view web/common/src/main/java/com/redhat/thermostat/web/common/ExpressionSerializer.java @ 1140:bf720980510c

Handle boolean formulas in Query.where This commit adds a hierarchy of expressions to storage-core. These expressions are used to create more general boolean formulas for queries than we currently support. Most importantly, this will allow us to use disjunctions in queries. Expressions are created using the ExpressionFactory methods corresponding to each operator. For instance, expressions created by the factory's "greaterThan" and "lessThan" methods can then be joined using the factory's "and" or "or" methods. These expressions are serialized/deserialized to/from JSON by the new ExpressionSerializer and OperatorSerializer classes. These serializers are written to only handle Expression subclasses that it knows about, and these concrete Expression classes are all declared final. This should help prevent the web service from handling malicious arbitrary queries. Ideally I would have liked to make all Expression constructors package-private and require that all instantiations be done through the factory, but the need to deserialize expressions from JSON prevents this unless we want storage-core to deal with JSON. The MongoDB storage backend uses a new MongoExpressionParser class to convert an expression into a Mongo query. Conjunctions are handled differently now. MongoDB supports implicit and explicit conjunctions. Previously, our MongoQuery.where appended new clauses to the query in each successive call. This resulted in an implicit conjunction of these clauses. Now we create explicit conjunctions using the $and operator. This has a couple of advantages: short-circuiting, and the ability to specify the same key twice (e.g. x > 7 && x < 10). Reviewed-by: jerboaa Review-thread: http://icedtea.classpath.org/pipermail/thermostat/2013-June/006932.html
author Elliott Baron <ebaron@redhat.com>
date Fri, 07 Jun 2013 13:49:04 -0400
parents
children e597d72c3ecb
line wrap: on
line source

/*
 * Copyright 2012, 2013 Red Hat, Inc.
 *
 * This file is part of Thermostat.
 *
 * Thermostat is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published
 * by the Free Software Foundation; either version 2, or (at your
 * option) any later version.
 *
 * Thermostat is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with Thermostat; see the file COPYING.  If not see
 * <http://www.gnu.org/licenses/>.
 *
 * Linking this code with other modules is making a combined work
 * based on this code.  Thus, the terms and conditions of the GNU
 * General Public License cover the whole combination.
 *
 * As a special exception, the copyright holders of this code give
 * you permission to link this code with independent modules to
 * produce an executable, regardless of the license terms of these
 * independent modules, and to copy and distribute the resulting
 * executable under terms of your choice, provided that you also
 * meet, for each linked independent module, the terms and conditions
 * of the license of that module.  An independent module is a module
 * which is not derived from or based on this code.  If you modify
 * this code, you may extend this exception to your version of the
 * library, but you are not obligated to do so.  If you do not wish
 * to do so, delete this exception statement from your version.
 */ 

package com.redhat.thermostat.web.common;

import java.lang.reflect.Type;

import com.google.gson.JsonDeserializationContext;
import com.google.gson.JsonDeserializer;
import com.google.gson.JsonElement;
import com.google.gson.JsonObject;
import com.google.gson.JsonParseException;
import com.google.gson.JsonSerializationContext;
import com.google.gson.JsonSerializer;
import com.redhat.thermostat.storage.core.Key;
import com.redhat.thermostat.storage.query.BinaryComparisonExpression;
import com.redhat.thermostat.storage.query.BinaryComparisonOperator;
import com.redhat.thermostat.storage.query.BinaryLogicalExpression;
import com.redhat.thermostat.storage.query.BinaryLogicalOperator;
import com.redhat.thermostat.storage.query.Expression;
import com.redhat.thermostat.storage.query.LiteralExpression;
import com.redhat.thermostat.storage.query.Operator;
import com.redhat.thermostat.storage.query.UnaryLogicalExpression;
import com.redhat.thermostat.storage.query.UnaryLogicalOperator;

public class ExpressionSerializer implements JsonSerializer<Expression>,
        JsonDeserializer<Expression> {
    /* The concrete Expression fully-qualified class name */
    static final String PROP_CLASS_NAME = "PROP_CLASS_NAME";
    /* Serialized operand for a UnaryExpression */
    static final String PROP_OPERAND = "PROP_OPERAND";
    /* Serialized left operand for a BinaryExpression */
    static final String PROP_OPERAND_LEFT = "PROP_OPERAND_LEFT";
    /* Serialized right operand for a BinaryExpression */
    static final String PROP_OPERAND_RIGHT = "PROP_OPERAND_RIGHT";
    /* Serialized operator for an Expression */
    static final String PROP_OPERATOR = "PROP_OPERATOR";
    /* Serialized value for a LiteralExpression */
    static final String PROP_VALUE = "PROP_VALUE";
    /* Fully-qualified class name of a LiteralExpression's value */
    static final String PROP_VALUE_CLASS = "PROP_VALUE_CLASS";
    
