Merge 0.9.14 changes back to master.

This commit is contained in:
Nick Couchman
2017-12-06 10:12:32 -05:00
2 changed files with 634 additions and 443 deletions

View File

@@ -1,468 +1,648 @@
/* --
* Licensed to the Apache Software Foundation (ASF) under one -- Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file -- or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information -- distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file -- regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the -- to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance -- "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at -- with the License. You may obtain a copy of the License at
* --
* http://www.apache.org/licenses/LICENSE-2.0 -- http://www.apache.org/licenses/LICENSE-2.0
* --
* Unless required by applicable law or agreed to in writing, -- Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an -- software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY -- "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the -- KIND, either express or implied. See the License for the
* specific language governing permissions and limitations -- specific language governing permissions and limitations
* under the License. -- under the License.
*/ --
/** --
* Turn on ANSI_NULLS for the entire DB to make it ISO-compliant. -- Connection group types
*/ --
ALTER DATABASE CURRENT SET ANSI_NULLS ON;
CREATE RULE [guacamole_connection_group_type_list] AS @list IN (
'ORGANIZATIONAL',
'BALANCING'
);
GO GO
/** CREATE TYPE [guacamole_connection_group_type] FROM [nvarchar](16) NOT NULL;
* Turn on QUOTED_IDENTIFIER for the entire DB. EXEC sp_bindrule
*/ 'guacamole_connection_group_type_list',
ALTER DATABASE CURRENT SET QUOTED_IDENTIFIER ON; 'guacamole_connection_group_type';
GO GO
/** --
* List for permission data type. -- Object permission types
*/ --
CREATE RULE [guacamole_permission_list]
AS CREATE RULE [guacamole_object_permission_list] AS @list IN (
@list IN ('READ','UPDATE','DELETE','ADMINISTER'); 'READ',
'UPDATE',
'DELETE',
'ADMINISTER'
);
GO GO
/** CREATE TYPE [guacamole_object_permission] FROM [nvarchar](16) NOT NULL;
* List for system permission data type. EXEC sp_bindrule
*/ 'guacamole_object_permission_list',
CREATE RULE [guacamole_system_permission_list] 'guacamole_object_permission';
AS GO
@list IN ('CREATE_CONNECTION',
--
-- System permission types
--
CREATE RULE [guacamole_system_permission_list] AS @list IN (
'CREATE_CONNECTION',
'CREATE_CONNECTION_GROUP', 'CREATE_CONNECTION_GROUP',
'CREATE_SHARING_PROFILE', 'CREATE_SHARING_PROFILE',
'CREATE_USER', 'CREATE_USER',
'ADMINISTER'); 'ADMINISTER'
);
GO GO
/**
* The permission data type.
*/
CREATE TYPE [guacamole_permission] FROM [nvarchar](10) NOT NULL;
EXEC sp_bindrule 'guacamole_permission_list','guacamole_permission';
/**
* The system permission data type.
*/
CREATE TYPE [guacamole_system_permission] FROM [nvarchar](32) NOT NULL; CREATE TYPE [guacamole_system_permission] FROM [nvarchar](32) NOT NULL;
EXEC sp_bindrule 'guacamole_system_permission_list','guacamole_system_permission'; EXEC sp_bindrule
'guacamole_system_permission_list',
'guacamole_system_permission';
GO GO
/** --
* The connection_group table stores organizational and balancing groups. -- Guacamole proxy (guacd) encryption methods.
*/ --
CREATE RULE [guacamole_proxy_encryption_method_list] AS @list IN (
'NONE',
'SSL'
);
GO
CREATE TYPE [guacamole_proxy_encryption_method] FROM [nvarchar](8) NOT NULL;
EXEC sp_bindrule
'guacamole_proxy_encryption_method_list',
'guacamole_proxy_encryption_method';
GO
--
-- Table of connection groups. Each connection group has a name, type, and
-- optional parent connection group.
