PersonDirectory was refactored for uPortal 2.5 to be backed by Spring to wire together its implementation. However, documentation exists for PersonDirectory in uPortal 2.4 and earlier.
PersonDirectory as API
In keeping with the uPortal 2 static service class model (often these static services are factories, e.g. ChannelManagerFactory, but sometimes they are merely static services such as RDBMServices, LdapServices, and PersonDirectory), PersonDirectory now provides a public static method whereby you can get an instance of IPersonAttributeDao.
Code Block |
IPersonAttributeDao dao = PersonDirectory.getPersonAttributeDaoInstance();
The public IPersonAttributeDao interface methods, in turn, provide an API whereby uPortal components access user attributes.
Code Block |
* Obtains a mutable {@link Map} from attribute names to values for
* the given query seed. The values may be mutable objects but it is
* recommended they are immutable.<br>
* For the returned {@link Map}; Names must be {@link String}, Values
* can be any {@link Object}, they are typically {@link String}<br>
* Values may also be multi-valued, in this case they are of type
* {@link java.util.List} and the lists contents are the values of the
* attribute.<br>
* The return of this method uses the following rules:<br>
* <ul>
* <li>If the user exists and has attributes a populated {@link Map} is returned.</li>
* <li>If the user exists and has no attributes an empty {@link Map} is returned.</li>
* <li>If the user doesn't exist <code>null</code> is returned.</li>
* <li>If an error occurs while getting the attributes the appropriate exception will be propagated.</li>
* </ul>
* @param seed Map of attributes and values to use for the query
* @return Map from attribute names to values
* @throws IllegalArgumentException If <code>seed</code> is <code>null</code>
public Map getUserAttributes(final Map seed);
* This method uses the default attribute to construct a seed
* {@link Map} and call the {@link #getUserAttributes(Map)} method
* with.
* @param uid The string to use as the value in the seed
* @return The same value as returned by {@link #getUserAttributes(Map)}
* @see #getUserAttributes(Map)
public Map getUserAttributes(final String uid);
* Gets a {@link Set} of attribute names that may be returned by the
* {@link #getUserAttributes(Map)}. The names returned represent all
* possible names {@link #getUserAttributes(Map)} could return. If the
* dao doesn't have a way to know all possible attribute names this
* method should return <code>null</code>
* <br>
* An immutable {@link Set} is returned.
* @return A {link Set} of possible attribute names for user queries.
public Set getPossibleUserAttributeNames();
To get the attributes into an IPerson object use the new (as of uP 2.5) setAttributes method:
Code Block |
* Associates attributes with the user
* @param attrs
public void setAttributes (Map attrs);
PersonFactory now offers the service of RestrictedPerson creation.
Code Block |
* Creates a <i>restricted</i> user.
* @return <i>restricted</i> user
public static RestrictedPerson createRestrictedPerson() {
PersonDirectory as configurable facility
PersonDirectory is a uPortal customization point.
You have three basic options for configuring PersonDirectory:
PersonDirs.xml configuration
You can configure purely by editing PersonDirs.xml, perhaps leveraging your existing skills with that file format. And you have a good deal of flexibility there, using LDAP and JDBC to get your attributes.
The uPortal 2.5 PersonDirectory continues to support PersonDirs.xml to configure your person attribute sources. The PersonDirs.xml language allows you to specify in the PersonDirs.xml the configuration parameters for LDAP or JDBC queries as sources of attributes, with the server configuration (database URL, username, password, driver, etc.) being configured right there. It also lets you configure queries against databases or LDAP servers that are managed by RDBMServices or LdapServices. So there's quite a bit of flexibility right there.
This means of configuration is supported in 2.5 – the new implementation even provides additional validation of PersonDirs.xml configuration data to catch problems and provide more helpful logging and exception messages.
This is a recommended approach if the PersonDirs.xml language supports everything you need.
uPortal 2.5 implements uPortal 2.4-style PersonDirs.xml-driven configuration by means of LegacyPersonAttributeDao.
Custom Java implementation
If you're most comfortable editing Java and don't want to be working with Spring XML, you can change the class name in the personDirectory.xml beans declaration to be a custom class of your choice, so long as it implements IPersonAttributeDao. You can then write the custom implementation that does exactly the queries, caching, and any other behavior you need.
Below is a description of the default Person Directory configuration. See JDBC User Attribute Sources and LDAP User Attribute Sources for examples of setting additional attributes via JDBC and LDAP.
The legacy xml configuration PersonDirs.xml is not supported in uPortal 3.0 and later.
