DigestAuthenticationFilter.java
/*
** Module : DigestAuthenticationFilter.java
** Abstract : Sets the credentials for the Digest challenge.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------------Description----------------------------------------
** 001 CA 20190924 First version.
** 002 CA 20191024 Added method support levels and updated the class support level.
** 003 ME 20201111 Remove dependency on StringUtils, cosmetics.
** CA 20220120 Do not used TypeFactory.object when the OO reference must not be tracked or registered.
** Do not use TypeFactory.object for internal usages, use ObjectVar if the reference must
** be tracked.
** All TypeFactory.object variable definitions must be done outside of the top-level block.
** CA 20220923 Variable definitions (including associated with parameters) must be done always outside of
** the BlockManager API
** 004 CA 20231113 The 'execute' method must be annotated with LegacySignature Type.Execute, and also can be
** dropped if is a no-op.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.oo.net.http.filter.auth;
import com.goldencode.p2j.oo.core.Assert;
import com.goldencode.p2j.oo.net.http.Credentials;
import com.goldencode.p2j.oo.net.http.HttpHeaderBuilder;
import com.goldencode.p2j.oo.net.http.IAuthenticatedRequest;
import com.goldencode.p2j.oo.net.http.IhttpRequest;
import com.goldencode.p2j.util.*;
import com.goldencode.p2j.util.BlockManager.Action;
import com.goldencode.p2j.util.BlockManager.Condition;
import com.goldencode.p2j.util.InternalEntry.Type;
import java.util.HashMap;
import static com.goldencode.p2j.report.ReportConstants.*;
import static com.goldencode.p2j.util.BlockManager.*;
/**
*
* Sets the credentials for the Digest challenge. These will be
* encoded per http://tools.ietf.org/html/rfc2617.
*
*/
@LegacyResource(resource = "OpenEdge.Net.HTTP.Filter.Auth.DigestAuthenticationFilter")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public class DigestAuthenticationFilter extends AuthenticationRequestFilter
{
/* List of nounces */
protected HashMap<character, integer> nonceList = new HashMap<character, integer>();
@LegacySignature(type = Type.EXECUTE)
public void __net_http_filter_auth_DigestAuthenticationFilter_execute__()
{
onBlockLevel(Condition.ERROR, Action.THROW);
}
@LegacySignature(type = Type.CONSTRUCTOR, parameters = {
@LegacyParameter(name = "poRequest", type = "OBJECT", qualified = "openedge.net.http.iauthenticatedrequest", mode = "INPUT") })
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public void __net_http_filter_auth_DigestAuthenticationFilter_constructor__(
final object<? extends IAuthenticatedRequest> _poRequest)
{
object<? extends IAuthenticatedRequest> poRequest = TypeFactory.initInput(_poRequest);
internalProcedure(DigestAuthenticationFilter.class, this,
"__net_http_filter_auth_DigestAuthenticationFilter_constructor__",
new Block((Body) () ->
{
__net_http_filter_auth_AuthenticationRequestFilter_constructor__(poRequest);
}));
}
@LegacySignature(type = Type.DESTRUCTOR)
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
public void __net_http_filter_auth_DigestAuthenticationFilter_destructor__()
{
internalProcedure(DigestAuthenticationFilter.class, this,
"__net_http_filter_auth_DigestAuthenticationFilter_destructor__", new Block((Body) () ->
{
nonceList.clear();
}));
}
/**
* Build the actual authentication.