--
CREATE TABLE [guacamole_connection_group] ( CREATE TABLE [guacamole_connection_group] (
[connection_group_id] [int] IDENTITY(1,1) NOT NULL, [connection_group_id] [int] IDENTITY(1,1) NOT NULL,
[parent_id] [int] NULL, [parent_id] [int],
[connection_group_name] [nvarchar](128) NOT NULL, [connection_group_name] [nvarchar](128) NOT NULL,
[type] [nvarchar](32) NOT NULL, [type] [guacamole_connection_group_type]
[max_connections] [int] NULL, NOT NULL DEFAULT 'ORGANIZATIONAL',
[max_connections_per_user] [int] NULL,
[enable_session_affinity] [bit] NOT NULL,
CONSTRAINT [PK_guacmaole_connection_group] PRIMARY KEY CLUSTERED -- Concurrency limits
([connection_group_id] ASC) ON [PRIMARY] [max_connections] [int],
) ON [PRIMARY]; [max_connections_per_user] [int],
[enable_session_affinity] [bit] NOT NULL DEFAULT 0,
/** CONSTRAINT [PK_guacamole_connection_group]
* Foreign keys for connection_group table. PRIMARY KEY CLUSTERED ([connection_group_id]),
*/
ALTER TABLE [guacamole_connection_group]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_group_connection_group_id] FOREIGN KEY([parent_id])
REFERENCES [guacamole_connection_group] ([connection_group_id]);
ALTER TABLE [guacamole_connection_group]
CHECK CONSTRAINT [FK_guacamole_connection_group_connection_group_id];
ALTER TABLE [guacamole_connection_group]
WITH CHECK ADD CONSTRAINT [CK_guacamole_connection_group_type]
CHECK (([type]='BALANCING' OR [type]='ORGANIZATIONAL'));
ALTER TABLE [guacamole_connection_group]
CHECK CONSTRAINT [CK_guacamole_connection_group_type];
/** CONSTRAINT [AK_guacamole_connection_group_name_parent]
* Default values for connection_group table. UNIQUE ([connection_group_name], [parent_id]),
*/
ALTER TABLE [guacamole_connection_group] CONSTRAINT [FK_guacamole_connection_group_parent_id]
ADD CONSTRAINT [DF_guacamole_connection_group_type] DEFAULT (N'ORGANIZATIONAL') FOR [type]; FOREIGN KEY ([parent_id])
ALTER TABLE [guacamole_connection_group] REFERENCES [guacamole_connection_group] ([connection_group_id])
ADD CONSTRAINT [DF_guacamole_connection_group_enable_session_affinity] DEFAULT ((0)) FOR [enable_session_affinity]; -- ON DELETE CASCADE handled by guacamole_delete_connection_group trigger
);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_group_parent_id]
ON [guacamole_connection_group] ([parent_id]);
GO GO
/** --
* The connection table, for storing connections and attributes. -- Table of connections. Each connection has a name, protocol, and
*/ -- associated set of parameters. A connection may belong to a connection group.
--
CREATE TABLE [guacamole_connection] ( CREATE TABLE [guacamole_connection] (
[connection_id] [int] IDENTITY(1,1) NOT NULL, [connection_id] [int] IDENTITY(1,1) NOT NULL,
[connection_name] [nvarchar](128) NOT NULL, [connection_name] [nvarchar](128) NOT NULL,
[parent_id] [int] NULL, [parent_id] [int],
[protocol] [nvarchar](32) NOT NULL, [protocol] [nvarchar](32) NOT NULL,
[proxy_port] [int] NULL,
[proxy_hostname] [nvarchar](512) NULL,
[proxy_encryption_method] [nvarchar](4) NULL,
[max_connections] [int] NULL,
[max_connections_per_user] [int] NULL,
[connection_weight] [int] NULL,
[failover_only] [bit] NOT NULL,
CONSTRAINT [PK_guacamole_connection] PRIMARY KEY CLUSTERED -- Concurrency limits
([connection_id] ASC) ON [PRIMARY] [max_connections] [int],
) ON [PRIMARY]; [max_connections_per_user] [int],
ALTER TABLE [guacamole_connection] -- Connection Weight
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_connection_group] FOREIGN KEY([parent_id]) [connection_weight] [int],
REFERENCES [guacamole_connection_group] ([connection_group_id]); [failover_only] [bit] NOT NULL DEFAULT 0,
ALTER TABLE [guacamole_connection]
CHECK CONSTRAINT [FK_guacamole_connection_connection_group]; -- Guacamole proxy (guacd) overrides
ALTER TABLE [guacamole_connection] [proxy_port] [int],
WITH CHECK ADD CONSTRAINT [CK_proxy_encryption_method] [proxy_hostname] [nvarchar](512),
CHECK (([proxy_encryption_method]='SSL' OR [proxy_encryption_method]='NONE')); [proxy_encryption_method] [guacamole_proxy_encryption_method],
ALTER TABLE [guacamole_connection]
CHECK CONSTRAINT [CK_proxy_encryption_method]; CONSTRAINT [PK_guacamole_connection]
ALTER TABLE [guacamole_connection] PRIMARY KEY CLUSTERED ([connection_id]),
ADD CONSTRAINT [DF_guacamole_connection_failover_only] DEFAULT ((0)) FOR [failover_only];
CONSTRAINT [AK_guacamole_connection_name_parent]
UNIQUE ([connection_name], [parent_id]),
CONSTRAINT [FK_guacamole_connection_parent_id]
FOREIGN KEY ([parent_id])
REFERENCES [guacamole_connection_group] ([connection_group_id])
-- ON DELETE CASCADE handled by guacamole_delete_connection_group trigger
);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_parent_id]
ON [guacamole_connection] ([parent_id]);
GO GO
/** --
* The user table stores user accounts, passwords, and properties. -- Table of users. Each user has a unique username and a hashed password
*/ -- with corresponding salt. Although the authentication system will always set
-- salted passwords, other systems may set unsalted passwords by simply not
-- providing the salt.
