Package org.apache.geronimo.jetty8.security.auth

Source Code of org.apache.geronimo.jetty8.security.auth.GeronimoJaspiAuthenticator

/*
* Licensed to the Apache Software Foundation (ASF) under one
* or more contributor license agreements.  See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership.  The ASF licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License.  You may obtain a copy of the License at
*
*  http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied.  See the License for the
* specific language governing permissions and limitations
* under the License.
*/

// ========================================================================
// Copyright (c) 2008-2009 Mort Bay Consulting Pty. Ltd.
// ------------------------------------------------------------------------
// All rights reserved. This program and the accompanying materials
// are made available under the terms of the Eclipse Public License v1.0
// and Apache License v2.0 which accompanies this distribution.
// The Eclipse Public License is available at
// http://www.eclipse.org/legal/epl-v10.html
// The Apache License v2.0 is available at
// http://www.opensource.org/licenses/apache2.0.php
// You may elect to redistribute this code under either of these licenses.
// ========================================================================
/*
This is a (hopefully temporary) copy of jetty 8's JaspiAuthenticator modified for correct handling of CallerPrincipalCallback and GroupsCallback.

See GERONIMO-6337 and GERONIMO-6338
*/

package org.apache.geronimo.jetty8.security.auth;

import java.util.Map;
import java.util.Set;

import javax.security.auth.Subject;
import javax.security.auth.callback.CallbackHandler;
import javax.security.auth.message.AuthException;
import javax.security.auth.message.AuthStatus;
import javax.security.auth.message.config.ServerAuthConfig;
import javax.security.auth.message.config.ServerAuthContext;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;

import org.eclipse.jetty.security.Authenticator;
import org.eclipse.jetty.security.IdentityService;
import org.eclipse.jetty.security.ServerAuthException;
import org.eclipse.jetty.security.UserAuthentication;
import org.eclipse.jetty.security.authentication.DeferredAuthentication;
import org.eclipse.jetty.security.jaspi.JaspiMessageInfo;
import org.eclipse.jetty.server.Authentication;
import org.eclipse.jetty.server.UserIdentity;

/**
* @version $Rev:$ $Date:$
*/
public class GeronimoJaspiAuthenticator implements Authenticator {

        private final ServerAuthConfig _authConfig;
        private final Map _authProperties;
        private final CallbackHandler _callbackHandler;
        private final Subject _serviceSubject;
        private final boolean _allowLazyAuthentication;
        private final IdentityService _identityService;
        private final DeferredAuthentication _deferred;

        public GeronimoJaspiAuthenticator(ServerAuthConfig authConfig, Map authProperties, CallbackHandler callbackHandler,
                                  Subject serviceSubject, boolean allowLazyAuthentication, IdentityService identityService)
        {
            // TODO maybe pass this in via setConfiguration ?
            if (callbackHandler == null)
                throw new NullPointerException("No CallbackHandler");
            if (authConfig == null)
                throw new NullPointerException("No AuthConfig");
            this._authConfig = authConfig;
            this._authProperties = authProperties;
            this._callbackHandler = callbackHandler;
            this._serviceSubject = serviceSubject;
            this._allowLazyAuthentication = allowLazyAuthentication;
            this._identityService = identityService;
            this._deferred=new DeferredAuthentication(this);
        }


        public void setConfiguration(AuthConfiguration configuration)
        {
        }


        public String getAuthMethod()
        {
            return "JASPI";
        }

        public Authentication validateRequest(ServletRequest request, ServletResponse response, boolean mandatory) throws ServerAuthException
        {
            if (_allowLazyAuthentication && !mandatory)
                return _deferred;

            JaspiMessageInfo info = new JaspiMessageInfo(request, response, mandatory);
            request.setAttribute("org.eclipse.jetty.security.jaspi.info",info);
            return validateRequest(info);
        }

        // most likely validatedUser is not needed here.
        public boolean secureResponse(ServletRequest req, ServletResponse res, boolean mandatory, Authentication.User validatedUser) throws ServerAuthException
        {
            JaspiMessageInfo info = (JaspiMessageInfo)req.getAttribute("org.eclipse.jetty.security.jaspi.info");
            if (info==null) throw new NullPointerException("MeesageInfo from request missing: " + req);
            return secureResponse(info,validatedUser);
        }

        public Authentication validateRequest(JaspiMessageInfo messageInfo) throws ServerAuthException
        {
            try
            {
                String authContextId = _authConfig.getAuthContextID(messageInfo);
                ServerAuthContext authContext = _authConfig.getAuthContext(authContextId,_serviceSubject,_authProperties);
                Subject clientSubject = new Subject();

                AuthStatus authStatus = authContext.validateRequest(messageInfo,clientSubject,_serviceSubject);
//            String authMethod = (String)messageInfo.getMap().get(JaspiMessageInfo.AUTH_METHOD_KEY);

                if (authStatus == AuthStatus.SEND_CONTINUE)
                    return Authentication.SEND_CONTINUE;
                if (authStatus == AuthStatus.SEND_FAILURE)
                    return Authentication.SEND_FAILURE;

                if (authStatus == AuthStatus.SUCCESS)
                {
                Set<UserIdentity> ids = clientSubject.getPrivateCredentials(UserIdentity.class);
                    UserIdentity userIdentity;
                    if (ids.size() > 0)
                    {
                        userIdentity = ids.iterator().next();
                    } else {
                        userIdentity = _identityService.newUserIdentity(clientSubject, null, null);
                    }
                    return new UserAuthentication(getAuthMethod(), userIdentity);
                }
                if (authStatus == AuthStatus.SEND_SUCCESS)
                {
                    //we are processing a message in a secureResponse dialog.
                    return Authentication.SEND_SUCCESS;
                }
                //should not happen
                throw new NullPointerException("No AuthStatus returned");
            }
            catch (AuthException e)
            {
                throw new ServerAuthException(e);
            }
        }

        public boolean secureResponse(JaspiMessageInfo messageInfo, Authentication validatedUser) throws ServerAuthException
        {
            try
            {
                String authContextId = _authConfig.getAuthContextID(messageInfo);
                ServerAuthContext authContext = _authConfig.getAuthContext(authContextId,_serviceSubject,_authProperties);
                // TODO authContext.cleanSubject(messageInfo,validatedUser.getUserIdentity().getSubject());
                AuthStatus status = authContext.secureResponse(messageInfo,_serviceSubject);
                return (AuthStatus.SEND_SUCCESS.equals(status));
            }
            catch (AuthException e)
            {
                throw new ServerAuthException(e);
            }
        }

    }
TOP

Related Classes of org.apache.geronimo.jetty8.security.auth.GeronimoJaspiAuthenticator

TOP
Copyright © 2018 www.massapi.com. All rights reserved.
All source code are property of their respective owners. Java is a trademark of Sun Microsystems, Inc and owned by ORACLE Inc. Contact coftware#gmail.com.