Add remote-gerrit-account-cache lib The remote-gerrit-account-cache lib provides a way to sync accounts from a remote Gerrit system. This library overrides the Accounts cache implementation from core and loads accounts from a remote Gerrit system using /accounts/ REST APIs. Upon fetching the account info from the remote Gerrit REST API, the account is saved into NoteDb and re-indexed. If the remote Gerrit REST API fails to return the account, the cache falls back to the account stored in NoteDb. Change-Id: If9a5ea1e2d2fd071e0765ebab844c8a87f3c2fbc
diff --git a/.bazelrc b/.bazelrc new file mode 100644 index 0000000..f9248ea --- /dev/null +++ b/.bazelrc
@@ -0,0 +1,2 @@ +build --workspace_status_command="python3 ./tools/workspace_status.py" +test --build_tests_only
diff --git a/.bazelversion b/.bazelversion new file mode 100644 index 0000000..91e4a9f --- /dev/null +++ b/.bazelversion
@@ -0,0 +1 @@ +6.3.2
diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..a240767 --- /dev/null +++ b/.gitignore
@@ -0,0 +1,10 @@ +/eclipse-out +/target +/.bazel_path +/.classpath +/.project +/.DS_Store +/bazel-* +*.iml +/.apt_generated/ +/.apt_generated_tests/
diff --git a/BUILD b/BUILD new file mode 100644 index 0000000..7562452 --- /dev/null +++ b/BUILD
@@ -0,0 +1,25 @@ +load("//tools/bzl:junit.bzl", "junit_tests") +load( + "//tools/bzl:plugin.bzl", + "PLUGIN_DEPS", + "PLUGIN_TEST_DEPS", + "gerrit_plugin", +) +load("@rules_java//java:defs.bzl", "java_library", "java_plugin") + +plugin_name = "remote-gerrit-account-cache" + +gerrit_plugin( + name = plugin_name, + srcs = glob(["src/main/java/**/*.java"]), + javacopts = [ + "-Werror", + "-Xlint:all", + "-Xlint:-classfile", + "-Xlint:-processing", + ], + manifest_entries = [ + "Gerrit-PluginName: " + plugin_name, + "Implementation-Title: remote-gerrit-account-cache Plugin", + ], +)
diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..11069ed --- /dev/null +++ b/LICENSE
@@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + +TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + +1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + +2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + +3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + +4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + +5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + +6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + +7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + +8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + +9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + +END OF TERMS AND CONDITIONS + +APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + +Copyright [yyyy] [name of copyright owner] + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License.
diff --git a/README.md b/README.md new file mode 100644 index 0000000..697e66c --- /dev/null +++ b/README.md
@@ -0,0 +1,139 @@ +# About + +The remote-gerrit-account-cache lib provides a way to sync accounts from +a remote Gerrit system. This library overrides the Accounts cache +implementation from core and loads accounts from a remote Gerrit +system using /accounts/ REST APIs. Upon fetching the account info from +the remote Gerrit REST API, the account is saved into NoteDb and re-indexed. +If the remote Gerrit REST API fails to return the account, the cache falls +back to the account stored in NoteDb. + +The HTTP user needs to have 'View All Accounts', 'Modify Account' and +'View Secondary Emails' Capabilities in remote gerrit site inorder to +fetch account details using /accounts/{account-id}/detail and +/accounts/{account-id}/external.ids REST APIs. + + +## Test scenarios: +#### Add new email +Add new email address for a user in the remote Gerrit site. +The new email address must be visible on the internal site either after +accounts cache expiry or flushing the accounts cache. + +#### Update preferred email +Update preferred email