Commit bd68da5cc68846d3d027c3dbeef497ae98e5b751
1 parent
c6d910ef
Exists in
master
Implementação do filtro para tratamento de passagem de credenciais via
autenticação BASIC
Showing
7 changed files
with
255 additions
and
18 deletions
Show diff stats
impl/core/src/main/java/br/gov/frameworkdemoiselle/transaction/TransactionalInterceptor.java
| ... | ... | @@ -187,7 +187,7 @@ public class TransactionalInterceptor implements Serializable { |
| 187 | 187 | return logger; |
| 188 | 188 | } |
| 189 | 189 | |
| 190 | - private static class VoidTransactionInfo extends TransactionInfo { | |
| 190 | + static class VoidTransactionInfo extends TransactionInfo { | |
| 191 | 191 | |
| 192 | 192 | private static final long serialVersionUID = 1L; |
| 193 | 193 | ... | ... |
impl/extension/servlet/pom.xml
| ... | ... | @@ -34,7 +34,8 @@ |
| 34 | 34 | ou escreva para a Fundação do Software Livre (FSF) Inc., |
| 35 | 35 | 51 Franklin St, Fifth Floor, Boston, MA 02111-1301, USA. |
| 36 | 36 | --> |
| 37 | -<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> | |
| 37 | +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | |
| 38 | + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> | |
| 38 | 39 | |
| 39 | 40 | <modelVersion>4.0.0</modelVersion> |
| 40 | 41 | |
| ... | ... | @@ -72,6 +73,12 @@ |
| 72 | 73 | <artifactId>javax.servlet-api</artifactId> |
| 73 | 74 | </dependency> |
| 74 | 75 | <dependency> |
| 76 | + <groupId>commons-codec</groupId> | |
| 77 | + <artifactId>commons-codec</artifactId> | |
| 78 | + <version>1.4</version> | |
| 79 | + </dependency> | |
| 80 | + | |
| 81 | + <dependency> | |
| 75 | 82 | <groupId>javax.el</groupId> |
| 76 | 83 | <artifactId>el-api</artifactId> |
| 77 | 84 | <scope>test</scope> | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/BasicAuthenticationFilter.java
0 → 100644
| ... | ... | @@ -0,0 +1,113 @@ |
| 1 | +/* | |
| 2 | + * Demoiselle Framework | |
| 3 | + * Copyright (C) 2010 SERPRO | |
| 4 | + * ---------------------------------------------------------------------------- | |
| 5 | + * This file is part of Demoiselle Framework. | |
| 6 | + * | |
| 7 | + * Demoiselle Framework is free software; you can redistribute it and/or | |
| 8 | + * modify it under the terms of the GNU Lesser General Public License version 3 | |
| 9 | + * as published by the Free Software Foundation. | |
| 10 | + * | |
| 11 | + * This program is distributed in the hope that it will be useful, | |
| 12 | + * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
| 13 | + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
| 14 | + * GNU General Public License for more details. | |
| 15 | + * | |
| 16 | + * You should have received a copy of the GNU Lesser General Public License version 3 | |
| 17 | + * along with this program; if not, see <http://www.gnu.org/licenses/> | |
| 18 | + * or write to the Free Software Foundation, Inc., 51 Franklin Street, | |
| 19 | + * Fifth Floor, Boston, MA 02110-1301, USA. | |
| 20 | + * ---------------------------------------------------------------------------- | |
| 21 | + * Este arquivo é parte do Framework Demoiselle. | |
| 22 | + * | |
| 23 | + * O Framework Demoiselle é um software livre; você pode redistribuí-lo e/ou | |
| 24 | + * modificá-lo dentro dos termos da GNU LGPL versão 3 como publicada pela Fundação | |
| 25 | + * do Software Livre (FSF). | |
| 26 | + * | |
| 27 | + * Este programa é distribuído na esperança que possa ser útil, mas SEM NENHUMA | |
| 28 | + * GARANTIA; sem uma garantia implícita de ADEQUAÇÃO a qualquer MERCADO ou | |
