BasicAuthenticationFilter.java

/*
** Module   : BasicAuthenticationFilter.java
** Abstract : Implementation of the builtin class.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- -------------------------------Description--------------------------------
** 001 IAS 20190923 First version.
** 002 ME  20200508 Implementation as of OE 11.7.4.
**         20201109 Replace string format with substitute.
**     CA  20220923 Variable definitions (including associated with parameters) must be done always outside of 
**                  the BlockManager API
** 003 CA  20231113 The 'execute' method must be annotated with LegacySignature Type.Execute, and also can be
**                  dropped if is a no-op.
*/

/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.oo.net.http.filter.auth;

import com.goldencode.p2j.oo.core.Assert;
import com.goldencode.p2j.oo.lang.*;
import com.goldencode.p2j.oo.net.http.Credentials;
import com.goldencode.p2j.oo.net.http.HttpHeaderBuilder;
import com.goldencode.p2j.oo.net.http.IAuthenticatedRequest;
import com.goldencode.p2j.util.*;
import com.goldencode.p2j.util.BlockManager.Action;
import com.goldencode.p2j.util.BlockManager.Condition;
import com.goldencode.p2j.util.InternalEntry.*;

import static com.goldencode.p2j.report.ReportConstants.*;
import static com.goldencode.p2j.util.BlockManager.*;

/**
 * 
 * Sets the credentials for the Basic challenge. These will be
 * encoded per http://tools.ietf.org/html/rfc2617
 *
 */
@LegacyResource(resource = "OpenEdge.Net.HTTP.Filter.Auth.BasicAuthenticationFilter")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public class BasicAuthenticationFilter extends AuthenticationRequestFilter
{
   @LegacySignature(type = Type.EXECUTE)
   public void __net_http_filter_auth_BasicAuthenticationFilter_execute__()
   {
      onBlockLevel(Condition.ERROR, Action.THROW);
   }

   @LegacySignature(type = Type.CONSTRUCTOR, parameters = {
            @LegacyParameter(name = "poRequest", type = "OBJECT", qualified = "openedge.net.http.iauthenticatedrequest", mode = "INPUT") })
   @LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
   public void __net_http_filter_auth_BasicAuthenticationFilter_constructor__(
            final object<? extends IAuthenticatedRequest> _poRequest)
   {
      object<? extends IAuthenticatedRequest> poRequest = TypeFactory.initInput(_poRequest);

      internalProcedure(BasicAuthenticationFilter.class, this,
               "__net_http_filter_auth_BasicAuthenticationFilter_constructor__",
               new Block((Body) () ->
               {
                  __net_http_filter_auth_AuthenticationRequestFilter_constructor__(poRequest);
               }));
   }

   /**
    *  Build the actual authentication. 
    */
   @LegacySignature(type = Type.METHOD, name = "AddAuthentication")
   @LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
   @Override
   protected void addAuthetication()
   {
      character cCredentials = TypeFactory.character();

      internalProcedure(BasicAuthenticationFilter.class, this, "AddAuthentication",
               new Block((Body) () ->
               {
                  character realm = TextOps.trim(TextOps.entry(2,
                           getAuthenticatedRequest().ref().getAuthenticationChallenge(), "="),
                           "\"");

                  Assert.notNull(realm, new character("Realm"));

                  object<? extends Credentials> credentials = getCredentials(realm);

                  if (!credentials._isValid())
                     undoThrow(AppError.newInstance(
                              TextOps.substitute("Missing credentials for realm \"&1\"", realm), new integer(0)));

                                    
                  cCredentials.assign(TextOps.substitute( "&1:&2", credentials.ref().getUserName(), credentials.ref().getPassword()));
                  
                  longchar authHeader = SecurityOps.base64Encode(cCredentials.getValue().getBytes());
                                
                  getMessage().ref()
                           .setHeader(HttpHeaderBuilder.build(new character("Authorization"))
                                    .ref()
                                    .value(TextOps.substitute("Basic &1", authHeader))
                                    .ref().getHeader());
               }));
   }
}