--
CREATE TABLE [guacamole_user] ( CREATE TABLE [guacamole_user] (
[user_id] [int] IDENTITY(1,1) NOT NULL, [user_id] [int] IDENTITY(1,1) NOT NULL,
-- Username and optionally-salted password
[username] [nvarchar](128) NOT NULL, [username] [nvarchar](128) NOT NULL,
[password_hash] [binary](32) NOT NULL, [password_hash] [binary](32) NOT NULL,
[password_salt] [binary](32) NULL, [password_salt] [binary](32),
[password_date] [datetime] NOT NULL, [password_date] [datetime] NOT NULL,
[disabled] [bit] NOT NULL,
[expired] [bit] NOT NULL,
[access_window_start] [time](7) NULL,
[access_window_end] [time](7) NULL,
[valid_from] [date] NULL,
[valid_until] [date] NULL,
[timezone] [nvarchar](64) NULL,
[full_name] [nvarchar](256) NULL,
[email_address] [nvarchar](256) NULL,
[organization] [nvarchar](256) NULL,
[organizational_role] [nvarchar](256) NULL,
CONSTRAINT [PK_guacamole_user] PRIMARY KEY CLUSTERED -- Account disabled/expired status
([user_id] ASC) ON [PRIMARY] [disabled] [bit] NOT NULL DEFAULT 0,
) ON [PRIMARY]; [expired] [bit] NOT NULL DEFAULT 0,
/** -- Time-based access restriction
* Defaults for user table [access_window_start] [time](7),
*/ [access_window_end] [time](7),
ALTER TABLE [guacamole_user]
ADD CONSTRAINT [DF_guacamole_user_disabled] DEFAULT ((0)) FOR [disabled]; -- Date-based access restriction
ALTER TABLE [guacamole_user] [valid_from] [date],
ADD CONSTRAINT [DF_guacamole_user_expired] DEFAULT ((0)) FOR [expired]; [valid_until] [date],
-- Timezone used for all date/time comparisons and interpretation
[timezone] [nvarchar](64),
-- Profile information
[full_name] [nvarchar](256),
[email_address] [nvarchar](256),
[organization] [nvarchar](256),
[organizational_role] [nvarchar](256),
CONSTRAINT [PK_guacamole_user]
PRIMARY KEY CLUSTERED ([user_id]),
CONSTRAINT [AK_guacamole_user_username]
UNIQUE ([username])
);
GO GO
/** --
* The sharing_profile table stores profiles that allow -- Table of sharing profiles. Each sharing profile has a name, associated set
* connections to be shared amongst multiple users. -- of parameters, and a primary connection. The primary connection is the
*/ -- connection that the sharing profile shares, and the parameters dictate the
-- restrictions/features which apply to the user joining the connection via the
-- sharing profile.
--
CREATE TABLE [guacamole_sharing_profile] ( CREATE TABLE [guacamole_sharing_profile] (
[sharing_profile_id] [int] IDENTITY(1,1) NOT NULL, [sharing_profile_id] [int] IDENTITY(1,1) NOT NULL,
[sharing_profile_name] [nvarchar](128) NOT NULL, [sharing_profile_name] [nvarchar](128) NOT NULL,
[primary_connection_id] [int] NOT NULL, [primary_connection_id] [int] NOT NULL,
CONSTRAINT [PK_guacamole_sharing_profile] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_sharing_profile]
([sharing_profile_id] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([sharing_profile_id]),
) ON [PRIMARY];
/** CONSTRAINT [AK_guacamole_sharing_profile_name_primary_connection]
* Foreign keys for sharing_profile table. UNIQUE ([sharing_profile_name], [primary_connection_id]),
*/
ALTER TABLE [guacamole_sharing_profile] CONSTRAINT [FK_guacamole_sharing_profile_primary_connection_id]
WITH CHECK ADD CONSTRAINT [FK_guacamole_sharing_profile_connection] FOREIGN KEY([primary_connection_id]) FOREIGN KEY ([primary_connection_id])
REFERENCES [guacamole_connection] ([connection_id]) REFERENCES [guacamole_connection] ([connection_id])
ON UPDATE CASCADE -- ON DELETE CASCADE handled by guacamole_delete_connection trigger
ON DELETE CASCADE;
ALTER TABLE [guacamole_sharing_profile] );
CHECK CONSTRAINT [FK_guacamole_sharing_profile_connection];
CREATE NONCLUSTERED INDEX [IX_guacamole_sharing_profile_primary_connection_id]
ON [guacamole_sharing_profile] ([primary_connection_id]);
GO GO
/** --
* The connection_parameter table stores parameters for -- Table of connection parameters. Each parameter is simply a name/value pair
* connection objects. -- associated with a connection.
