DigestAuthenticationFilter.java

/*
** Module   : DigestAuthenticationFilter.java
** Abstract : Sets the credentials for the Digest challenge.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------------Description----------------------------------------
** 001 CA  20190924 First version.
** 002 CA  20191024 Added method support levels and updated the class support level.
** 003 ME  20201111 Remove dependency on StringUtils, cosmetics.
**     CA  20220120 Do not used TypeFactory.object when the OO reference must not be tracked or registered.
**                  Do not use TypeFactory.object for internal usages, use ObjectVar if the reference must 
**                  be tracked.
**                  All TypeFactory.object variable definitions must be done outside of the top-level block.
**     CA  20220923 Variable definitions (including associated with parameters) must be done always outside of 
**                  the BlockManager API
** 004 CA  20231113 The 'execute' method must be annotated with LegacySignature Type.Execute, and also can be
**                  dropped if is a no-op.
*/

/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.oo.net.http.filter.auth;

import com.goldencode.p2j.oo.core.Assert;
import com.goldencode.p2j.oo.net.http.Credentials;
import com.goldencode.p2j.oo.net.http.HttpHeaderBuilder;
import com.goldencode.p2j.oo.net.http.IAuthenticatedRequest;
import com.goldencode.p2j.oo.net.http.IhttpRequest;
import com.goldencode.p2j.util.*;
import com.goldencode.p2j.util.BlockManager.Action;
import com.goldencode.p2j.util.BlockManager.Condition;
import com.goldencode.p2j.util.InternalEntry.Type;

import java.util.HashMap;

import static com.goldencode.p2j.report.ReportConstants.*;
import static com.goldencode.p2j.util.BlockManager.*;


/**
 * 
 * Sets the credentials for the Digest challenge. These will be
 * encoded per http://tools.ietf.org/html/rfc2617.
 *
 */
@LegacyResource(resource = "OpenEdge.Net.HTTP.Filter.Auth.DigestAuthenticationFilter")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public class DigestAuthenticationFilter extends AuthenticationRequestFilter
{
   /* List of nounces */
   protected HashMap<character, integer> nonceList = new HashMap<character, integer>();
   
   @LegacySignature(type = Type.EXECUTE)
   public void __net_http_filter_auth_DigestAuthenticationFilter_execute__()
   {
      onBlockLevel(Condition.ERROR, Action.THROW);
   }

   @LegacySignature(type = Type.CONSTRUCTOR, parameters = {
            @LegacyParameter(name = "poRequest", type = "OBJECT", qualified = "openedge.net.http.iauthenticatedrequest", mode = "INPUT") })
   @LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
   public void __net_http_filter_auth_DigestAuthenticationFilter_constructor__(
            final object<? extends IAuthenticatedRequest> _poRequest)
   {
      object<? extends IAuthenticatedRequest> poRequest = TypeFactory.initInput(_poRequest);

      internalProcedure(DigestAuthenticationFilter.class, this,
               "__net_http_filter_auth_DigestAuthenticationFilter_constructor__",
               new Block((Body) () ->
               {
                  __net_http_filter_auth_AuthenticationRequestFilter_constructor__(poRequest);
               }));
   }

   @LegacySignature(type = Type.DESTRUCTOR)
   @LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
   public void __net_http_filter_auth_DigestAuthenticationFilter_destructor__()
   {
      internalProcedure(DigestAuthenticationFilter.class, this,
               "__net_http_filter_auth_DigestAuthenticationFilter_destructor__", new Block((Body) () ->
               {
                  nonceList.clear();
               }));
   }

   /**
    *  Build the actual authentication. 
    */
   @LegacySignature(type = Type.METHOD, name = "AddAuthentication")
   @LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
   @Override
   protected void addAuthetication()
   {
      object<? extends Credentials> oCredentials = TypeFactory.object(Credentials.class);
      object<? extends IhttpRequest> oRequest = TypeFactory.object(IhttpRequest.class);
      character cRealm = TypeFactory.character();
      character cDomain = TypeFactory.character();
      character cNonce = TypeFactory.character();
      character cOpaque = TypeFactory.character();
      logical lStale = TypeFactory.logical();
      character cAlgorithm = TypeFactory.character();
      character cQualityOfProtection = TypeFactory.character();
      logical lServerSentQoP = TypeFactory.logical();
      raw rHash1 = TypeFactory.raw();
      raw rHash2 = TypeFactory.raw();
      raw rResponse = TypeFactory.raw();
      character cCredentials = TypeFactory.character();
      character cClientNonce = TypeFactory.character();
      character paramValue = TypeFactory.character();
      
      internalProcedure(DigestAuthenticationFilter.class, this, "AddAuthentication", new Block((Body) () ->
      {
         cRealm.setUnknown();
         cDomain.setUnknown();
         cNonce.setUnknown();
         cOpaque.setUnknown();
         lStale.setUnknown();
         
         oRequest.assign(this.getMessage());
         character cChallengeInit = this.getAuthenticatedRequest().ref().getAuthenticationChallenge();
         
         if (!cChallengeInit.isUnknown())
         {
            int jPos = cChallengeInit.getValue().indexOf(" ");
            String jSChallenge = cChallengeInit.getValue().substring(jPos + 1);
            
            for(String elem : jSChallenge.split(","))
            {
               String[] entries = TextOps.entries(elem, "=");

