authentication configurations with a blank password will result in a plain text file which may contain sensitive information. Are you sure you want to do this?" ), QMessageBox::Ok | QMessageBox::Cancel, QMessageBox::Cancel ) == QMessageBox::Cancel )
85 {
86 return;
87 }
88 }
89
90 const QString filename = QFileDialog::getSaveFileName( msgbar, QObject::tr( "Export Authentication Configurations" ), QDir::homePath(), QObject::tr( "XML files (*.xml *.XML)" ) );
91 if ( filename.isEmpty() )
92 return;
93
94 const bool ok = QgsApplication::authManager()->exportAuthenticationConfigsToXml( filename, authenticationConfigIds, password );
95 if ( !ok )
96 {
97 msgbar->clearWidgets();
98 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), QObject::tr( "Export of authentication configurations failed." ), Qgis::MessageLevel::Critical );
99 }
100}
101
103{
104 const QString filename = QFileDialog::getOpenFileName( msgbar, QObject::tr( "Export Authentication Configurations" ), QDir::homePath(), QObject::tr( "XML files (*.xml *.XML)" ) );
105 if ( filename.isEmpty() )
106 return;
107
108
109 QFile file( filename );
110 if ( !file.open( QFile::ReadOnly ) )
111 {
112 return;
113 }
114
115 QDomDocument document( QStringLiteral( "qgis_authentication" ) );
116 if ( !document.setContent( &file ) )
117 {
118 file.close();
119 return;
120 }
121 file.close();
122
123 const QDomElement root = document.documentElement();
124 if ( root.tagName() != QLatin1String( "qgis_authentication" ) )
125 {
126 return;
127 }
128
129 QString password;
130 if ( root.hasAttribute( QStringLiteral( "salt" ) ) )
131 {
132 password = QInputDialog::getText( msgbar, QObject::tr( "Import Authentication Configurations" ), QObject::tr( "Enter the password to decrypt the configurations file:" ), QLineEdit::Password );
133 }
134
135 const bool ok = QgsApplication::authManager()->importAuthenticationConfigsFromXml( filename, password );
136 if ( !ok )
137 {
138 msgbar->clearWidgets();
139 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), QObject::tr( "Import of authentication configurations failed." ), Qgis::MessageLevel::Critical );
140 }
141}
142
144{
145 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
146 return;
147
148 if ( QgsApplication::authManager()->masterPasswordIsSet() )
149 {
150 msgbar->clearWidgets();
151 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), QObject::tr( "Master password already set." ), Qgis::MessageLevel::Info );
152 return;
153 }
155}
156
158{
159 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
160 return;
161
162 QString msg( QObject::tr( "Master password not cleared because it is not set." ) );
164
165 if ( QgsApplication::authManager()->masterPasswordIsSet() )
166 {
168 msg = QObject::tr( "Master password cleared (NOTE: network connections may be cached)." );
169 if ( QgsApplication::authManager()->masterPasswordIsSet() )
170 {
171 msg = QObject::tr( "Master password FAILED to be cleared." );
173 }
174 }
175
176 msgbar->clearWidgets();
177 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), msg, level );
178}
179
181{
182 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
183 return;
184
185 QString msg( QObject::tr( "Master password reset" ) );
187
188 // check that a master password is even set in auth db
189 if ( !QgsApplication::authManager()->masterPasswordHashInDatabase() )
190 {
191 msg = QObject::tr( "Master password reset: NO current password hash in database" );
192 msgbar->clearWidgets();
194 return;
195 }
196
197 // get new password via dialog; do current password verification in-dialog
198 QString newpass;
199 QString oldpass;
200 bool keepbackup = false;
201 QgsMasterPasswordResetDialog dlg( parent );
202
203 if ( !dlg.requestMasterPasswordReset( &newpass, &oldpass, &keepbackup ) )
204 {
205 QgsDebugMsgLevel( QStringLiteral( "Master password reset: input canceled by user" ), 2 );
206 return;
207 }
208
209 QString backuppath;
210 if ( !QgsApplication::authManager()->resetMasterPassword( newpass, oldpass, keepbackup, &backuppath ) )
211 {
212 msg = QObject::tr( "Master password FAILED to be reset" );
214 }
215
216 if ( !backuppath.isEmpty() )
217 {
218 msg += QObject::tr( " (database backup: %1)" ).arg( backuppath );
219 }
220
221 msgbar->clearWidgets();
222 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), msg, level );
223}
224
226{
227 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
228 return;
229
231 const QString msg = QObject::tr( "Cached authentication configurations for session cleared" );
232 msgbar->clearWidgets();
234}
235
237{
238 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
239 return;
240
