Commit bd68da5cc68846d3d027c3dbeef497ae98e5b751
1 parent
c6d910ef
Exists in
master
Implementação do filtro para tratamento de passagem de credenciais via
autenticação BASIC
Showing
7 changed files
with
255 additions
and
18 deletions
Show diff stats
impl/core/src/main/java/br/gov/frameworkdemoiselle/transaction/TransactionalInterceptor.java
... | ... | @@ -187,7 +187,7 @@ public class TransactionalInterceptor implements Serializable { |
187 | 187 | return logger; |
188 | 188 | } |
189 | 189 | |
190 | - private static class VoidTransactionInfo extends TransactionInfo { | |
190 | + static class VoidTransactionInfo extends TransactionInfo { | |
191 | 191 | |
192 | 192 | private static final long serialVersionUID = 1L; |
193 | 193 | ... | ... |
impl/extension/servlet/pom.xml
... | ... | @@ -34,7 +34,8 @@ |
34 | 34 | ou escreva para a Fundação do Software Livre (FSF) Inc., |
35 | 35 | 51 Franklin St, Fifth Floor, Boston, MA 02111-1301, USA. |
36 | 36 | --> |
37 | -<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> | |
37 | +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | |
38 | + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> | |
38 | 39 | |
39 | 40 | <modelVersion>4.0.0</modelVersion> |
40 | 41 | |
... | ... | @@ -72,6 +73,12 @@ |
72 | 73 | <artifactId>javax.servlet-api</artifactId> |
73 | 74 | </dependency> |
74 | 75 | <dependency> |
76 | + <groupId>commons-codec</groupId> | |
77 | + <artifactId>commons-codec</artifactId> | |
78 | + <version>1.4</version> | |
79 | + </dependency> | |
80 | + | |
81 | + <dependency> | |
75 | 82 | <groupId>javax.el</groupId> |
76 | 83 | <artifactId>el-api</artifactId> |
77 | 84 | <scope>test</scope> | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/BasicAuthenticationFilter.java
0 → 100644
... | ... | @@ -0,0 +1,113 @@ |
1 | +/* | |
2 | + * Demoiselle Framework | |
3 | + * Copyright (C) 2010 SERPRO | |
4 | + * ---------------------------------------------------------------------------- | |
5 | + * This file is part of Demoiselle Framework. | |
6 | + * | |
7 | + * Demoiselle Framework is free software; you can redistribute it and/or | |
8 | + * modify it under the terms of the GNU Lesser General Public License version 3 | |
9 | + * as published by the Free Software Foundation. | |
10 | + * | |
11 | + * This program is distributed in the hope that it will be useful, | |
12 | + * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
13 | + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
14 | + * GNU General Public License for more details. | |
15 | + * | |
16 | + * You should have received a copy of the GNU Lesser General Public License version 3 | |
17 | + * along with this program; if not, see <http://www.gnu.org/licenses/> | |
18 | + * or write to the Free Software Foundation, Inc., 51 Franklin Street, | |
19 | + * Fifth Floor, Boston, MA 02110-1301, USA. | |
20 | + * ---------------------------------------------------------------------------- | |
21 | + * Este arquivo é parte do Framework Demoiselle. | |
22 | + * | |
23 | + * O Framework Demoiselle é um software livre; você pode redistribuí-lo e/ou | |
24 | + * modificá-lo dentro dos termos da GNU LGPL versão 3 como publicada pela Fundação | |
25 | + * do Software Livre (FSF). | |
26 | + * | |
27 | + * Este programa é distribuído na esperança que possa ser útil, mas SEM NENHUMA | |
28 | + * GARANTIA; sem uma garantia implícita de ADEQUAÇÃO a qualquer MERCADO ou | |
29 | + * APLICAÇÃO EM PARTICULAR. Veja a Licença Pública Geral GNU/LGPL em português | |
30 | + * para maiores detalhes. | |
31 | + * | |
32 | + * Você deve ter recebido uma cópia da GNU LGPL versão 3, sob o título | |
33 | + * "LICENCA.txt", junto com esse programa. Se não, acesse <http://www.gnu.org/licenses/> | |
34 | + * ou escreva para a Fundação do Software Livre (FSF) Inc., | |
35 | + * 51 Franklin St, Fifth Floor, Boston, MA 02111-1301, USA. | |
36 | + */ | |
37 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
38 | + | |
39 | +import java.io.IOException; | |
40 | +import java.util.Arrays; | |
41 | + | |
42 | +import javax.servlet.Filter; | |
43 | +import javax.servlet.FilterChain; | |
44 | +import javax.servlet.FilterConfig; | |
45 | +import javax.servlet.ServletException; | |
46 | +import javax.servlet.ServletRequest; | |
47 | +import javax.servlet.ServletResponse; | |
48 | +import javax.servlet.http.HttpServletRequest; | |
49 | + | |
50 | +import org.apache.commons.codec.binary.Base64; | |
51 | + | |
52 | +import br.gov.frameworkdemoiselle.security.AuthenticationException; | |