*/
@LegacySignature(type = Type.METHOD, name = "AddAuthentication")
@LegacyResourceSupport(supportLvl = CVT_LVL_FULL | RT_LVL_FULL)
@Override
protected void addAuthetication()
{
object<? extends Credentials> oCredentials = TypeFactory.object(Credentials.class);
object<? extends IhttpRequest> oRequest = TypeFactory.object(IhttpRequest.class);
character cRealm = TypeFactory.character();
character cDomain = TypeFactory.character();
character cNonce = TypeFactory.character();
character cOpaque = TypeFactory.character();
logical lStale = TypeFactory.logical();
character cAlgorithm = TypeFactory.character();
character cQualityOfProtection = TypeFactory.character();
logical lServerSentQoP = TypeFactory.logical();
raw rHash1 = TypeFactory.raw();
raw rHash2 = TypeFactory.raw();
raw rResponse = TypeFactory.raw();
character cCredentials = TypeFactory.character();
character cClientNonce = TypeFactory.character();
character paramValue = TypeFactory.character();
internalProcedure(DigestAuthenticationFilter.class, this, "AddAuthentication", new Block((Body) () ->
{
cRealm.setUnknown();
cDomain.setUnknown();
cNonce.setUnknown();
cOpaque.setUnknown();
lStale.setUnknown();
oRequest.assign(this.getMessage());
character cChallengeInit = this.getAuthenticatedRequest().ref().getAuthenticationChallenge();
if (!cChallengeInit.isUnknown())
{
int jPos = cChallengeInit.getValue().indexOf(" ");
String jSChallenge = cChallengeInit.getValue().substring(jPos + 1);
for(String elem : jSChallenge.split(","))
{
String[] entries = TextOps.entries(elem, "=");
String entryKey = entries[0].trim().toLowerCase();
paramValue.assign(entries.length == 1 ? new character("") : TextOps.trim(entries[1], " \""));
switch (entryKey) {
case "realm":
cRealm.assign(paramValue);
break;
case "domain":
cDomain.assign(paramValue);
break;
case "nonce":
cNonce.assign(paramValue);
break;
case "opaque":
cOpaque.assign(paramValue);
break;
case "stale":
lStale.assign(paramValue);
break;
case "algorithm":
cAlgorithm.assign(paramValue);
break;
case "qop":
cQualityOfProtection.assign(paramValue);
lServerSentQoP.assign(new logical(true));
break;
}
}
}
Assert.notNull(cRealm, new character("Realm"));
Assert.notNull(cNonce, new character("Nonce"));
oCredentials.assign(this.getCredentials(cRealm));
Assert.notNull(oCredentials, new character("Credentials"));
cClientNonce.assign(SecurityOps.hexEncode(SecurityOps.generateUUID()));
String intToHex8Pad = Integer.toHexString(NextNonceCount(cNonce));
character cToHex8Pad = TextOps.substitute("&1&2", character.fill("0", 8 - intToHex8Pad.length()), intToHex8Pad);
switch(cAlgorithm.getValue())
{
case "MD5-sess":
rHash1.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
SecurityOps.hexEncode(
SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
oCredentials.ref().getUserName(),
cRealm,
oCredentials.ref().getPassword()))),
cNonce,
cClientNonce)
));
break;
case "MD5": case "":
rHash1.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
oCredentials.ref().getUserName(),
cRealm,
oCredentials.ref().getPassword())
));
break;
}
Assert.isPositive(rHash1.length(), new character("First hash"));
switch(cQualityOfProtection.getValue())
{
case "":
rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2",
oRequest.ref().getMethod(),
oRequest.ref().getUri().ref().getRelativeUri())
));
rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
SecurityOps.hexEncode(rHash1),
cNonce,
SecurityOps.hexEncode(rHash2))
));
break;
case "auth":
rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2",
oRequest.ref().getMethod(),
oRequest.ref().getUri().ref().getRelativeUri())
));
rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3:&4:&5:&6",
SecurityOps.hexEncode(rHash1),
cNonce,
cToHex8Pad,
cClientNonce,
cQualityOfProtection,
SecurityOps.hexEncode(rHash2))
));
break;
case "auth-int":
rHash2.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3",
oRequest.ref().getMethod(),
oRequest.ref().getUri().ref().getRelativeUri(),
oRequest.ref().getContentMd5())
));
rResponse.assign(SecurityOps.md5Digest(TextOps.substitute("&1:&2:&3:&4:&5:&6",
SecurityOps.hexEncode(rHash1),
cNonce,
cToHex8Pad,
cClientNonce,
cQualityOfProtection,
SecurityOps.hexEncode(rHash2))
));
break;
}
Assert.isPositive(rHash2.length(), new character("Second hash"));
Assert.isPositive(rResponse.length(), new character("Response hash"));
cCredentials.assign(TextOps.substitute("Digest username=\"&1\",realm=\"&2\",nonce=\"&3\",uri=\"&4\",response=\"&5\"",
oCredentials.ref().getUserName(),
cRealm,
cNonce,
oRequest.ref().getUri().ref().getRelativeUri(),
SecurityOps.hexEncode(rResponse)
));
if (!cAlgorithm.getValue().isEmpty())
{
cCredentials.assign(TextOps.substitute("&1,algorithm=&2", cCredentials, cAlgorithm));
}
if (!cOpaque.isUnknown())
{
cCredentials.assign(TextOps.substitute("&1,opaque=\"&2\"", cCredentials, cOpaque));
}
if (lServerSentQoP.booleanValue())
{
cCredentials.assign(TextOps.substitute("&1,cnonce=\"&2\",nc=&3,qop=\"&4\"",
cCredentials,
cClientNonce,
cToHex8Pad,
cQualityOfProtection));
}
oRequest.ref().setHeader(HttpHeaderBuilder.build(new character("Authorization")).ref().
value(cCredentials).ref().getHeader());
}));
}
private int NextNonceCount(character pNonce)
{
integer count = nonceList.get(pNonce);
if (count != null)
{
count.assign(count.intValue() + 1);
}
else
{
count = TypeFactory.integer(1L);
nonceList.put(pNonce, count);
}
return count.intValue();
}
}