Using Spring to configure an IPersonAttributeDao implementation
The recommended approach is to use Spring to wire together a Java object that implements IPersonAttributeDao. This facility was added in uPortal 2.5. We expect that the provided implementations of IPersonAttributeDao will be sufficient for most uPortal deployments, however you can also develop a custom IPersonAttributeDao to meet additional needs.
Spring and PersonDirectory
Currently a Spring beans.dtd-compliant XML file named personDirectoryContext.xml declares the configuration of an instance of IPersonAttributeDao. The class PersonDirectory delegates to this Spring-configured IPersonAttributeDao instance to actually implement the PersonDirectory behavior.
JDBC Example
For examples, visit the page dedicated to JDBC User Attribute Sources.
LDAP example
For examples, visit the page dedicated to LDAP User Attribute Sources.
Request Attribute Filter Example
The Request Attribute Filter is designed for use with Shibboleth. For a complete discussion of configuring uPortal for Shibboleth, see Shibboleth. The following example shows a use of the RequestAttributeSourceFilter to retrieve the serverName attribute. In a real life scenario you would want to retrieve person attributes provided in the request.
Code Block | ||
| ||
| Servlet filter that creates an attribute for the serverName
<bean id="requestAttributeSourceFilter" class="org.jasig.services.persondir.support.web.RequestAttributeSourceFilter">
<property name="additionalDescriptors" ref="requestAdditionalDescriptors" />
<property name="serverNameAttribute" value="serverName" />
<property name="processingPosition" value="BOTH" />
</bean> |
Merging example
This would get pretty boring if we could only ever have one source of user attributes at a time. MergingPersonAttributeDaoImpl merges attributes from multiple sources.
Here we're merging together attributes from a JDBCPersonAttributeDaoImpl and from an LdapPersonAttributeDaoImpl. Here we've accepted the default merge strategy, but MergingPersonAttributeDaoImpl is configurable to accept alternative merge strategies. MergingPersonAttributeDaoImpl can also be configured as to how it should handle exceptions thrown by the DAOs it is merging.
Code Block | ||||
| ||||
<beans> <bean id="personAttributeDao" class="org.jasig.portal.services.persondir.support.MergingPersonAttributeDaoImpl"> <property name="personAttributeDaos"> <list> <bean class="org.jasig.portal.services.persondir.support.JdbcPersonAttributeDaoImpl"> <constructor-arg> <bean class="org.springframework.jdbc.datasource.DriverManagerDataSource"> <property name="driverClassName"><value>${jdbc.driverClassName}</value></property> <property name="url"><value>${jdbc.url}</value></property> <property name="username"><value>${jdbc.username}</value></property> <property name="password"><value>${jdbc.password}</value></property> </bean> </constructor-arg> <constructor-arg> <value>SELECT name, shirt_color FROM someschema.sometable WHERE uid = ?</value> </constructor-arg> <property name="columnsToAttributes"> <map> <entry key="name"> <value>name</value> </entry> <entry key="shirt_color"> add any properties here --> </bean> </beans> |
If you're customizing PersonDirectory behavior, Spring likely has something to offer you in terms of configuring your custom IPersonAttributeDao implementation. However, if you really want to, you can code all of your configuration directly in Java, compile it, and simply reference your implementation.
While these examples conform to beans.dtd, they haven't necessarily been actually run in uPortal instances, so these XMLs might not actually work as is. If you find anything wrong with these example XMLs, please either fix them if you feel comfortable or else comment on this page so that they can be fixed. Thanks!
For more examples, visit the page dedicated to JdbcPersonAttributeDaoImpl.
Spring recap
Now, you might be thinking, "That makes perfect sense to me, I've seen this before because I use Spring for my other applications." If so, this way of configuration might be right for you.
LegacyPersonDirectoryToPersonAttributeDaoAdapter and PersonDirs.xml revisited
But you might be thinking, "That's really complicated. I don't like this. I'd be much happier using the old PersonDirs.xml approach to life." And if that's what you're thinking, LegacyPersonAttributeDao and the default personDirectory.xml configuration will probably be right for you.
Rolling your own
<beans> <bean id="personAttributeDao" class="edu.youruniv.portal.persondir.CustomPersonAttributeDaoImpl"> </bean> </beans> |
As of uPortal 2.4.2, caching internal to PersonDirectory was removed in uPortal 2.4 and 2.HEAD. This was because the caching implementation leaked memory.
Custom Java implementation
Although not recommended it is possible to change the class name in the personDirectory.xml beans declaration to be a custom class of your choice, so long as it implements IPersonAttributeDao. You could then write a custom implementation that does exactly the queries, caching, and any other behavior you need.