*/ --
CREATE TABLE [guacamole_connection_parameter] ( CREATE TABLE [guacamole_connection_parameter] (
[connection_id] [int] NOT NULL, [connection_id] [int] NOT NULL,
[parameter_name] [nvarchar](128) NOT NULL, [parameter_name] [nvarchar](128) NOT NULL,
[parameter_value] [nvarchar](4000) NOT NULL, [parameter_value] [nvarchar](4000) NOT NULL,
CONSTRAINT [PK_guacamole_connection_parameter] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_connection_parameter]
([connection_id] ASC, [parameter_name] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([connection_id], [parameter_name]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_connection_parameter_connection_id]
* Foreign keys for the connection_parameter table. FOREIGN KEY ([connection_id])
*/
ALTER TABLE [guacamole_connection_parameter]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_parameter_connection] FOREIGN KEY([connection_id])
REFERENCES [guacamole_connection] ([connection_id]) REFERENCES [guacamole_connection] ([connection_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_connection_parameter] );
CHECK CONSTRAINT [FK_guacamole_connection_parameter_connection];
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_parameter_connection_id]
ON [guacamole_connection_parameter] ([connection_id]);
GO GO
/** --
* The sharing_profile_parameter table stores parameters -- Table of sharing profile parameters. Each parameter is simply
* for sharing_profile objects. -- name/value pair associated with a sharing profile. These parameters dictate
*/ -- the restrictions/features which apply to the user joining the associated
-- connection via the sharing profile.
--
CREATE TABLE [guacamole_sharing_profile_parameter] ( CREATE TABLE [guacamole_sharing_profile_parameter] (
[sharing_profile_id] [int] NOT NULL, [sharing_profile_id] [int] NOT NULL,
[parameter_name] [nvarchar](128) NOT NULL, [parameter_name] [nvarchar](128) NOT NULL,
[parameter_value] [nvarchar](4000) NOT NULL, [parameter_value] [nvarchar](4000) NOT NULL,
CONSTRAINT [PK_guacamole_sharing_profile_parameter] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_sharing_profile_parameter]
([sharing_profile_id] ASC, [parameter_name] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([sharing_profile_id], [parameter_name]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_sharing_profile_parameter_connection_id]
* Foreign keys for the sharing_profile_parameter FOREIGN KEY ([sharing_profile_id])
* table.
*/
ALTER TABLE [guacamole_sharing_profile_parameter]
WITH CHECK ADD CONSTRAINT [FK_guacamole_sharing_profile_parameter_sharing_profile] FOREIGN KEY([sharing_profile_id])
REFERENCES [guacamole_sharing_profile] ([sharing_profile_id]) REFERENCES [guacamole_sharing_profile] ([sharing_profile_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_sharing_profile_parameter] );
CHECK CONSTRAINT [FK_guacamole_sharing_profile_parameter_sharing_profile];
CREATE NONCLUSTERED INDEX [IX_guacamole_sharing_profile_parameter_sharing_profile_id]
ON [guacamole_sharing_profile_parameter] ([sharing_profile_id]);
GO GO
/** --
* The connection_permission table stores permission -- Table of connection permissions. Each connection permission grants a user
* mappings for connection objects. -- specific access to a connection.
*/ --
CREATE TABLE [guacamole_connection_permission] ( CREATE TABLE [guacamole_connection_permission] (
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
[connection_id] [int] NOT NULL, [connection_id] [int] NOT NULL,
[permission] [guacamole_permission] NOT NULL, [permission] [guacamole_object_permission] NOT NULL,
CONSTRAINT [PK_guacamole_connection_permission] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_connection_permission]
([user_id] ASC, [connection_id] ASC, [permission] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([user_id], [connection_id], [permission]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_connection_permission_connection_id]
* Foreign keys for the connection_permission table. FOREIGN KEY ([connection_id])
*/
ALTER TABLE [guacamole_connection_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_permission_connection1] FOREIGN KEY([connection_id])
REFERENCES [guacamole_connection] ([connection_id]) REFERENCES [guacamole_connection] ([connection_id])
ON UPDATE CASCADE ON DELETE CASCADE,
ON DELETE CASCADE;
ALTER TABLE [guacamole_connection_permission] CONSTRAINT [FK_guacamole_connection_permission_user_id]
CHECK CONSTRAINT [FK_guacamole_connection_permission_connection1]; FOREIGN KEY ([user_id])
ALTER TABLE [guacamole_connection_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_permission_user1] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_connection_permission] );
CHECK CONSTRAINT [FK_guacamole_connection_permission_user1];
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_permission_connection_id]
ON [guacamole_connection_permission] ([connection_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_permission_user_id]
ON [guacamole_connection_permission] ([user_id]);
GO GO
/** --
* The connection_group_permission table stores permission mappings for -- Table of connection group permissions. Each group permission grants a user
* connection_group objects. -- specific access to a connection group.
