Optimized 'View By' DAO querries

This commit is contained in:
Eugene Livis
2021-10-20 17:12:27 -04:00
parent ee6c485e5a
commit 3d95aa0885
3 changed files with 37 additions and 33 deletions
@@ -43,12 +43,10 @@ public class FileRowDTO extends BaseRowDTO {
private final ExtensionMediaType extensionMediaType;
private final boolean allocated;
private final TskData.TSK_DB_FILES_TYPE_ENUM fileType;
private final boolean encryptionDetected;
private final boolean visibleChildren;
public FileRowDTO(AbstractFile abstractFile, long id, String fileName, String extension,
ExtensionMediaType extensionMediaType, boolean allocated, TskData.TSK_DB_FILES_TYPE_ENUM fileType,
boolean encryptionDetected, boolean visibleChildren, List<Object> cellValues) {
List<Object> cellValues) {
super(cellValues, TYPE_ID, id);
this.abstractFile = abstractFile;
this.fileName = fileName;
@@ -56,8 +54,6 @@ public class FileRowDTO extends BaseRowDTO {
this.extensionMediaType = extensionMediaType;
this.allocated = allocated;
this.fileType = fileType;
this.encryptionDetected = encryptionDetected;
this.visibleChildren = visibleChildren;
}
public ExtensionMediaType getExtensionMediaType() {
@@ -80,15 +76,7 @@ public class FileRowDTO extends BaseRowDTO {
return extension;
}
public boolean isEncryptionDetected() {
return encryptionDetected;
}
public String getFileName() {
return fileName;
}
public boolean hasVisibleChildren() {
return visibleChildren;
}
}
@@ -296,26 +296,29 @@ public class ViewsDAO {
return fetchFileViewFiles(whereStatement, filter.getDisplayName(), startItem, maxResultCount);
}
private SearchResultsDTO fetchFileViewFiles(String whereStatement, String displayName, long startItem, Long maxResultCount) throws NoCurrentCaseException, TskCoreException {
List<AbstractFile> files = getCase().findAllFilesWhere(whereStatement);
private SearchResultsDTO fetchFileViewFiles(String originalWhereStatement, String displayName, long startItem, Long maxResultCount) throws NoCurrentCaseException, TskCoreException {
Stream<AbstractFile> pagedFileStream = files.stream()
.sorted(Comparator.comparing(af -> af.getId()))
.skip(startItem);
// Add offset and/or paging, if specified
String modifiedWhereStatement = originalWhereStatement
+ " ORDER BY obj_id ASC"
+ (maxResultCount != null && maxResultCount > 0 ? " LIMIT " + maxResultCount : "")
+ (startItem > 0 ? " OFFSET " + startItem : "");
List<AbstractFile> files = getCase().findAllFilesWhere(modifiedWhereStatement);
if (maxResultCount != null) {
pagedFileStream = pagedFileStream.limit(maxResultCount);
long totalResultsCount;
// get total number of results
if ( (startItem == 0) // offset is zero AND
&& ( (maxResultCount != null && files.size() < maxResultCount) // number of results is less than max
|| (maxResultCount == null)) ) { // OR max number of results was not specified
totalResultsCount = files.size();
} else {
// do a query to get total number of results
totalResultsCount = getCase().countFilesWhere(originalWhereStatement);
}
List<AbstractFile> pagedFiles = pagedFileStream.collect(Collectors.toList());
List<RowDTO> fileRows = new ArrayList<>();
for (AbstractFile file : pagedFiles) {
boolean isArchive = FileTypeExtensions.getArchiveExtensions().contains("." + file.getNameExtension().toLowerCase());
boolean encryptionDetected = isArchive && file.getArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTION_DETECTED).size() > 0;
boolean hasVisibleChildren = isArchive || file.isDir();
for (AbstractFile file : files) {
List<Object> cellValues = Arrays.asList(
file.getName(), // GVDTODO handle . and .. from getContentDisplayName()
@@ -358,12 +361,10 @@ public class ViewsDAO {
getExtensionMediaType(file.getNameExtension()),
file.isDirNameFlagSet(TskData.TSK_FS_NAME_FLAG_ENUM.ALLOC),
file.getType(),
encryptionDetected,
hasVisibleChildren,
cellValues));
}
return new BaseSearchResultsDTO(FILE_VIEW_EXT_TYPE_ID, displayName, FILE_COLUMNS, fileRows, startItem, files.size());
return new BaseSearchResultsDTO(FILE_VIEW_EXT_TYPE_ID, displayName, FILE_COLUMNS, fileRows, startItem, totalResultsCount);
}
}
@@ -32,6 +32,7 @@ import org.openide.util.Utilities;
import org.sleuthkit.autopsy.actions.AddContentTagAction;
import org.sleuthkit.autopsy.actions.DeleteFileContentTagAction;
import org.sleuthkit.autopsy.coreutils.ContextMenuExtensionPoint;
import org.sleuthkit.autopsy.datamodel.FileTypeExtensions;
import org.sleuthkit.autopsy.mainui.datamodel.SearchResultsDTO;
import org.sleuthkit.autopsy.mainui.datamodel.FileRowDTO;
import org.sleuthkit.autopsy.directorytree.ExportCSVAction;
@@ -44,6 +45,8 @@ import org.sleuthkit.autopsy.mainui.datamodel.FileRowDTO.ExtensionMediaType;
import org.sleuthkit.autopsy.modules.embeddedfileextractor.ExtractArchiveWithPasswordAction;
import org.sleuthkit.autopsy.timeline.actions.ViewFileInTimelineAction;
import org.sleuthkit.datamodel.AbstractFile;
import org.sleuthkit.datamodel.BlackboardArtifact;
import org.sleuthkit.datamodel.TskCoreException;
import org.sleuthkit.datamodel.TskData.TSK_DB_FILES_TYPE_ENUM;
/**
@@ -173,9 +176,21 @@ public class FileNode extends AbstractNode {
actionsList.add(DeleteFileContentTagAction.getInstance());
}
actionsList.addAll(ContextMenuExtensionPoint.getActions());
if (this.fileData.isEncryptionDetected()) {
actionsList.add(new ExtractArchiveWithPasswordAction(this.fileData.getAbstractFile()));
// GVDTODO: HANDLE THIS ACTION IN A BETTER WAY!-----
// See JIRA-8099
AbstractFile file = this.fileData.getAbstractFile();
boolean isArchive = FileTypeExtensions.getArchiveExtensions().contains("." + file.getNameExtension().toLowerCase());
boolean encryptionDetected = false;
try {
encryptionDetected = isArchive && file.getArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTION_DETECTED).size() > 0;
} catch (TskCoreException ex) {
// TODO
}
if (encryptionDetected) {
actionsList.add(new ExtractArchiveWithPasswordAction(this.fileData.getAbstractFile()));
}
//------------------------------------------------
actionsList.add(null);
actionsList.addAll(Arrays.asList(super.getActions(true)));