BasicAuthenticationFilter.java
/*
** Module : BasicAuthenticationFilter.java
** Abstract : Implementation of the builtin class.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- -------------------------------Description--------------------------------
** 001 IAS 20190923 First version.
** 002 ME 20200508 Implementation as of OE 11.7.4.
** 20201109 Replace string format with substitute.
** CA 20220923 Variable definitions (including associated with parameters) must be done always outside of
** the BlockManager API
** 003 CA 20231113 The 'execute' method must be annotated with LegacySignature Type.Execute, and also can be
** dropped if is a no-op.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.oo.net.http.filter.auth;
import com.goldencode.p2j.oo.core.Assert;
import com.goldencode.p2j.oo.lang.*;
import com.goldencode.p2j.oo.net.http.Credentials;
import com.goldencode.p2j.oo.net.http.HttpHeaderBuilder;
import com.goldencode.p2j.oo.net.http.IAuthenticatedRequest;
import com.goldencode.p2j.util.*;
import com.goldencode.p2j.util.BlockManager.Action;
import com.goldencode.p2j.util.BlockManager.Condition;
import com.goldencode.p2j.util.InternalEntry.*;
import static com.goldencode.p2j.report.ReportConstants.*;
import static com.goldencode.p2j.util.BlockManager.*;
/**
*
* Sets the credentials for the Basic challenge. These will be
* encoded per http://tools.ietf.org/html/rfc2617
*
*/
@LegacyResource(resource = "OpenEdge.Net.HTTP.Filter.Auth.BasicAuthenticationFilter")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public class BasicAuthenticationFilter extends AuthenticationRequestFilter
{
@LegacySignature(type = Type.EXECUTE)
public void __net_http_filter_auth_BasicAuthenticationFilter_execute__()
{
onBlockLevel(Condition.ERROR, Action.THROW);
}
@LegacySignature(type = Type.CONSTRUCTOR, parameters = {
@LegacyParameter(name = "poRequest", type = "OBJECT", qualified = "openedge.net.http.iauthenticatedrequest", mode = "INPUT") })
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public void __net_http_filter_auth_BasicAuthenticationFilter_constructor__(
final object<? extends IAuthenticatedRequest> _poRequest)
{
object<? extends IAuthenticatedRequest> poRequest = TypeFactory.initInput(_poRequest);
internalProcedure(BasicAuthenticationFilter.class, this,
"__net_http_filter_auth_BasicAuthenticationFilter_constructor__",
new Block((Body) () ->
{
__net_http_filter_auth_AuthenticationRequestFilter_constructor__(poRequest);
}));
}
/**
* Build the actual authentication.
*/
@LegacySignature(type = Type.METHOD, name = "AddAuthentication")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
@Override
protected void addAuthetication()
{
character cCredentials = TypeFactory.character();
internalProcedure(BasicAuthenticationFilter.class, this, "AddAuthentication",
new Block((Body) () ->
{
character realm = TextOps.trim(TextOps.entry(2,
getAuthenticatedRequest().ref().getAuthenticationChallenge(), "="),
"\"");
Assert.notNull(realm, new character("Realm"));
object<? extends Credentials> credentials = getCredentials(realm);
if (!credentials._isValid())
undoThrow(AppError.newInstance(
TextOps.substitute("Missing credentials for realm \"&1\"", realm), new integer(0)));
cCredentials.assign(TextOps.substitute( "&1:&2", credentials.ref().getUserName(), credentials.ref().getPassword()));
longchar authHeader = SecurityOps.base64Encode(cCredentials.getValue().getBytes());
getMessage().ref()
.setHeader(HttpHeaderBuilder.build(new character("Authorization"))
.ref()
.value(TextOps.substitute("Basic &1", authHeader))
.ref().getHeader());
}));
}
}