for a user in the remote Gerrit site. +The update must be visible on the internal site either after +accounts cache expiry or flushing the accounts cache. + +#### Delete an email +Delete an email for a user in the remote Gerrit site. +The update must be visible on the internal site either after +accounts cache expiry or flushing the accounts cache. + +#### Add a new account +Add a new account in the remote Gerrit site. The new account must +be visible on the internal site whenever the new account is +queried for. + +#### Delete an account +Delete an account in the remote Gerrit site. The internal +Gerrit site continues to return the account as it falls-back +to NoteDB when /accounts/ API fails to return an account. + +#### Accounts cache timeout +The entries in the accounts cache must be evicted after maxAge +duration reaches. + + +# How to build + +This lib can be built either standalone or in-tree. + +Example: + +``` +bazel build remote-gerrit-account-cache +``` + +The output module jar is created in: + +``` +bazel-bin/remote-gerrit-account-cache.jar +``` + +# How to install + +Copy the remote-gerrit-account-cache.jar into the `${GERRIT_SITE}/lib/` +so that it is being loaded when the Gerrit instance is started. Note +that the following configuration options need to be added. + +# Configuration + +## Section gerrit + +### gerrit.installModule + +AccountCache module which will be overriding the core AccountCache +implementation. By default, unset. + +Example: +``` +[gerrit] + installModule = com.googlesource.gerrit.plugins.remotegerritaccountcache.AccountCacheImpl$AccountCacheModule +``` + +## Section remote-gerrit-account-cache + +### remote-gerrit-account-cache.remoteGerritBaseUrl + +The remote Gerrit site base URL. By default, unset. + +Example: +``` +[remote-gerrit-account-cache] + remoteGerritBaseUrl = https://gerrit.example.com +``` + +### remote-gerrit-account-cache.httpUsername + +The remote Gerrit site HTTP username. By default, unset. + +Example: +``` +[remote-gerrit-account-cache] + httpUsername = example +``` + +### remote-gerrit-account-cache.httpPassword + +The remote Gerrit site HTTP password. By default, unset. + +Example: +``` +[remote-gerrit-account-cache] + httpPassword = *** +``` + +## Section cache + +### cache.accounts.maxAge + +Maximum age to keep an entry in the accounts cache. By default, +the entries in accounts cache expire in a day. + +Example: +``` +[cache "accounts"] + maxAge = 1d +``` + +### cache.accounts.refreshAfterWrite + +Duration after which account cache entries are eligible for asynchronous +refresh. By default, set to 23h. + +Example: +``` +[cache "accounts"] + refreshAfterWrite = 23h +```
diff --git a/WORKSPACE b/WORKSPACE new file mode 100644 index 0000000..31be08e --- /dev/null +++ b/WORKSPACE
@@ -0,0 +1,18 @@ +workspace(name = "remote-gerrit-account-cache") + +load("//:bazlets.bzl", "load_bazlets") + +load_bazlets( + commit = "f9c119e45d9a241bee720b7fbd6c7fdbc952da5f", +) + +load( + "@com_googlesource_gerrit_bazlets//:gerrit_api.bzl", + "gerrit_api", +) + +# Load release Plugin API +gerrit_api( + plugin_api_sha1 = "72a06d1253d86405c1d78a534181b9fc95f7cfa2", + version = "3.8.2-1092-g31712ad612", +)
diff --git a/bazlets.bzl b/bazlets.bzl new file mode 100644 index 0000000..f089af4 --- /dev/null +++ b/bazlets.bzl
@@ -0,0 +1,18 @@ +load("@bazel_tools//tools/build_defs/repo:git.bzl", "git_repository") + +NAME = "com_googlesource_gerrit_bazlets" + +def load_bazlets( + commit, + local_path = None): + if not local_path: + git_repository( + name = NAME, + remote = "https://gerrit.googlesource.com/bazlets", + commit = commit, + ) + else: + native.local_repository( + name = NAME, + path = local_path, + )
diff --git a/src/main/java/com/googlesource/gerrit/plugins/remotegerritaccountcache/AccountCacheImpl.java b/src/main/java/com/googlesource/gerrit/plugins/remotegerritaccountcache/AccountCacheImpl.java new file mode 100644 index 0000000..a70e33a --- /dev/null +++ b/src/main/java/com/googlesource/gerrit/plugins/remotegerritaccountcache/AccountCacheImpl.java