    @Override
    public Expression deserialize(JsonElement json, Type typeOfT,
            JsonDeserializationContext context) throws JsonParseException {
        JsonElement jsonClassName = json.getAsJsonObject().get(PROP_CLASS_NAME);
        if (jsonClassName == null) {
            throw new JsonParseException("No class name property provided");
        }
        String className = jsonClassName.getAsString();
        Expression result;
        try {
            Class<?> clazz = (Class<?>) Class.forName(className);
            // Deserialize using concrete implementations to avoid reflection
            // and unchecked casts
            if (BinaryComparisonExpression.class.isAssignableFrom(clazz)) {
                result = deserializeBinaryComparisonExpression(json, context);
            }
            else if (BinaryLogicalExpression.class.isAssignableFrom(clazz)) {
                result = deserializeBinaryLogicalExpression(json, context);
            }
            else if (UnaryLogicalExpression.class.isAssignableFrom(clazz)) {
                result = deserializeUnaryLogicalExpression(json, context);
            }
            else if (LiteralExpression.class.isAssignableFrom(clazz)) {
                result = deserializeLiteralExpression(json, context);
            }
            else {
                throw new JsonParseException("Unknown Expression of type " + className);
            }
        } catch (ClassNotFoundException e) {
            throw new JsonParseException("Unable to deserialize Expression", e);
        }
        return result;
    }

    private <T> Expression deserializeBinaryComparisonExpression(JsonElement json,
            JsonDeserializationContext context) {
        JsonElement jsonLeft = json.getAsJsonObject().get(PROP_OPERAND_LEFT);
        JsonElement jsonRight = json.getAsJsonObject().get(PROP_OPERAND_RIGHT);
        JsonElement jsonOp = json.getAsJsonObject().get(PROP_OPERATOR);
        
        LiteralExpression<Key<T>> left = context.deserialize(jsonLeft, Expression.class);
        LiteralExpression<T> right = context.deserialize(jsonRight, Expression.class);
        BinaryComparisonOperator op = context.deserialize(jsonOp, Operator.class);
        return new BinaryComparisonExpression<>(left, op, right);
    }

    private <S extends Expression, T extends Expression> Expression deserializeBinaryLogicalExpression(JsonElement json,
            JsonDeserializationContext context) {
        JsonElement jsonLeft = json.getAsJsonObject().get(PROP_OPERAND_LEFT);
        JsonElement jsonRight = json.getAsJsonObject().get(PROP_OPERAND_RIGHT);
        JsonElement jsonOp = json.getAsJsonObject().get(PROP_OPERATOR);
        
        S left = context.deserialize(jsonLeft, Expression.class);
        T right = context.deserialize(jsonRight, Expression.class);
        BinaryLogicalOperator op = context.deserialize(jsonOp, Operator.class);
        return new BinaryLogicalExpression<>(left, op, right);
    }

    private <T extends Expression> Expression deserializeUnaryLogicalExpression(JsonElement json,
            JsonDeserializationContext context) {
        JsonElement jsonOperand = json.getAsJsonObject().get(PROP_OPERAND);
        JsonElement jsonOp = json.getAsJsonObject().get(PROP_OPERATOR);
        
        T operand = context.deserialize(jsonOperand, Expression.class);
        UnaryLogicalOperator operator = context.deserialize(jsonOp, Operator.class);
        return new UnaryLogicalExpression<>(operand, operator);
    }

    private Expression deserializeLiteralExpression(JsonElement json,
            JsonDeserializationContext context) throws ClassNotFoundException {
        JsonElement jsonValue = json.getAsJsonObject().get(PROP_VALUE);
        JsonElement jsonValueClass = json.getAsJsonObject().get(PROP_VALUE_CLASS);
        String valueClassName = jsonValueClass.getAsString();
        Class<?> valueClass = Class.forName(valueClassName);
        return makeLiteralExpression(context, jsonValue, valueClass);
    }

    private <T> Expression makeLiteralExpression(JsonDeserializationContext context, 
            JsonElement jsonValue, Class<T> valueClass) throws ClassNotFoundException {
        T value = context.deserialize(jsonValue, valueClass);
        return new LiteralExpression<>(value);
    }

    @Override
    public JsonElement serialize(Expression src, Type typeOfSrc,
            JsonSerializationContext context) {
        JsonObject result;
        // Only concrete implementations are public
        if (src instanceof BinaryLogicalExpression) {
            BinaryLogicalExpression<?, ?> binExpr = (BinaryLogicalExpression<?, ?>) src;
            JsonElement left = context.serialize(binExpr.getLeftOperand());
            JsonElement op = context.serialize(binExpr.getOperator());
            JsonElement right = context.serialize(binExpr.getRightOperand());
            result = new JsonObject();
            result.add(PROP_OPERAND_LEFT, left);
            result.add(PROP_OPERATOR, op);
            result.add(PROP_OPERAND_RIGHT, right);
        }
        else if (src instanceof BinaryComparisonExpression) {
            BinaryComparisonExpression<?> binExpr = (BinaryComparisonExpression<?>) src;
            JsonElement left = context.serialize(binExpr.getLeftOperand());
            JsonElement op = context.serialize(binExpr.getOperator());
            JsonElement right = context.serialize(binExpr.getRightOperand());
            result = new JsonObject();
            result.add(PROP_OPERAND_LEFT, left);
            result.add(PROP_OPERATOR, op);
            result.add(PROP_OPERAND_RIGHT, right);
        }
        else if (src instanceof UnaryLogicalExpression) {
            UnaryLogicalExpression<?> unaryExpr = (UnaryLogicalExpression<?>) src;
            JsonElement operand = context.serialize(unaryExpr.getOperand());
            JsonElement operator = context.serialize(unaryExpr.getOperator());
            result = new JsonObject();
            result.add(PROP_OPERAND, operand);
            result.add(PROP_OPERATOR, operator);
        }
        else if (src instanceof LiteralExpression) {
            LiteralExpression<?> litExpr = (LiteralExpression<?>) src;
            JsonElement value = context.serialize(litExpr.getValue());
            result = new JsonObject();
            result.add(PROP_VALUE, value);
            // Store the type of value to properly deserialize it later
            result.addProperty(PROP_VALUE_CLASS, litExpr.getValue().getClass().getCanonicalName());
        }
        else {
            throw new JsonParseException("Unknown expression of type " + src.getClass());
        }
        result.addProperty(PROP_CLASS_NAME, src.getClass().getCanonicalName());
        return result;
    }

}