| 29 | + * APLICAÇÃO EM PARTICULAR. Veja a Licença Pública Geral GNU/LGPL em português | |
| 30 | + * para maiores detalhes. | |
| 31 | + * | |
| 32 | + * Você deve ter recebido uma cópia da GNU LGPL versão 3, sob o título | |
| 33 | + * "LICENCA.txt", junto com esse programa. Se não, acesse <http://www.gnu.org/licenses/> | |
| 34 | + * ou escreva para a Fundação do Software Livre (FSF) Inc., | |
| 35 | + * 51 Franklin St, Fifth Floor, Boston, MA 02111-1301, USA. | |
| 36 | + */ | |
| 37 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
| 38 | + | |
| 39 | +import java.io.IOException; | |
| 40 | +import java.util.Arrays; | |
| 41 | + | |
| 42 | +import javax.servlet.Filter; | |
| 43 | +import javax.servlet.FilterChain; | |
| 44 | +import javax.servlet.FilterConfig; | |
| 45 | +import javax.servlet.ServletException; | |
| 46 | +import javax.servlet.ServletRequest; | |
| 47 | +import javax.servlet.ServletResponse; | |
| 48 | +import javax.servlet.http.HttpServletRequest; | |
| 49 | + | |
| 50 | +import org.apache.commons.codec.binary.Base64; | |
| 51 | + | |
| 52 | +import br.gov.frameworkdemoiselle.security.AuthenticationException; | |
| 53 | +import br.gov.frameworkdemoiselle.security.Credentials; | |
| 54 | +import br.gov.frameworkdemoiselle.security.SecurityContext; | |
| 55 | +import br.gov.frameworkdemoiselle.util.Beans; | |
| 56 | + | |
| 57 | +public class BasicAuthenticationFilter implements Filter { | |
| 58 | + | |
| 59 | + @Override | |
| 60 | + public void init(FilterConfig filterConfig) throws ServletException { | |
| 61 | + } | |
| 62 | + | |
| 63 | + @Override | |
| 64 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
| 65 | + ServletException { | |
| 66 | + | |
| 67 | + String[] basicCredentials = getCredentials((HttpServletRequest) request); | |
| 68 | + | |
| 69 | + if (basicCredentials != null) { | |
| 70 | + Credentials credentials = Beans.getReference(Credentials.class); | |
| 71 | + credentials.setUsername(basicCredentials[0]); | |
| 72 | + credentials.setPassword(basicCredentials[1]); | |
| 73 | + | |
| 74 | + try { | |
| 75 | + Beans.getReference(SecurityContext.class).login(); | |
| 76 | + | |
| 77 | + } catch (AuthenticationException cause) { | |
| 78 | + // TODO Informar via logger que a autenticação não foi bem sucedida. | |
| 79 | + } | |
| 80 | + } | |
| 81 | + | |
| 82 | + chain.doFilter(request, response); | |
| 83 | + } | |
| 84 | + | |
| 85 | + private String getAuthHeader(HttpServletRequest request) { | |
| 86 | + String result = request.getHeader("Authorization"); | |
| 87 | + result = (result == null ? request.getHeader("authorization") : result); | |
| 88 | + | |
| 89 | + return result; | |
| 90 | + } | |
| 91 | + | |
| 92 | + private String[] getCredentials(HttpServletRequest request) { | |
| 93 | + String[] result = null; | |
| 94 | + String header = getAuthHeader(request); | |
| 95 | + | |
| 96 | + if (header != null) { | |
| 97 | + byte[] decoded = Base64.decodeBase64(header.substring(6)); | |
| 98 | + result = new String(decoded).split(":"); | |
| 99 | + } | |
| 100 | + | |
| 101 | + if (result != null && Arrays.asList(result).size() != 2) { | |
| 102 | + result = null; | |
| 103 | + | |
| 104 | + // TODO Informar via logger que o header Authorization não contém as informações de username e password | |
| 105 | + } | |
| 106 | + | |
| 107 | + return result; | |
| 108 | + } | |
| 109 | + | |
| 110 | + @Override | |
| 111 | + public void destroy() { | |
| 112 | + } | |
| 113 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/HttpServletRequestProducerFilter.java
0 → 100644
| ... | ... | @@ -0,0 +1,32 @@ |
