1 /*
2 * Licensed to the Apache Software Foundation (ASF) under one
3 * or more contributor license agreements. See the NOTICE file
4 * distributed with this work for additional information
5 * regarding copyright ownership. The ASF licenses this file
6 * to you under the Apache License, Version 2.0 (the
7 * "License"); you may not use this file except in compliance
8 * with the License. You may obtain a copy of the License at
9 *
10 * http://www.apache.org/licenses/LICENSE-2.0
11 *
12 * Unless required by applicable law or agreed to in writing,
13 * software distributed under the License is distributed on an
14 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15 * KIND, either express or implied. See the License for the
16 * specific language governing permissions and limitations
17 * under the License.
18 *
19 */
20 package org.apache.directory.server.core.authn;
21
22
23 import javax.naming.NamingException;
24
25 import org.apache.directory.server.core.interceptor.context.BindOperationContext;
26 import org.apache.directory.shared.ldap.constants.AuthenticationLevel;
27 import org.apache.directory.shared.ldap.exception.LdapNoPermissionException;
28
29
30 /**
31 * An {@link Authenticator} that handles anonymous connections
32 * (type <tt>'none'</tt>).
33 *
34 * @author <a href="mailto:dev@directory.apache.org">Apache Directory Project</a>
35 */
36 public class AnonymousAuthenticator extends AbstractAuthenticator
37 {
38 /**
39 * Creates a new instance.
40 */
41 public AnonymousAuthenticator()
42 {
43 super( AuthenticationLevel.NONE.toString() );
44 }
45
46
47 /**
48 * If the context is not configured to allow anonymous connections,
49 * this method throws a {@link javax.naming.NoPermissionException}.
50 */
51 public LdapPrincipal authenticate( BindOperationContext opContext ) throws NamingException
52 {
53 // We only allow Anonymous binds if the sservice allows them _or_
54 // if the user wants to bind on the rootDSE
55 if ( getDirectoryService().isAllowAnonymousAccess() || opContext.getDn().isEmpty() )
56 {
57 return LdapPrincipal.ANONYMOUS;
58 }
59 else
60 {
61 throw new LdapNoPermissionException( "Anonymous bind NOT permitted!" );
62 }
63 }
64 }