@@ -0,0 +1,415 @@ +// Copyright (C) 2023 The Android Open Source Project +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package com.googlesource.gerrit.plugins.remotegerritaccountcache; + +import static com.google.gerrit.server.account.AccountCacheImpl.AccountCacheModule.ACCOUNT_CACHE_MODULE; +import static com.google.gerrit.server.account.externalids.ExternalId.SCHEME_USERNAME; +import static com.google.gerrit.server.git.QueueProvider.QueueType.BATCH; + +import com.google.common.cache.CacheLoader; +import com.google.common.cache.LoadingCache; +import com.google.common.collect.ImmutableMap; +import com.google.common.collect.Sets; +import com.google.common.flogger.FluentLogger; +import com.google.common.util.concurrent.ListeningExecutorService; +import com.google.gerrit.entities.Account; +import com.google.gerrit.entities.RefNames; +import com.google.gerrit.exceptions.StorageException; +import com.google.gerrit.extensions.common.AccountDetailInfo; +import com.google.gerrit.extensions.common.AccountExternalIdInfo; +import com.google.gerrit.json.OutputFormat; +import com.google.gerrit.server.ModuleImpl; +import com.google.gerrit.server.account.AccountCache; +import com.google.gerrit.server.account.AccountConfig; +import com.google.gerrit.server.account.AccountDelta; +import com.google.gerrit.server.account.AccountState; +import com.google.gerrit.server.account.AccountsUpdate; +import com.google.gerrit.server.account.CachedAccountDetails; +import com.google.gerrit.server.account.externalids.ExternalId; +import com.google.gerrit.server.account.externalids.ExternalIdKeyFactory; +import com.google.gerrit.server.account.externalids.ExternalIds; +import com.google.gerrit.server.cache.CacheModule; +import com.google.gerrit.server.config.AllUsersName; +import com.google.gerrit.server.config.CachedPreferences; +import com.google.gerrit.server.config.DefaultPreferencesCache; +import com.google.gerrit.server.config.GerritServerConfig; +import com.google.gerrit.server.git.GitRepositoryManager; +import com.google.gerrit.server.index.IndexExecutor; +import com.google.gerrit.server.index.account.AccountIndexer; +import com.google.gerrit.server.util.time.TimeUtil; +import com.google.gson.Gson; +import com.google.gson.reflect.TypeToken; +import com.google.inject.Inject; +import com.google.inject.Provider; +import com.google.inject.Singleton; +import com.google.inject.name.Named; +import java.io.IOException; +import java.lang.reflect.Type; +import java.net.Authenticator; +import java.net.PasswordAuthentication; +import java.net.URI; +import java.net.http.HttpClient; +import java.net.http.HttpRequest; +import java.net.http.HttpResponse; +import java.time.Duration; +import java.util.ArrayList; +import java.util.Collection; +import java.util.Collections; +import java.util.List; +import java.util.Map; +import java.util.Optional; +import java.util.Set; +import java.util.concurrent.ExecutionException; +import java.util.concurrent.Future; +import java.util.function.Consumer; +import java.util.stream.Collectors; +import org.eclipse.jgit.errors.ConfigInvalidException; +import org.eclipse.jgit.lib.ObjectId; +import org.eclipse.jgit.lib.Ref; +import org.eclipse.jgit.lib.Repository; + +public class AccountCacheImpl implements AccountCache { + private static final FluentLogger logger = FluentLogger.forEnclosingClass(); + + @ModuleImpl(name = ACCOUNT_CACHE_MODULE) + public static class AccountCacheModule extends CacheModule { + @Override + protected void configure() { + persist(BYID_AND_REV_NAME, CachedAccountDetails.Key.class, CachedAccountDetails.class) + .version(2) + .keySerializer(CachedAccountDetails.Key.Serializer.INSTANCE) + .valueSerializer(CachedAccountDetails.Serializer.INSTANCE) + .loader(Loader.class) + .expireAfterWrite(Duration.ofDays(1)) + .refreshAfterWrite(Duration.ofHours(23)); + + bind(AccountCacheImpl.class); + bind(AccountCache.class).to(AccountCacheImpl.class); + } + } + + protected