| 1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
| 2 | + | |
| 3 | +import java.io.IOException; | |
| 4 | + | |
| 5 | +import javax.servlet.Filter; | |
| 6 | +import javax.servlet.FilterChain; | |
| 7 | +import javax.servlet.FilterConfig; | |
| 8 | +import javax.servlet.ServletException; | |
| 9 | +import javax.servlet.ServletRequest; | |
| 10 | +import javax.servlet.ServletResponse; | |
| 11 | +import javax.servlet.http.HttpServletRequest; | |
| 12 | + | |
| 13 | +import br.gov.frameworkdemoiselle.internal.producer.HttpServletRequestProducer; | |
| 14 | +import br.gov.frameworkdemoiselle.util.Beans; | |
| 15 | + | |
| 16 | +public class HttpServletRequestProducerFilter implements Filter { | |
| 17 | + | |
| 18 | + @Override | |
| 19 | + public void init(FilterConfig config) throws ServletException { | |
| 20 | + } | |
| 21 | + | |
| 22 | + @Override | |
| 23 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
| 24 | + ServletException { | |
| 25 | + Beans.getReference(HttpServletRequestProducer.class).setDelegate((HttpServletRequest) request); | |
| 26 | + chain.doFilter(request, response); | |
| 27 | + } | |
| 28 | + | |
| 29 | + @Override | |
| 30 | + public void destroy() { | |
| 31 | + } | |
| 32 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/HttpServletResponseProducerFilter.java
0 → 100644
| ... | ... | @@ -0,0 +1,32 @@ |
| 1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
| 2 | + | |
| 3 | +import java.io.IOException; | |
| 4 | + | |
| 5 | +import javax.servlet.Filter; | |
| 6 | +import javax.servlet.FilterChain; | |
| 7 | +import javax.servlet.FilterConfig; | |
| 8 | +import javax.servlet.ServletException; | |
| 9 | +import javax.servlet.ServletRequest; | |
| 10 | +import javax.servlet.ServletResponse; | |
| 11 | +import javax.servlet.http.HttpServletResponse; | |
| 12 | + | |
| 13 | +import br.gov.frameworkdemoiselle.internal.producer.HttpServletResponseProducer; | |
| 14 | +import br.gov.frameworkdemoiselle.util.Beans; | |
| 15 | + | |
| 16 | +public class HttpServletResponseProducerFilter implements Filter { | |
| 17 | + | |
| 18 | + @Override | |
| 19 | + public void init(FilterConfig config) throws ServletException { | |
| 20 | + } | |
| 21 | + | |
| 22 | + @Override | |
| 23 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
| 24 | + ServletException { | |
| 25 | + Beans.getReference(HttpServletResponseProducer.class).setDelegate((HttpServletResponse) response); | |
| 26 | + chain.doFilter(request, response); | |
| 27 | + } | |
| 28 | + | |
| 29 | + @Override | |
| 30 | + public void destroy() { | |
| 31 | + } | |
| 32 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/internal/implementation/InternalProcessorFilterImpl.java
0 → 100644
| ... | ... | @@ -0,0 +1,62 @@ |
| 1 | +package br.gov.frameworkdemoiselle.internal.implementation; | |
| 2 | + | |
| 3 | +import java.io.IOException; | |
| 4 | +import java.util.ArrayList; | |
| 5 | +import java.util.List; | |
| 6 | + | |
| 7 | +import javax.servlet.Filter; | |
| 8 | +import javax.servlet.FilterChain; | |
| 9 | +import javax.servlet.FilterConfig; | |
| 10 | +import javax.servlet.ServletException; | |
| 11 | +import javax.servlet.ServletRequest; | |
| 12 | +import javax.servlet.ServletResponse; | |
| 13 | + | |
| 14 | +import br.gov.frameworkdemoiselle.annotation.StaticScoped; | |
| 15 | +import br.gov.frameworkdemoiselle.util.ServletFilter.InternalProcessorFilter; | |
| 16 | + | |
| 17 | +@StaticScoped | |
| 18 | +public class InternalProcessorFilterImpl implements InternalProcessorFilter { | |
| 19 | + | |
| 20 | + private List<Filter> filters; | |
| 21 | + | |