241 if ( QMessageBox::warning( parent, QObject::tr( "Remove Configurations" ), QObject::tr( "Are you sure you want to remove ALL authentication configurations?\n\n"
242 "Operation can NOT be undone!" ),
243 QMessageBox::Ok | QMessageBox::Cancel, QMessageBox::Cancel )
244 == QMessageBox::Cancel )
245 {
246 return;
247 }
248
249 QString msg( QObject::tr( "Authentication configurations removed." ) );
251
252 if ( !QgsApplication::authManager()->removeAllAuthenticationConfigs() )
253 {
254 msg = QObject::tr( "Authentication configurations FAILED to be removed." );
256 }
257
258 msgbar->clearWidgets();
259 msgbar->pushMessage( QgsApplication::authManager()->authManTag(), msg, level );
260}
261
263{
264 if ( QgsAuthGuiUtils::isDisabled( msgbar ) )
265 return;
266
267 const QMessageBox::StandardButton btn = QMessageBox::warning(
268 parent,
269 QObject::tr( "Erase Database" ),
270 QObject::tr( "Are you sure you want to ERASE the entire authentication database?\n\n"
271 "Operation can NOT be undone!\n\n"
272 "(Current database will be backed up and new one created.)" ),
273 QMessageBox::Ok | QMessageBox::Cancel,
274 QMessageBox::Cancel
275 );
276
278
279 if ( btn == QMessageBox::Cancel )
280 {
281 return;
282 }
283
284 QString msg( QObject::tr( "Active authentication database erased." ) );
286
287 QString backuppath;
288 if ( !QgsApplication::authManager()->eraseAuthenticationDatabase( true, &backuppath ) )
289 {
290 msg = QObject::tr( "Authentication database FAILED to be erased." );
292 }
293 else
294 {
295 if ( !backuppath.isEmpty() )
296 {
297 msg += QObject::tr( " (backup: %1)" ).arg( backuppath );
298 }
300 }
301
302 msgbar->clearWidgets();
303 msgbar->pushMessage( QObject::tr( "RESTART QGIS" ), msg, level );
304}
305
306void QgsAuthGuiUtils::fileFound( bool found, QWidget *widget )
307{
308 if ( !found )
309 {
310 widget->setStyleSheet( QgsAuthGuiUtils::redTextStyleSheet( QStringLiteral( "QLineEdit" ) ) );
311 widget->setToolTip( QObject::tr( "File not found" ) );
312 }
313 else
314 {
315 widget->setStyleSheet( QString() );
316 widget->setToolTip( QString() );
317 }
318}
319
320QString QgsAuthGuiUtils::getOpenFileName( QWidget *parent, const QString &title, const QString &extfilter )
321{
322 QgsSettings settings;
323 const QString recentdir = settings.value( QStringLiteral( "UI/lastAuthOpenFileDir" ), QDir::homePath() ).toString();
324 QString f = QFileDialog::getOpenFileName( parent, title, recentdir, extfilter );
325 if ( !f.isEmpty() )
326 {
327 settings.setValue( QStringLiteral( "UI/lastAuthOpenFileDir" ), QFileInfo( f ).absoluteDir().path() );
328 }
329 return f;
330}
331
333{
334 if ( QMessageBox::warning( parent, QObject::tr( "Delete Password" ), QObject::tr( "Do you really want to delete the master password from your %1?" ).arg( QgsAuthManager::AUTH_PASSWORD_HELPER_DISPLAY_NAME ), QMessageBox::Ok | QMessageBox::Cancel, QMessageBox::Cancel ) == QMessageBox::Cancel )
335 {
336 return;
337 }
338 QString msg;
339 Qgis::MessageLevel level;
341 {
344 }
345 else
346 {
347 msg = QObject::tr( "Master password was successfully deleted from your %1" )
349
351 }
352 msgbar->clearWidgets();
353 msgbar->pushMessage( QObject::tr( "Password helper delete" ), msg, level );
354}
355
357{
358 QString msg;
359 Qgis::MessageLevel level;
360 if ( !QgsApplication::authManager()->masterPasswordIsSet() )
361 {
362 msg = QObject::tr( "Master password is not set and cannot be stored in your %1." )
365 }
367 {
370 }
371 else
372 {
373 msg = QObject::tr( "Master password has been successfully stored in your %1." )
375
377 }
378 msgbar->clearWidgets();
379 msgbar->pushMessage( QObject::tr( "Password helper write" ), msg, level );
380}
381
383{
385 const QString msg = enabled ? QObject::tr( "Your %1 will be <b>used from now</b> on to store and retrieve the master password." )
387 : QObject::tr( "Your %1 will <b>not be used anymore</b> to store and retrieve the master password." )
389 msgbar->clearWidgets();
390 msgbar->pushMessage( QObject::tr( "Password helper write" ), msg, Qgis::MessageLevel::Info );
391}
392
393void QgsAuthGuiUtils::passwordHelperLoggingEnable( bool enabled, QgsMessageBar *msgbar, int timeout )
394{
395 Q_UNUSED( msgbar )
396 Q_UNUSED( timeout )
398}
399
400void QgsAuthGuiUtils::setItemBold( QTreeWidgetItem *item )
401{
402 item->setFirstColumnSpanned( true );
403 QFont secf( item->font( 0 ) );
404 secf.setBold( true );
405 item->setFont( 0, secf );
406}
407
408void QgsAuthGuiUtils::removeChildren( QTreeWidgetItem *item )
409{
410 const auto constTakeChildren = item->takeChildren();
411 for ( QTreeWidgetItem *child : constTakeChildren )
412 {
413 delete child;
414 }
415}
MessageLevel
Level for messages This will be used both for message log and message bar in application.