static class Config { + protected static final String SECTION = "remote-gerrit-account-cache"; + protected static final String REMOTE_GERRIT_BASE_URL = "remoteGerritBaseUrl"; + protected static final String HTTP_USERNAME = "httpUsername"; + protected static final String HTTP_PASSWORD = "httpPassword"; + + protected final String remoteGerritBaseUrl; + protected final String username; + protected final String password; + + @Inject + Config(@GerritServerConfig org.eclipse.jgit.lib.Config config) { + remoteGerritBaseUrl = config.getString(SECTION, null, REMOTE_GERRIT_BASE_URL); + username = config.getString(SECTION, null, HTTP_USERNAME); + password = config.getString(SECTION, null, HTTP_PASSWORD); + } + + URI getAccountDetailUri(Account.Id id) { + return URI.create(String.format("%s/a/accounts/%s/detail", remoteGerritBaseUrl, id.get())); + } + + URI getExternalIdsUri(Account.Id id) { + return URI.create( + String.format("%s/a/accounts/%s/external.ids", remoteGerritBaseUrl, id.get())); + } + } + + public static final String BYID_AND_REV_NAME = "accounts"; + private final ExternalIds externalIds; + private final LoadingCache<CachedAccountDetails.Key, CachedAccountDetails> accountDetailsCache; + private final GitRepositoryManager repoManager; + private final AllUsersName allUsersName; + private final DefaultPreferencesCache defaultPreferenceCache; + private final ExternalIdKeyFactory externalIdKeyFactory; + + @Inject + AccountCacheImpl( + ExternalIds externalIds, + @Named(BYID_AND_REV_NAME) + LoadingCache<CachedAccountDetails.Key, CachedAccountDetails> accountDetailsCache, + GitRepositoryManager repoManager, + AllUsersName allUsersName, + DefaultPreferencesCache defaultPreferenceCache, + ExternalIdKeyFactory externalIdKeyFactory) { + this.externalIds = externalIds; + this.accountDetailsCache = accountDetailsCache; + this.repoManager = repoManager; + this.allUsersName = allUsersName; + this.defaultPreferenceCache = defaultPreferenceCache; + this.externalIdKeyFactory = externalIdKeyFactory; + } + + @Override + public AccountState getEvenIfMissing(Account.Id accountId) { + return get(accountId).orElse(missing(accountId)); + } + + @Override + public Optional<AccountState> get(Account.Id accountId) { + return Optional.ofNullable(get(Collections.singleton(accountId)).getOrDefault(accountId, null)); + } + + @Override + public AccountState getFromMetaId(Account.Id id, ObjectId metaId) { + try { + CachedAccountDetails.Key key = CachedAccountDetails.Key.create(id, metaId); + + CachedAccountDetails accountDetails = accountDetailsCache.get(key); + return AccountState.forCachedAccount(accountDetails, CachedPreferences.EMPTY, externalIds); + } catch (IOException | ExecutionException e) { + throw new StorageException(e); + } + } + + @Override + public Map<Account.Id, AccountState> get(Set<Account.Id> accountIds) { + try { + try (Repository allUsers = repoManager.openRepository(allUsersName)) { + Set<CachedAccountDetails.Key> keys = + Sets.newLinkedHashSetWithExpectedSize(accountIds.size()); + for (Account.Id id : accountIds) { + Ref userRef = allUsers.exactRef(RefNames.refsUsers(id)); + if (userRef == null) { + keys.add(CachedAccountDetails.Key.create(id, ObjectId.zeroId())); + } else { + keys.add(CachedAccountDetails.Key.create(id, userRef.getObjectId())); + } + } + CachedPreferences defaultPreferences = defaultPreferenceCache.get(); + ImmutableMap.Builder<Account.Id, AccountState> result = ImmutableMap.builder(); + for (CachedAccountDetails.Key key : keys) { + try { + CachedAccountDetails cachedAccountDetails = accountDetailsCache.get(key); + result.put( + key.accountId(), + AccountState.forCachedAccount( + cachedAccountDetails, defaultPreferences, externalIds)); + } catch (Exception e) { + if (e instanceof ExecutionException + && e.getCause() instanceof AccountNotFoundException) { + continue; + } + throw e; + } + } + return result.build(); + } + } catch (Exception e) { + throw new StorageException(e); + } + } + + @Override + public Optional<AccountState> getByUsername(String username) { + try { + return externalIds + .get(externalIdKeyFactory.create(SCHEME_USERNAME, username)) + .map(e -> get(e.accountId())) + .orElseGet(Optional::empty); + } catch (IOException e) { + logger.atWarning().withCause(e).log("Cannot load AccountState for username %s", username); + return Optional.empty(); + } + } + + private AccountState missing(Account.Id accountId) { + Account.Builder account = Account.builder(accountId, TimeUtil.now()); + account.setActive(false); + return AccountState.forAccount(account.build()); + } + + @Singleton + static class Loader extends CacheLoader<CachedAccountDetails.Key, CachedAccountDetails> { + protected static final String UPDATE_MESSAGE = "Sync account via remote-gerrit-account-cache"; + + private final Gson gson = OutputFormat.JSON.newGson(); + private final AccountsUpdate.AccountsUpdateLoader accountsUpdateFactory; + private final Provider<AccountIndexer> accountIndexerProvider; + private final ListeningExecutorService executor; + private final ExternalIds externalIds; + private final Config config; + private final ExternalIdKeyFactory externalIdKeyFactory; + private final GitRepositoryManager repoManager; + private final AllUsersName allUsersName; + private final HttpClient client; + + @Inject + Loader( + @AccountsUpdate.AccountsUpdateLoader.NoReindex + AccountsUpdate.AccountsUpdateLoader accountsUpdateFactory, + Provider<AccountIndexer> accountIndexerProvider, + @IndexExecutor(BATCH) ListeningExecutorService executor, + ExternalIds externalIds, + Config config, + ExternalIdKeyFactory externalIdKeyFactory, + GitRepositoryManager repoManager, + AllUsersName allUsersName) { + this.accountsUpdateFactory = accountsUpdateFactory; + this.accountIndexerProvider = accountIndexerProvider; + this.executor = executor; + this.externalIds = externalIds; + this.config = config; + this.externalIdKeyFactory = externalIdKeyFactory; + this.repoManager = repoManager; + this.allUsersName = allUsersName; + this.client = getHttpClient(); + } + + @SuppressWarnings("unused") + @Override + public CachedAccountDetails load(CachedAccountDetails.Key key) throws Exception { + AccountDetailInfo accountInfo = getAccountFromRemoteSite(key.accountId()); + if (accountInfo == null) { + try (Repository repo = repoManager.openRepository(allUsersName)) { + return getAccountDetailsFromNoteDb(repo, key); + } + } + Account.Id accountId = Account.id(accountInfo._accountId); + Collection<ExternalId> extIds = new ArrayList<>(); + Collection<ExternalId> oldExtIds = new ArrayList<>(); + try { + extIds.addAll(getExternalIdsFromRemoteSite(accountId)); + oldExtIds.addAll(externalIds.byAccount(accountId)); + } catch (Exception ignore) { + } + + Consumer<AccountDelta.Builder> update = + u -> + u.setFullName(accountInfo.name) + .setDisplayName(accountInfo.displayName) + .setPreferredEmail(accountInfo.email) + .setStatus(accountInfo.status) + .deleteExternalIds(oldExtIds) + .addExternalIds(extIds); + + try (Repository repo = repoManager.openRepository(allUsersName)) { + Ref userRef = repo.exactRef(RefNames.refsUsers(key.accountId())); + if (userRef != null) { + accountsUpdateFactory.createWithServerIdent().update(UPDATE_MESSAGE, accountId, update); + } else { + accountsUpdateFactory.createWithServerIdent().insert(UPDATE_MESSAGE, accountId, update); + } + logger.atInfo().log("Account updated: %s", accountId); + Future<?