*/ --
CREATE TABLE [guacamole_connection_group_permission] ( CREATE TABLE [guacamole_connection_group_permission] (
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
[connection_group_id] [int] NOT NULL, [connection_group_id] [int] NOT NULL,
[permission] [guacamole_permission] NOT NULL, [permission] [guacamole_object_permission] NOT NULL,
CONSTRAINT [PK_guacamole_connection_group_permission] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_connection_group_permission]
([user_id] ASC, [connection_group_id] ASC, [permission] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([user_id], [connection_group_id], [permission]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_connection_group_permission_connection_group_id]
* Foreign keys for the connection_group_permission table. FOREIGN KEY ([connection_group_id])
*/
ALTER TABLE [guacamole_connection_group_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_group_permission_connection_group] FOREIGN KEY([connection_group_id])
REFERENCES [guacamole_connection_group] ([connection_group_id]) REFERENCES [guacamole_connection_group] ([connection_group_id])
ON UPDATE CASCADE ON DELETE CASCADE,
ON DELETE CASCADE;
ALTER TABLE [guacamole_connection_group_permission] CONSTRAINT [FK_guacamole_connection_group_permission_user_id]
CHECK CONSTRAINT [FK_guacamole_connection_group_permission_connection_group]; FOREIGN KEY ([user_id])
ALTER TABLE [guacamole_connection_group_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_group_permission_user] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_connection_group_permission] );
CHECK CONSTRAINT [FK_guacamole_connection_group_permission_user];
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_group_permission_connection_group_id]
ON [guacamole_connection_group_permission] ([connection_group_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_group_permission_user_id]
ON [guacamole_connection_group_permission] ([user_id]);
GO GO
/** --
* The sharing_profile_permission table stores permission -- Table of sharing profile permissions. Each sharing profile permission grants
* mappings for sharing_profile objects. -- a user specific access to a sharing profile.
*/ --
CREATE TABLE [guacamole_sharing_profile_permission] ( CREATE TABLE [guacamole_sharing_profile_permission] (
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
[sharing_profile_id] [int] NOT NULL, [sharing_profile_id] [int] NOT NULL,
[permission] [guacamole_permission] NOT NULL, [permission] [guacamole_object_permission] NOT NULL,
CONSTRAINT [PK_guacamole_sharing_profile_permission] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_sharing_profile_permission]
([user_id] ASC, [sharing_profile_id] ASC, [permission] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([user_id], [sharing_profile_id], [permission]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_sharing_profile_permission_sharing_profile_id]
* Foreign keys for the sharing_profile_permission table. FOREIGN KEY ([sharing_profile_id])
*/
ALTER TABLE [guacamole_sharing_profile_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_sharing_profile_permission_sharing_profile] FOREIGN KEY([sharing_profile_id])
REFERENCES [guacamole_sharing_profile] ([sharing_profile_id]) REFERENCES [guacamole_sharing_profile] ([sharing_profile_id])
ON UPDATE CASCADE ON DELETE CASCADE,
ON DELETE CASCADE;
ALTER TABLE [guacamole_sharing_profile_permission] CONSTRAINT [FK_guacamole_sharing_profile_permission_user_id]
CHECK CONSTRAINT [FK_guacamole_sharing_profile_permission_sharing_profile]; FOREIGN KEY ([user_id])
ALTER TABLE [guacamole_sharing_profile_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_sharing_profile_permission_user] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_sharing_profile_permission] );
CHECK CONSTRAINT [FK_guacamole_sharing_profile_permission_user];
CREATE NONCLUSTERED INDEX [IX_guacamole_sharing_profile_permission_sharing_profile_id]
ON [guacamole_sharing_profile_permission] ([sharing_profile_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_sharing_profile_permission_user_id]
ON [guacamole_sharing_profile_permission] ([user_id]);
GO GO
/** --
* The system_permission table stores permission mappings -- Table of system permissions. Each system permission grants a user a
* for system-level operations. -- system-level privilege of some kind.
*/ --
CREATE TABLE [guacamole_system_permission] ( CREATE TABLE [guacamole_system_permission] (
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
[permission] [guacamole_system_permission] NOT NULL, [permission] [guacamole_system_permission] NOT NULL,
CONSTRAINT [PK_guacamole_system_permission] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_system_permission]
([user_id] ASC, [permission] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([user_id], [permission]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_system_permission_user_id]
* Foreign keys for system_permission table. FOREIGN KEY ([user_id])
*/
ALTER TABLE [guacamole_system_permission]
WITH CHECK ADD CONSTRAINT [FK_guacamole_system_permission_user] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_system_permission] );
CHECK CONSTRAINT [FK_guacamole_system_permission_user];
CREATE NONCLUSTERED INDEX [IX_guacamole_system_permission_user_id]
ON [guacamole_system_permission] ([user_id]);
GO GO
/** --
* The user_permission table stores permission mappings -- Table of user permissions. Each user permission grants a user access to
* for users to other users. -- another user (the "affected" user) for a specific type of operation.