53 | +import br.gov.frameworkdemoiselle.security.Credentials; | |
54 | +import br.gov.frameworkdemoiselle.security.SecurityContext; | |
55 | +import br.gov.frameworkdemoiselle.util.Beans; | |
56 | + | |
57 | +public class BasicAuthenticationFilter implements Filter { | |
58 | + | |
59 | + @Override | |
60 | + public void init(FilterConfig filterConfig) throws ServletException { | |
61 | + } | |
62 | + | |
63 | + @Override | |
64 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
65 | + ServletException { | |
66 | + | |
67 | + String[] basicCredentials = getCredentials((HttpServletRequest) request); | |
68 | + | |
69 | + if (basicCredentials != null) { | |
70 | + Credentials credentials = Beans.getReference(Credentials.class); | |
71 | + credentials.setUsername(basicCredentials[0]); | |
72 | + credentials.setPassword(basicCredentials[1]); | |
73 | + | |
74 | + try { | |
75 | + Beans.getReference(SecurityContext.class).login(); | |
76 | + | |
77 | + } catch (AuthenticationException cause) { | |
78 | + // TODO Informar via logger que a autenticação não foi bem sucedida. | |
79 | + } | |
80 | + } | |
81 | + | |
82 | + chain.doFilter(request, response); | |
83 | + } | |
84 | + | |
85 | + private String getAuthHeader(HttpServletRequest request) { | |
86 | + String result = request.getHeader("Authorization"); | |
87 | + result = (result == null ? request.getHeader("authorization") : result); | |
88 | + | |
89 | + return result; | |
90 | + } | |
91 | + | |
92 | + private String[] getCredentials(HttpServletRequest request) { | |
93 | + String[] result = null; | |
94 | + String header = getAuthHeader(request); | |
95 | + | |
96 | + if (header != null) { | |
97 | + byte[] decoded = Base64.decodeBase64(header.substring(6)); | |
98 | + result = new String(decoded).split(":"); | |
99 | + } | |
100 | + | |
101 | + if (result != null && Arrays.asList(result).size() != 2) { | |
102 | + result = null; | |
103 | + | |
104 | + // TODO Informar via logger que o header Authorization não contém as informações de username e password | |
105 | + } | |
106 | + | |
107 | + return result; | |
108 | + } | |
109 | + | |
110 | + @Override | |
111 | + public void destroy() { | |
112 | + } | |
113 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/HttpServletRequestProducerFilter.java
0 → 100644
... | ... | @@ -0,0 +1,32 @@ |
1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
2 | + | |
3 | +import java.io.IOException; | |
4 | + | |
5 | +import javax.servlet.Filter; | |
6 | +import javax.servlet.FilterChain; | |
7 | +import javax.servlet.FilterConfig; | |
8 | +import javax.servlet.ServletException; | |
9 | +import javax.servlet.ServletRequest; | |
10 | +import javax.servlet.ServletResponse; | |
11 | +import javax.servlet.http.HttpServletRequest; | |
12 | + | |
13 | +import br.gov.frameworkdemoiselle.internal.producer.HttpServletRequestProducer; | |
14 | +import br.gov.frameworkdemoiselle.util.Beans; | |
15 | + | |
16 | +public class HttpServletRequestProducerFilter implements Filter { | |
17 | + | |
18 | + @Override | |
19 | + public void init(FilterConfig config) throws ServletException { | |
20 | + } | |
21 | + | |
22 | + @Override | |
23 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
24 | + ServletException { | |
25 | + Beans.getReference(HttpServletRequestProducer.class).setDelegate((HttpServletRequest) request); | |
26 | + chain.doFilter(request, response); | |
27 | + } | |
28 | + | |
29 | + @Override | |
30 | + public void destroy() { | |
31 | + } | |
32 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/HttpServletResponseProducerFilter.java
0 → 100644
... | ... | @@ -0,0 +1,32 @@ |
1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
2 | + | |
3 | +import java.io.IOException; | |
4 | + | |
5 | +import javax.servlet.Filter; | |
6 | +import javax.servlet.FilterChain; | |
7 | +import javax.servlet.FilterConfig; | |
8 | +import javax.servlet.ServletException; | |
9 | +import javax.servlet.ServletRequest; | |
10 | +import javax.servlet.ServletResponse; | |
11 | +import javax.servlet.http.HttpServletResponse; | |
12 | + | |
13 | +import br.gov.frameworkdemoiselle.internal.producer.HttpServletResponseProducer; | |
14 | +import br.gov.frameworkdemoiselle.util.Beans; | |
15 | + | |
16 | +public class HttpServletResponseProducerFilter implements Filter { | |
17 | + | |
18 | + @Override | |
19 | + public void init(FilterConfig config) throws ServletException { | |
20 | + } | |
21 | + | |
22 | + @Override | |
23 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
24 | + ServletException { | |