               String entryKey = entries[0].trim().toLowerCase();
               paramValue.assign(entries.length == 1 ? new character("") : TextOps.trim(entries[1], " \""));
               
               switch (entryKey) {
                  case "realm":
                     cRealm.assign(paramValue);                                    
                     break;
                  case "domain":
                     cDomain.assign(paramValue);
                     break;
                  case "nonce":
                     cNonce.assign(paramValue);
                     break;
                  case "opaque":
                     cOpaque.assign(paramValue);
                     break;
                  case "stale":
                     lStale.assign(paramValue);
                     break;
                  case "algorithm":
                     cAlgorithm.assign(paramValue);
                     break;
                  case "qop":
                     cQualityOfProtection.assign(paramValue);
                     lServerSentQoP.assign(new logical(true));
                     break;
               }            
            }
         }
         
         Assert.notNull(cRealm, new character("Realm"));
         Assert.notNull(cNonce, new character("Nonce"));
         
         oCredentials.assign(this.getCredentials(cRealm));
         Assert.notNull(oCredentials, new character("Credentials"));
         
         cClientNonce.assign(SecurityOps.hexEncode(SecurityOps.generateUUID()));
         
         String intToHex8Pad = Integer.toHexString(NextNonceCount(cNonce));
         character cToHex8Pad = TextOps.substitute("&1&2", character.fill("0", 8 - intToHex8Pad.length()), intToHex8Pad);
         
         switch(cAlgorithm.getValue())
         {
            case "MD5-sess":
               rHash1.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3", 
                        SecurityOps.hexEncode(
                                 SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3", 
                                          oCredentials.ref().getUserName(),
                                          cRealm,
                                          oCredentials.ref().getPassword()))), 
                        cNonce, 
                        cClientNonce)
                        ));
               break;
            case "MD5": case "":
               rHash1.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3", 
                        oCredentials.ref().getUserName(),
                        cRealm,
                        oCredentials.ref().getPassword())
                        ));
               break;   
         }
         Assert.isPositive(rHash1.length(), new character("First hash"));
         
         switch(cQualityOfProtection.getValue())
         {
            case "":
               rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2",
                        oRequest.ref().getMethod(),
                        oRequest.ref().getUri().ref().getRelativeUri())                       
                        ));
               rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3", 
                        SecurityOps.hexEncode(rHash1),
                        cNonce,
                        SecurityOps.hexEncode(rHash2))
                        ));
               break;
            case "auth":
               rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2",
                        oRequest.ref().getMethod(),
                        oRequest.ref().getUri().ref().getRelativeUri())                       
                        ));
               rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3:&4:&5:&6", 
                        SecurityOps.hexEncode(rHash1),
                        cNonce,
                        cToHex8Pad,
                        cClientNonce,
                        cQualityOfProtection,
                        SecurityOps.hexEncode(rHash2))
                        ));
               break;
            case "auth-int":
               rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
                        oRequest.ref().getMethod(),
                        oRequest.ref().getUri().ref().getRelativeUri(), 
                        oRequest.ref().getContentMd5())                       
                        ));
               rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3:&4:&5:&6", 
                        SecurityOps.hexEncode(rHash1),
                        cNonce,
                        cToHex8Pad,
                        cClientNonce,
                        cQualityOfProtection,
                        SecurityOps.hexEncode(rHash2))
                        ));               
               break;
         }
         Assert.isPositive(rHash2.length(), new character("Second hash"));
         Assert.isPositive(rResponse.length(), new character("Response hash"));
         
         cCredentials.assign(TextOps.substitute("Digest username=\"&1\",realm=\"&2\",nonce=\"&3\",uri=\"&4\",response=\"&5\"", 
                  oCredentials.ref().getUserName(),
                  cRealm,
                  cNonce,
                  oRequest.ref().getUri().ref().getRelativeUri(),
                  SecurityOps.hexEncode(rResponse)
                  ));
         
         if (!cAlgorithm.getValue().isEmpty())
         {
            cCredentials.assign(TextOps.substitute("&1,algorithm=&2", cCredentials, cAlgorithm));
         }
         
         if (!cOpaque.isUnknown())
         {
            cCredentials.assign(TextOps.substitute("&1,opaque=\"&2\"", cCredentials, cOpaque));
         }
         
         if (lServerSentQoP.booleanValue())
         {
            cCredentials.assign(TextOps.substitute("&1,cnonce=\"&2\",nc=&3,qop=\"&4\"", 
                     cCredentials, 
                     cClientNonce,
                     cToHex8Pad,
                     cQualityOfProtection));
         }
         
         oRequest.ref().setHeader(HttpHeaderBuilder.build(new character("Authorization")).ref().
                  value(cCredentials).ref().getHeader());
                          
      }));
   }
   
   private int NextNonceCount(character pNonce)
   {
      
      integer count = nonceList.get(pNonce); 
      
      if (count != null) 
      {
         count.assign(count.intValue() + 1);
      }
      else 
      {
         count = TypeFactory.integer(1L);
         nonceList.put(pNonce, count);
      }

      return count.intValue();
   }   
}