*/ --
CREATE TABLE [guacamole_user_permission] ( CREATE TABLE [guacamole_user_permission] (
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
[affected_user_id] [int] NOT NULL, [affected_user_id] [int] NOT NULL,
[permission] [guacamole_permission] NOT NULL, [permission] [guacamole_object_permission] NOT NULL,
CONSTRAINT [PK_guacamole_user_permission] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_user_permission]
([user_id] ASC, [affected_user_id] ASC, [permission] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([user_id], [affected_user_id], [permission]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_user_permission_affected_user_id]
* Foreign keys for user_permission table. FOREIGN KEY ([affected_user_id])
*/ REFERENCES [guacamole_user] ([user_id]),
ALTER TABLE [guacamole_user_permission] -- ON DELETE CASCADE handled by guacamole_delete_user trigger
WITH CHECK ADD CONSTRAINT [FK_guacamole_user_permission_user] FOREIGN KEY([user_id])
CONSTRAINT [FK_guacamole_user_permission_user_id]
FOREIGN KEY ([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE -- ON DELETE CASCADE handled by guacamole_delete_user trigger
ON DELETE CASCADE;
ALTER TABLE [guacamole_user_permission] );
CHECK CONSTRAINT [FK_guacamole_user_permission_user];
ALTER TABLE [guacamole_user_permission] CREATE NONCLUSTERED INDEX [IX_guacamole_user_permission_user_id]
WITH CHECK ADD CONSTRAINT [FK_guacamole_user_permission_user1] FOREIGN KEY([affected_user_id]) ON [guacamole_user_permission] ([user_id]);
REFERENCES [guacamole_user] ([user_id]);
ALTER TABLE [guacamole_user_permission] CREATE NONCLUSTERED INDEX [IX_guacamole_user_permission_affected_user_id]
CHECK CONSTRAINT [FK_guacamole_user_permission_user1]; ON [guacamole_user_permission] ([affected_user_id]);
GO GO
/** --
* The connection_history table stores records for historical -- Table of connection history records. Each record defines a specific user's
* connections. -- session, including the connection used, the start time, and the end time
*/ -- (if any).
--
CREATE TABLE [guacamole_connection_history] ( CREATE TABLE [guacamole_connection_history] (
[history_id] [int] IDENTITY(1,1) NOT NULL, [history_id] [int] IDENTITY(1,1) NOT NULL,
[user_id] [int] NULL, [user_id] [int],
[username] [nvarchar](128) NOT NULL, [username] [nvarchar](128) NOT NULL,
[remote_host] [nvarchar](256) NULL, [remote_host] [nvarchar](256),
[connection_id] [int] NULL, [connection_id] [int],
[connection_name] [nvarchar](128) NOT NULL, [connection_name] [nvarchar](128) NOT NULL,
[sharing_profile_id] [int] NULL, [sharing_profile_id] [int],
[sharing_profile_name] [nvarchar](128) NULL, [sharing_profile_name] [nvarchar](128),
[start_date] [datetime] NOT NULL, [start_date] [datetime] NOT NULL,
[end_date] [datetime] NULL, [end_date] [datetime],
CONSTRAINT [PK_guacamole_connection_history] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_connection_history]
([history_id] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([history_id]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_connection_history_user_id]
* Foreign keys for connection_history table FOREIGN KEY ([user_id])
*/
ALTER TABLE [guacamole_connection_history]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_history_connection] FOREIGN KEY([connection_id])
REFERENCES [guacamole_connection] ([connection_id])
ON UPDATE CASCADE
ON DELETE SET NULL;
ALTER TABLE [guacamole_connection_history]
CHECK CONSTRAINT [FK_guacamole_connection_history_connection];
ALTER TABLE [guacamole_connection_history]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_history_sharing_profile] FOREIGN KEY([sharing_profile_id])
REFERENCES [guacamole_sharing_profile] ([sharing_profile_id]);
ALTER TABLE [guacamole_connection_history]
CHECK CONSTRAINT [FK_guacamole_connection_history_sharing_profile];
ALTER TABLE [guacamole_connection_history]
WITH CHECK ADD CONSTRAINT [FK_guacamole_connection_history_user] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE SET NULL,
ON DELETE SET NULL;
ALTER TABLE [guacamole_connection_history] CONSTRAINT [FK_guacamole_connection_history_connection_id]
CHECK CONSTRAINT [FK_guacamole_connection_history_user]; FOREIGN KEY ([connection_id])
REFERENCES [guacamole_connection] ([connection_id])
ON DELETE SET NULL,
CONSTRAINT [FK_guacamole_connection_history_sharing_profile_id]
FOREIGN KEY ([sharing_profile_id])
REFERENCES [guacamole_sharing_profile] ([sharing_profile_id])
-- ON DELETE SET NULL handled by guacamole_delete_sharing profile trigger
);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_history_user_id]
ON [guacamole_connection_history] ([user_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_history_connection_id]
ON [guacamole_connection_history] ([connection_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_history_sharing_profile_id]
ON [guacamole_connection_history] ([sharing_profile_id]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_history_start_date]
ON [guacamole_connection_history] ([start_date]);
CREATE NONCLUSTERED INDEX [IX_guacamole_connection_history_end_date]
ON [guacamole_connection_history] ([end_date]);
GO GO
/** --
* The user_password_history table stores password history -- The user_password_history table stores password history
* for users, allowing for enforcing rules associated with -- for users, allowing for enforcing rules associated with
* reuse of passwords. -- reuse of passwords.