> ignore = + executor.submit( + () -> { + try { + accountIndexerProvider.get().reindexIfStale(accountId); + logger.atInfo().log("Reindexing is done for account: %s", accountId); + } catch (Exception e) { + logger.atWarning().log( + "Reindexing for account: %s failed with error %s", + accountId, e.getMessage()); + } + }); + return getAccountDetailsFromNoteDb(repo, key); + } + } + + protected CachedAccountDetails getAccountDetailsFromNoteDb( + Repository repo, CachedAccountDetails.Key key) + throws ConfigInvalidException, IOException, AccountNotFoundException { + Ref userRef = repo.exactRef(RefNames.refsUsers(key.accountId())); + if (userRef == null) { + throw new AccountNotFoundException(key.accountId() + " not found"); + } + AccountConfig cfg = + new AccountConfig(key.accountId(), allUsersName, repo).load(userRef.getObjectId()); + Account account = + cfg.getLoadedAccount() + .orElseThrow(() -> new AccountNotFoundException(key.accountId() + " not found")); + return CachedAccountDetails.create( + account, cfg.getProjectWatches(), cfg.asCachedPreferences()); + } + + protected AccountDetailInfo getAccountFromRemoteSite(Account.Id accountId) { + HttpRequest request = + HttpRequest.newBuilder().uri(config.getAccountDetailUri(accountId)).GET().build(); + try { + HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString()); + if (response.statusCode() == 200) { + Type type = new TypeToken<AccountDetailInfo>() {}.getType(); + return gson.fromJson(response.body(), type); + } + logger.atSevere().log( + "Failed to fetch account from remote Gerrit %s, %s", accountId, response.body()); + } catch (IOException | InterruptedException e) { + logger.atSevere().withCause(e).log("Failed to fetch account from remote Gerrit"); + } + return null; + } + + public List<ExternalId> getExternalIdsFromRemoteSite(Account.Id accountId) + throws AccountNotFoundInRemoteGerritException { + HttpRequest request = + HttpRequest.newBuilder().uri(config.getExternalIdsUri(accountId)).GET().build(); + + try { + HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString()); + if (response.statusCode() == 200) { + Type type = new TypeToken<List<AccountExternalIdInfo>>() {}.getType(); + List<AccountExternalIdInfo> accountExternalIdInfos = gson.fromJson(response.body(), type); + return accountExternalIdInfos.stream() + .map( + i -> + ExternalId.create( + externalIdKeyFactory.parse(i.identity), + accountId, + i.emailAddress, + null, + null)) + .collect(Collectors.toList()); + } + logger.atSevere().log( + "Failed to fetch remote ids for account %s, %s", accountId, response.body()); + } catch (IOException | InterruptedException e) { + logger.atSevere().withCause(e).log("Failed to fetch remote ids for account %s", accountId); + } + throw new AccountNotFoundInRemoteGerritException( + String.format("%s not found in remote Gerrit", accountId)); + } + + protected HttpClient getHttpClient() { + return HttpClient.newBuilder() + .authenticator( + new Authenticator() { + @Override + protected PasswordAuthentication getPasswordAuthentication() { + return new PasswordAuthentication(config.username, config.password.toCharArray()); + } + }) + .build(); + } + } + + /** Signals that the account was not found in the primary storage. */ + private static class AccountNotFoundException extends Exception { + private static final long serialVersionUID = 1L; + + public AccountNotFoundException(String message) { + super(message); + } + } + + /** Signals that the account was not found in the remote Gerrit. */ + private static class AccountNotFoundInRemoteGerritException extends Exception { + private static final long serialVersionUID = 1L; + + public AccountNotFoundInRemoteGerritException(String message) { + super(message); + } + } +}
diff --git a/tools/BUILD b/tools/BUILD new file mode 100644 index 0000000..1fa2160 --- /dev/null +++ b/tools/BUILD
@@ -0,0 +1 @@ +# Empty file - bazel treat directories with BUILD file as a package \ No newline at end of file
diff --git a/tools/bzl/BUILD b/tools/bzl/BUILD new file mode 100644 index 0000000..f40498e --- /dev/null +++ b/tools/bzl/BUILD
@@ -0,0 +1 @@ +# Empty BUILD file, needed by Bazel.