Definition qgis.h:154
@ Warning
Warning message.
Definition qgis.h:156
@ Critical
Critical/error message.
Definition qgis.h:157
@ Info
Information message.
Definition qgis.h:155
static QgsAuthManager * authManager()
Returns the application's authentication manager instance.
static void importAuthenticationConfigs(QgsMessageBar *msgbar)
Import authentication configurations from a XML file.
static void exportSelectedAuthenticationConfigs(QStringList authenticationConfigIds, QgsMessageBar *msgbar)
Exports selected authentication configurations to a XML file.
static QString greenTextStyleSheet(const QString &selector="*")
Green text stylesheet representing valid, trusted, etc. certificate.
static void resetMasterPassword(QgsMessageBar *msgbar, QWidget *parent=nullptr)
Reset the cached master password, updating its hash in authentication database and resetting all exis...
static QColor greenColor()
Green color representing valid, trusted, etc. certificate.
static QColor orangeColor()
Orange color representing loaded component, but not stored in database.
static QString redTextStyleSheet(const QString &selector="*")
Red text stylesheet representing invalid, untrusted, etc. certificate.
static void clearCachedMasterPassword(QgsMessageBar *msgbar)
Clear the currently cached master password (not its hash in database)
static void passwordHelperEnable(bool enabled, QgsMessageBar *msgbar)
Sets password helper enabled (enable/disable)
static QString orangeTextStyleSheet(const QString &selector="*")
Orange text stylesheet representing loaded component, but not stored in database.
static void setItemBold(QTreeWidgetItem *item)
Call setFirstColumnSpanned(true) on the item and make its font bold.
static void removeChildren(QTreeWidgetItem *item)
Remove the children of the passed item.
static void clearCachedAuthenticationConfigs(QgsMessageBar *msgbar)
Clear all cached authentication configs for session.
static bool isDisabled(QgsMessageBar *msgbar)
Verify the authentication system is active, else notify user.
static void passwordHelperLoggingEnable(bool enabled, QgsMessageBar *msgbar, int timeout=0)
Sets password helper logging enabled (enable/disable)
static void eraseAuthenticationDatabase(QgsMessageBar *msgbar, QWidget *parent=nullptr)
Completely clear out the authentication database (configs and master password)
static void removeAuthenticationConfigs(QgsMessageBar *msgbar, QWidget *parent=nullptr)
Remove all authentication configs.
static QColor yellowColor()
Yellow color representing caution regarding action.
static void fileFound(bool found, QWidget *widget)
Color a widget via a stylesheet if a file path is found or not.
static void setMasterPassword(QgsMessageBar *msgbar)
Sets the cached master password (and verifies it if its hash is in authentication database)
static QString getOpenFileName(QWidget *parent, const QString &title, const QString &extfilter)
Open file dialog for auth associated widgets.
static void passwordHelperDelete(QgsMessageBar *msgbar, QWidget *parent=nullptr)
Remove master password from wallet.
static void passwordHelperSync(QgsMessageBar *msgbar)
Store master password into the wallet.
static QColor redColor()
Red color representing invalid, untrusted, etc. certificate.
void clearAllCachedConfigs()
Clear all authentication configs from authentication method caches.
bool exportAuthenticationConfigsToXml(const QString &filename, const QStringList &authcfgs, const QString &password=QString())
Export authentication configurations to an XML file.
void setPasswordHelperEnabled(bool enabled)
Password helper enabled setter.
void setScheduledAuthDatabaseErase(bool scheduleErase)
Schedule an optional erase of authentication database, starting when mutex is lockable.
bool importAuthenticationConfigsFromXml(const QString &filename, const QString &password=QString(), bool overwrite=false)
Import authentication configurations from an XML file.
void clearMasterPassword()
Clear supplied master password.
const QString passwordHelperErrorMessage()
Error message getter.
static void setPasswordHelperLoggingEnabled(bool enabled)
Password helper logging enabled setter.
bool setMasterPassword(bool verify=false)
Main call to initially set or continually check master password is set.
static const QString AUTH_PASSWORD_HELPER_DISPLAY_NAME
The display name of the password helper (platform dependent)
Dialog to verify current master password and initiate reset of authentication database with a new pas...
bool requestMasterPasswordReset(QString *newpass, QString *oldpass, bool *keepbackup)
A bar for displaying non-blocking messages to the user.
void pushMessage(const QString &text, Qgis::MessageLevel level=Qgis::MessageLevel::Info, int duration=-1)
A convenience method for pushing a message with the specified text to the bar.
bool clearWidgets()
Removes all items from the bar.
This class is a composition of two QSettings instances:
Definition qgssettings.h:64
QVariant value(const QString &key, const QVariant &defaultValue=QVariant(), Section section=NoSection) const
Returns the value for setting key.
void setValue(const QString &key, const QVariant &value, QgsSettings::Section section=QgsSettings::NoSection)
Sets the value of setting key to value.
#define QgsDebugMsgLevel(str, level)
Definition qgslogger.h:39