*/ --
CREATE TABLE [guacamole_user_password_history] ( CREATE TABLE [guacamole_user_password_history] (
[password_history_id] [int] IDENTITY(1,1) NOT NULL, [password_history_id] [int] IDENTITY(1,1) NOT NULL,
[user_id] [int] NOT NULL, [user_id] [int] NOT NULL,
-- Salted password
[password_hash] [binary](32) NOT NULL, [password_hash] [binary](32) NOT NULL,
[password_salt] [binary](32) NULL, [password_salt] [binary](32),
[password_date] [datetime] NOT NULL, [password_date] [datetime] NOT NULL,
CONSTRAINT [PK_guacamole_user_password_history] PRIMARY KEY CLUSTERED CONSTRAINT [PK_guacamole_user_password_history]
([password_history_id] ASC) ON [PRIMARY] PRIMARY KEY CLUSTERED ([password_history_id]),
) ON [PRIMARY];
/** CONSTRAINT [FK_guacamole_user_password_history_user_id]
* Foreign keys for user_password_history table FOREIGN KEY ([user_id])
*/
ALTER TABLE [guacamole_user_password_history]
WITH CHECK ADD CONSTRAINT [FK_guacamole_user_password_history_user] FOREIGN KEY([user_id])
REFERENCES [guacamole_user] ([user_id]) REFERENCES [guacamole_user] ([user_id])
ON UPDATE CASCADE ON DELETE CASCADE
ON DELETE CASCADE;
ALTER TABLE [guacamole_user_password_history] );
CHECK CONSTRAINT [FK_guacamole_user_password_history_user];
CREATE NONCLUSTERED INDEX [IX_guacamole_user_password_history_user_id]
ON [guacamole_user_password_history] ([user_id]);
GO
--
-- Handle cascading deletion/updates of records in response to deletion of
-- guacamole_user records, where such deletion is not already covered by
-- ON DELETE CASCADE or ON DELETE SET NULL.
--
CREATE TRIGGER [guacamole_delete_user]
ON [guacamole_user]
INSTEAD OF DELETE
AS BEGIN
-- Do not take trigger into account when producing row counts for the DELETE
SET NOCOUNT ON;
-- Delete all associated permissions not covered by ON DELETE CASCADE
DELETE FROM [guacamole_user_permission]
WHERE
[user_id] IN (SELECT [user_id] FROM DELETED)
OR [user_id] IN (SELECT [user_id] FROM DELETED);
-- Perform original deletion
DELETE FROM [guacamole_user]
WHERE [user_id] IN (SELECT [user_id] FROM DELETED);
END
GO
--
-- Handle cascading deletion/updates of records in response to deletion of
-- guacamole_connection records, where such deletion is not already covered by
-- ON DELETE CASCADE or ON DELETE SET NULL.
--
CREATE TRIGGER [guacamole_delete_connection]
ON [guacamole_connection]
INSTEAD OF DELETE
AS BEGIN
-- Do not take trigger into account when producing row counts for the DELETE
SET NOCOUNT ON;
-- Delete associated sharing profiles
DELETE FROM [guacamole_sharing_profile]
WHERE [primary_connection_id] IN (SELECT [connection_id] FROM DELETED);
-- Perform original deletion
DELETE FROM [guacamole_connection]
WHERE [connection_id] IN (SELECT [connection_id] FROM DELETED);
END
GO
--
-- Handle cascading deletion/updates of records in response to deletion of
-- guacamole_connection_group records, where such deletion is not already
-- covered by ON DELETE CASCADE or ON DELETE SET NULL.
--
CREATE TRIGGER [guacamole_delete_connection_group]
ON [guacamole_connection_group]
INSTEAD OF DELETE
AS BEGIN
-- Do not take trigger into account when producing row counts for the DELETE
SET NOCOUNT ON;
-- Delete all requested connection groups, including descendants
WITH [connection_groups] ([connection_group_id]) AS (
SELECT [connection_group_id] FROM DELETED
UNION ALL
SELECT [guacamole_connection_group].[connection_group_id]
FROM [guacamole_connection_group]
JOIN [connection_groups] ON [connection_groups].[connection_group_id] = [guacamole_connection_group].[parent_id]
)
DELETE FROM [guacamole_connection_group]
WHERE [connection_group_id] IN (
SELECT [connection_group_id]
FROM [connection_groups]
);
-- Delete all child connections
DELETE FROM [guacamole_connection]
WHERE [parent_id] IN (SELECT [connection_group_id] FROM DELETED);
END
GO
--
-- Handle cascading deletion/updates of records in response to deletion of
-- guacamole_sharing_profile records, where such deletion is not already
-- covered by ON DELETE CASCADE or ON DELETE SET NULL.
