AuthServiceImpl.java

/*
** Module   : AuthServiceImpl.java
** Abstract : Authentication admin service
**
** Copyright (c) 2017-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ------------------------------Description----------------------------------
** 001 HC  20170612 Initial version.
** 002 GBB 20230825 SecurityManager context & session methods calls updated.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
**
**   0. Attribution Requirement.
**
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
**
**   1. No License To Use Trademarks.
**
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
**
**   2. No Misrepresentation of Affiliation.
**
**     You may not represent yourself as Golden Code Development Corporation or FWD.
**
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
**
**   3. No Misrepresentation of Source or Origin.
**
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/
package com.goldencode.p2j.admin.server;

import com.goldencode.p2j.admin.*;
import com.goldencode.p2j.security.*;
import com.google.gwt.user.server.rpc.RemoteServiceServlet;
import com.goldencode.p2j.admin.shared.AuthService;

import javax.servlet.http.*;

/**
 * Authentication admin service.
 */
public class AuthServiceImpl
extends RemoteServiceServlet
implements AuthService
{
   /** The session key used to track authentication status */
   private static final String AUTHENICATED_KEY = "admin_authenticated";

   /**
    * Returns <code>true</code> if the supplied request is authenticated
    *
    * @param   req
    *          The request to check.
    *
    * @return  see above
    */
   public static boolean isAuthenticated(HttpServletRequest req)
   {
      HttpSession s = req.getSession(false);
      return s != null && s.getAttribute(AUTHENICATED_KEY) != null;
   }


   /**
    * Authenticates the current servlet session based on the supplied authentication information.
    *
    * @param   userid
    *          User id.
    * @param   password
    *          Password.
    *
    * @return  the authentication status code, see SecurityConstants.AUTH_RES*
    */
   @Override
   public int login(String userid, String password)
   {
      HttpServletRequest req = getThreadLocalRequest();

      if (isAuthenticated(req))
      {
         logout();
      }

      com.goldencode.p2j.security.SecurityManager secMgr =
         com.goldencode.p2j.security.SecurityManager.getInstance();

      HttpSession s = req.getSession();

      int res = 0;
      try
      {
         res = secMgr.authenticateServer(s.getId(), userid, password);
         if (res == SecurityConstants.AUTH_RESULT_SUCCESS)
         {
            secMgr.contextSm.pushAndSwitchSecurityContextBySessionId(s.getId());
            try
            {
               AdminServerImpl.setTargetLive(true);
            }
            finally
            {
               secMgr.contextSm.popAndRestoreSecurityContext();
            }
         }
      }
      catch (RestrictedUseException e)
      {
         throw new RuntimeException(e);
      }
      finally
      {
         secMgr.contextSm.dropInitialSecurityContext();
      }

      if (res == SecurityConstants.AUTH_RESULT_SUCCESS)
      {
         s.setAttribute(AUTHENICATED_KEY, Boolean.TRUE);
      }

      return res;
   }

   /**
    * Logs out the currently logged in user.
    */
   @Override
   public void logout()
   {
      HttpServletRequest req = getThreadLocalRequest();
      HttpSession s = req.getSession(false);
      if (s != null)
      {
         s.setAttribute(AUTHENICATED_KEY, null);
      }

      com.goldencode.p2j.security.SecurityManager secMgr =
         com.goldencode.p2j.security.SecurityManager.getInstance();
      try
      {
         secMgr.sessionSm.terminateSessionById(s.getId());
      }
      catch (RestrictedUseException e)
      {
         throw new RuntimeException(e);
      }
   }
}