pwpolicy.js revision 4f4573637d598fab1818164e79e51a079494b33f
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle/*
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * The contents of this file are subject to the terms of the Common Development and
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * Distribution License (the License). You may not use this file except in compliance with the
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * License.
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle *
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * specific language governing permission and limitations under the License.
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle *
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * When distributing Covered Software, include this CDDL Header Notice in each file and include
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * Header, with the fields enclosed by brackets [] replaced by your own identifying
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * information: "Portions copyright [year] [name of copyright owner]".
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle *
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle * Copyright 2015 ForgeRock AS.
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle */
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle/*global addPolicy, request, openidm */
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad KienleaddPolicy({
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle "policyId" : "is-new",
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle "policyExec" : "isNew",
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle "policyRequirements" : ["IS_NEW"]
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle});
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienlefunction isNew(fullObject, value, params, property) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle var historyLength, fieldHistory, currentObject, lastFieldValues, i;
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Don't enforce this policy if the resource ends with "/*", which indicates that this is a create with a
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // server-supplied id
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (!request.resourcePath || request.resourcePath.match('/\\*$')) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Read the resource
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle currentObject = openidm.read(request.resourcePath);
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Don't enforce this policy if the resource being evaluated wasn't found. Happens in the case of a create with a
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // client-supplied id.
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (currentObject === null) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Decrypt the "fieldHistory" field.
4f4573637d598fab1818164e79e51a079494b33fChad Kienle fieldHistory = currentObject.fieldHistory;
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
4f4573637d598fab1818164e79e51a079494b33fChad Kienle // Don't enforce this policy if there is no history object available
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (fieldHistory[property] === null || fieldHistory[property] === undefined) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Get the current field value
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (currentObject[property] !== null && currentObject[property] !== undefined &&
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle openidm.isEncrypted(currentObject[property])) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle currentObject[property] = openidm.decrypt(currentObject[property]);
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Don't enforce this policy if the password hasn't changed
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (currentObject[property] === value) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Get the last field values
4f4573637d598fab1818164e79e51a079494b33fChad Kienle lastFieldValues = fieldHistory[property];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle if (params.historyLength !== undefined) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle historyLength = params.historyLength;
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle } else {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle historyLength = lastFieldValues.length;
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle numOfFields = lastFieldValues.length;
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle // Check if the current value matches any previous values
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle for(i = numOfFields - 1; i >= (numOfFields - historyLength) && i >= 0; i--) {
4f4573637d598fab1818164e79e51a079494b33fChad Kienle if ((openidm.isHashed(lastFieldValues[i]) && openidm.matches(value, lastFieldValues[i]))
4f4573637d598fab1818164e79e51a079494b33fChad Kienle || (lastFieldValues[i] === value)) {
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [{"policyRequirement": "IS_NEW"}];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle }
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle return [];
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle
25b1abfbb74fea0ddfcf186f7be3ef5f8c095790Chad Kienle}