| 22 | + public InternalProcessorFilterImpl() { | |
| 23 | + filters = new ArrayList<Filter>(); | |
| 24 | + | |
| 25 | + filters.add(new HttpServletRequestProducerFilter()); | |
| 26 | + filters.add(new HttpServletResponseProducerFilter()); | |
| 27 | + filters.add(new BasicAuthenticationFilter()); | |
| 28 | + } | |
| 29 | + | |
| 30 | + @Override | |
| 31 | + public void init(FilterConfig config) throws ServletException { | |
| 32 | + for (Filter filter : filters) { | |
| 33 | + filter.init(config); | |
| 34 | + } | |
| 35 | + } | |
| 36 | + | |
| 37 | + @Override | |
| 38 | + public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, | |
| 39 | + ServletException { | |
| 40 | + FilterChain emptyChain = createEmptyChain(); | |
| 41 | + | |
| 42 | + for (Filter filter : filters) { | |
| 43 | + filter.doFilter(request, response, emptyChain); | |
| 44 | + } | |
| 45 | + } | |
| 46 | + | |
| 47 | + @Override | |
| 48 | + public void destroy() { | |
| 49 | + for (Filter filter : filters) { | |
| 50 | + filter.destroy(); | |
| 51 | + } | |
| 52 | + } | |
| 53 | + | |
| 54 | + private FilterChain createEmptyChain() { | |
| 55 | + return new FilterChain() { | |
| 56 | + | |
| 57 | + @Override | |
| 58 | + public void doFilter(ServletRequest request, ServletResponse response) throws IOException, ServletException { | |
| 59 | + } | |
| 60 | + }; | |
| 61 | + } | |
| 62 | +} | ... | ... |
impl/extension/servlet/src/main/java/br/gov/frameworkdemoiselle/util/ServletFilter.java
| ... | ... | @@ -44,36 +44,27 @@ import javax.servlet.FilterConfig; |
| 44 | 44 | import javax.servlet.ServletException; |
| 45 | 45 | import javax.servlet.ServletRequest; |
| 46 | 46 | import javax.servlet.ServletResponse; |
| 47 | -import javax.servlet.http.HttpServletRequest; | |
| 48 | -import javax.servlet.http.HttpServletResponse; | |
| 49 | - | |
| 50 | -import br.gov.frameworkdemoiselle.internal.producer.HttpServletRequestProducer; | |
| 51 | -import br.gov.frameworkdemoiselle.internal.producer.HttpServletResponseProducer; | |
| 52 | 47 | |
| 53 | 48 | public class ServletFilter implements Filter { |
| 54 | 49 | |
| 55 | 50 | @Override |
| 56 | - public void init(FilterConfig filterConfig) throws ServletException { | |
| 51 | + public void init(FilterConfig config) throws ServletException { | |
| 52 | + Beans.getReference(InternalProcessorFilter.class).init(config); | |
| 57 | 53 | } |
| 58 | 54 | |
| 59 | 55 | @Override |
| 60 | 56 | public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, |
| 61 | 57 | ServletException { |
| 62 | - | |
| 63 | - Beans.getReference(HttpServletRequestProducer.class).setDelegate((HttpServletRequest) request); | |
| 64 | - Beans.getReference(HttpServletResponseProducer.class).setDelegate((HttpServletResponse) response); | |
| 65 | - | |
| 66 | - // X509Certificate[] certificates = (X509Certificate[]) ((HttpServletRequest) request) | |
| 67 | - // .getAttribute("javax.servlet.request.X509Certificate"); | |
| 68 | - // | |
| 69 | - // for (X509Certificate certificate : certificates) { | |
| 70 | - // System.out.println(certificate.toString()); | |
| 71 | - // } | |
| 58 | + Beans.getReference(InternalProcessorFilter.class).doFilter(request, response, chain); | |
| 72 | 59 | |
| 73 | 60 | chain.doFilter(request, response); |
| 74 | 61 | } |
| 75 | 62 | |
| 76 | 63 | @Override |
| 77 | 64 | public void destroy() { |
| 65 | + Beans.getReference(InternalProcessorFilter.class).destroy(); | |
| 66 | + } | |
| 67 | + | |
| 68 | + public interface InternalProcessorFilter extends Filter { | |
| 78 | 69 | } |
| 79 | 70 | } | ... | ... |