diff --git a/tools/bzl/classpath.bzl b/tools/bzl/classpath.bzl new file mode 100644 index 0000000..c921d01 --- /dev/null +++ b/tools/bzl/classpath.bzl
@@ -0,0 +1,6 @@ +load( + "@com_googlesource_gerrit_bazlets//tools:classpath.bzl", + _classpath_collector = "classpath_collector", +) + +classpath_collector = _classpath_collector
diff --git a/tools/bzl/junit.bzl b/tools/bzl/junit.bzl new file mode 100644 index 0000000..97307bd --- /dev/null +++ b/tools/bzl/junit.bzl
@@ -0,0 +1,6 @@ +load( + "@com_googlesource_gerrit_bazlets//tools:junit.bzl", + _junit_tests = "junit_tests", +) + +junit_tests = _junit_tests
diff --git a/tools/bzl/maven_jar.bzl b/tools/bzl/maven_jar.bzl new file mode 100644 index 0000000..ed1504d --- /dev/null +++ b/tools/bzl/maven_jar.bzl
@@ -0,0 +1,4 @@ +load("@com_googlesource_gerrit_bazlets//tools:maven_jar.bzl", _gerrit = "GERRIT", _maven_jar = "maven_jar") + +maven_jar = _maven_jar +GERRIT = _gerrit
diff --git a/tools/bzl/plugin.bzl b/tools/bzl/plugin.bzl new file mode 100644 index 0000000..4d2dbdd --- /dev/null +++ b/tools/bzl/plugin.bzl
@@ -0,0 +1,10 @@ +load( + "@com_googlesource_gerrit_bazlets//:gerrit_plugin.bzl", + _gerrit_plugin = "gerrit_plugin", + _plugin_deps = "PLUGIN_DEPS", + _plugin_test_deps = "PLUGIN_TEST_DEPS", +) + +gerrit_plugin = _gerrit_plugin +PLUGIN_DEPS = _plugin_deps +PLUGIN_TEST_DEPS = _plugin_test_deps
diff --git a/tools/eclipse/BUILD b/tools/eclipse/BUILD new file mode 100644 index 0000000..8811f30 --- /dev/null +++ b/tools/eclipse/BUILD
@@ -0,0 +1,9 @@ +load("//tools/bzl:plugin.bzl", "PLUGIN_DEPS") +load("//tools/bzl:classpath.bzl", "classpath_collector") + +classpath_collector( + name = "main_classpath_collect", + deps = PLUGIN_DEPS + [ + "//:remote-gerrit-account-cache__plugin", + ], +)
diff --git a/tools/eclipse/project.sh b/tools/eclipse/project.sh new file mode 100755 index 0000000..45bd4b1 --- /dev/null +++ b/tools/eclipse/project.sh
@@ -0,0 +1,15 @@ +#!/bin/bash +# Copyright (C) 2023 The Android Open Source Project +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +`bazel query @com_googlesource_gerrit_bazlets//tools/eclipse:project --output location | sed s/BUILD:.*//`project.py -n remote-gerrit-account-cache -r .
diff --git a/tools/workspace_status.py b/tools/workspace_status.py new file mode 100644 index 0000000..5c16612 --- /dev/null +++ b/tools/workspace_status.py
@@ -0,0 +1,31 @@ +#!/usr/bin/env python3 + +# This script will be run by bazel when the build process starts to +# generate key-value information that represents the status of the +# workspace. The output should be like +# +# KEY1 VALUE1 +# KEY2 VALUE2 +# +# If the script exits with non-zero code, it's considered as a failure +# and the output will be discarded. + +from __future__ import print_function +import subprocess +import sys + +CMD = ['git', 'describe', '--always', '--match', 'v[0-9].*', '--dirty'] + + +def revision(): + try: + return subprocess.check_output(CMD).strip().decode("utf-8") + except OSError as err: + print('could not invoke git: %s' % err, file=sys.stderr) + sys.exit(1) + except subprocess.CalledProcessError as err: + print('error using git: %s' % err, file=sys.stderr) + sys.exit(1) + + +print("STABLE_BUILD_REMOTE-GERRIT-ACCOUNT-CACHE_LABEL %s" % revision())