--
CREATE TRIGGER [guacamole_delete_sharing_profile]
ON [guacamole_sharing_profile]
INSTEAD OF DELETE
AS BEGIN
-- Do not take trigger into account when producing row counts for the DELETE
SET NOCOUNT ON;
-- Delete all associated permissions not covered by ON DELETE CASCADE
UPDATE [guacamole_connection_history]
SET [sharing_profile_id] = NULL
WHERE [sharing_profile_id] IN (SELECT [sharing_profile_id] FROM DELETED);
-- Perform original deletion
DELETE FROM [guacamole_sharing_profile]
WHERE [sharing_profile_id] IN (SELECT [sharing_profile_id] FROM DELETED);
END
GO GO

View File

@@ -1,49 +1,60 @@
/* --
* Licensed to the Apache Software Foundation (ASF) under one -- Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements. See the NOTICE file -- or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information -- distributed with this work for additional information
* regarding copyright ownership. The ASF licenses this file -- regarding copyright ownership. The ASF licenses this file
* to you under the Apache License, Version 2.0 (the -- to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance -- "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at -- with the License. You may obtain a copy of the License at
* --
* http://www.apache.org/licenses/LICENSE-2.0 -- http://www.apache.org/licenses/LICENSE-2.0
* --
* Unless required by applicable law or agreed to in writing, -- Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an -- software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY -- "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the -- KIND, either express or implied. See the License for the
* specific language governing permissions and limitations -- specific language governing permissions and limitations
* under the License. -- under the License.
*/ --
/** -- Create default user "guacadmin" with password "guacadmin"
* Create the default admin user account and set up full privileges. INSERT INTO [guacamole_user] (
*/ [username],
INSERT INTO [guacamole_user] (username, password_hash, password_salt, password_date) [password_hash],
VALUES ('guacadmin', [password_salt],
[password_date]
)
VALUES (
'guacadmin',
0xCA458A7D494E3BE824F5E1E175A1556C0F8EEF2C2D7DF3633BEC4A29C4411960, 0xCA458A7D494E3BE824F5E1E175A1556C0F8EEF2C2D7DF3633BEC4A29C4411960,
0xFE24ADC5E11E2B25288D1704ABE67A79E342ECC26064CE69C5B3177795A82264, 0xFE24ADC5E11E2B25288D1704ABE67A79E342ECC26064CE69C5B3177795A82264,
getdate()); getdate()
);
-- Grant this user all system permissions
INSERT INTO [guacamole_system_permission]
SELECT
[user_id],
[permission]
FROM (
SELECT 'guacadmin', 'CREATE_CONNECTION'
UNION SELECT 'guacadmin', 'CREATE_CONNECTION_GROUP'
UNION SELECT 'guacadmin', 'CREATE_SHARING_PROFILE'
UNION SELECT 'guacadmin', 'CREATE_USER'
UNION SELECT 'guacadmin', 'ADMINISTER'
) [permissions] ([username], [permission])
JOIN [guacamole_user] ON [permissions].[username] = [guacamole_user].[username];
INSERT INTO [guacamole_user_permission] INSERT INTO [guacamole_user_permission]
SELECT [guacamole_user].[user_id], [affected].[user_id], permission SELECT
[guacamole_user].[user_id],
[affected].[user_id],
[permission]
FROM ( FROM (
SELECT 'guacadmin' AS username, 'guacadmin' AS affected_username, 'READ' AS permission SELECT 'guacadmin', 'guacadmin', 'READ'
UNION SELECT 'guacadmin' AS username, 'guacadmin' AS affected_username, 'UPDATE' AS permission UNION SELECT 'guacadmin', 'guacadmin', 'UPDATE'
UNION SELECT 'guacadmin' AS username, 'guacadmin' AS affected_username, 'ADMINISTER' AS permission) UNION SELECT 'guacadmin', 'guacadmin', 'ADMINISTER'
permissions ) [permissions] ([username], [affected_username], [permission])
JOIN [guacamole_user] ON permissions.username = [guacamole_user].[username] JOIN [guacamole_user] ON permissions.username = [guacamole_user].[username]
JOIN [guacamole_user] affected ON permissions.affected_username = affected.username; JOIN [guacamole_user] [affected] ON permissions.affected_username = affected.username;
INSERT INTO [guacamole_system_permission]
SELECT user_id, permission
FROM (
SELECT 'guacadmin' AS username, 'CREATE_CONNECTION' AS permission
UNION SELECT 'guacadmin' AS username, 'CREATE_CONNECTION_GROUP' AS permission
UNION SELECT 'guacadmin' AS username, 'CREATE_SHARING_PROFILE' AS permission
UNION SELECT 'guacadmin' AS username, 'CREATE_USER' AS permission
UNION SELECT 'guacadmin' AS username, 'ADMINISTER' AS permission)
permissions
JOIN [guacamole_user] ON permissions.username = [guacamole_user].[username];
GO GO