25 | + Beans.getReference(HttpServletResponseProducer.class).setDelegate((HttpServletResponse) response); | |
26 | + chain.doFilter(request, response); | |
27 | + } | |
28 | + | |
29 | + @Override | |
30 | + public void destroy() { | |
31 | + } | |
32 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/InternalProcessorFilterImpl.java
0 → 100644
... | ... | @@ -0,0 +1,62 @@ |
1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
2 | + | |
3 | +import java.io.IOException; | |
4 | +import java.util.ArrayList; | |
5 | +import java.util.List; | |
6 | + | |
7 | +import javax.servlet.Filter; | |
8 | +import javax.servlet.FilterChain; | |
9 | +import javax.servlet.FilterConfig; | |
10 | +import javax.servlet.ServletException; | |
11 | +import javax.servlet.ServletRequest; | |
12 | +import javax.servlet.ServletResponse; | |
13 | + | |
14 | +import br.gov.frameworkdemoiselle.annotation.StaticScoped; | |
15 | +import br.gov.frameworkdemoiselle.util.ServletFilter.InternalProcessorFilter; | |
16 | + | |
17 | +@StaticScoped | |
18 | +public class InternalProcessorFilterImpl implements InternalProcessorFilter { | |
19 | + | |
20 | + private List<Filter> filters; | |
21 | + | |
22 | + public InternalProcessorFilterImpl() { | |
23 | + filters = new ArrayList<Filter>(); | |
24 | + | |
25 | + filters.add(new HttpServletRequestProducerFilter()); | |
26 | + filters.add(new HttpServletResponseProducerFilter()); | |
27 | + filters.add(new BasicAuthenticationFilter()); | |
28 | + } | |
29 | + | |
30 | + @Override | |
31 | + public void init(FilterConfig config) throws ServletException { | |
32 | + for (Filter filter : filters) { | |
33 | + filter.init(config); | |
34 | + } | |
35 | + } | |
36 | + | |
37 | + @Override | |
38 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
39 | + ServletException { | |
40 | + FilterChain emptyChain = createEmptyChain(); | |
41 | + | |
42 | + for (Filter filter : filters) { | |
43 | + filter.doFilter(request, response, emptyChain); | |
44 | + } | |
45 | + } | |
46 | + | |
47 | + @Override | |
48 | + public void destroy() { | |
49 | + for (Filter filter : filters) { | |
50 | + filter.destroy(); | |
51 | + } | |
52 | + } | |
53 | + | |
54 | + private FilterChain createEmptyChain() { | |
55 | + return new FilterChain() { | |
56 | + | |
57 | + @Override | |
58 | + public void doFilter(ServletRequest request, ServletResponse response) throws IOException, ServletException { | |
59 | + } | |
60 | + }; | |
61 | + } | |
62 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/util/ServletFilter.java
... | ... | @@ -44,36 +44,27 @@ import javax.servlet.FilterConfig; |
44 | 44 | import javax.servlet.ServletException; |
45 | 45 | import javax.servlet.ServletRequest; |
46 | 46 | import javax.servlet.ServletResponse; |
47 | -import javax.servlet.http.HttpServletRequest; | |
48 | -import javax.servlet.http.HttpServletResponse; | |
49 | - | |
50 | -import br.gov.frameworkdemoiselle.internal.producer.HttpServletRequestProducer; | |
51 | -import br.gov.frameworkdemoiselle.internal.producer.HttpServletResponseProducer; | |
52 | 47 | |
53 | 48 | public class ServletFilter implements Filter { |
54 | 49 | |
55 | 50 | @Override |
56 | - public void init(FilterConfig filterConfig) throws ServletException { | |
51 | + public void init(FilterConfig config) throws ServletException { | |
52 | + Beans.getReference(InternalProcessorFilter.class).init(config); | |
57 | 53 | } |
58 | 54 | |
59 | 55 | @Override |
60 | 56 | public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, |
61 | 57 | ServletException { |
62 | - | |
63 | - Beans.getReference(HttpServletRequestProducer.class).setDelegate((HttpServletRequest) request); | |
64 | - Beans.getReference(HttpServletResponseProducer.class).setDelegate((HttpServletResponse) response); | |
65 | - | |
66 | - // X509Certificate[] certificates = (X509Certificate[]) ((HttpServletRequest) request) | |
67 | - // .getAttribute("javax.servlet.request.X509Certificate"); | |
68 | - // | |
69 | - // for (X509Certificate certificate : certificates) { | |
70 | - // System.out.println(certificate.toString()); | |
71 | - // } | |
58 | + Beans.getReference(InternalProcessorFilter.class).doFilter(request, response, chain); | |
72 | 59 | |
73 | 60 | chain.doFilter(request, response); |
74 | 61 | } |
75 | 62 | |
76 | 63 | @Override |
77 | 64 | public void destroy() { |
65 | + Beans.getReference(InternalProcessorFilter.class).destroy(); | |
66 | + } | |
67 | + | |
68 | + public interface InternalProcessorFilter extends Filter { | |
78 | 69 | } |
79 | 70 | } | ... | ... |