ContextSwitcher.java

/*
** Module   : ContextSwitcher.java
** Abstract : Allows access to a worker to switch contexts, but only if first it could authenticate first.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------------Description----------------------------------------
** 001 CA  20190719 Created initial version.
** 002 CA  20220405 Added authentication and authorization for web requests.  When this is enabled, the target
**                  API call will be executed under the authenticated FWD context, and not the agent's context.
** 003 GBB 20230825 SecurityManager context methods calls updated.
*/

/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

/**
 * Instance to allow a thread to switch context to another session.  This will be provided only
 * if the thread can authenticate first.
 *
 */
public final class ContextSwitcher
{
   /** Security manager cache. */
   private final SecurityManager sm;
   
   /** 
    * If this context had an additional security context when {@link #setContext context was switched}, this 
    * will be restored on {@link #releaseContext release}.
    */
   private SecurityContext additional = null;
   
   /**
    * Create a new instance, allow only by the security package.
    */
   ContextSwitcher() 
   {
      sm = SecurityManager.getInstance(); 
   }
   
   /**
    * Switch the context to the specified session ID.
    * 
    * @param    sessionId
    *           The session ID.
    */
   public void setContext(Object sessionId)
   {
      setContext(sessionId, true);
   }
   
   /**
    * Release the current context.
    */
   public void releaseContext()
   {
      releaseContext(true);
   }
   
   /**
    * Switch the context to the specified session ID.
    * 
    * @param    sessionId
    *           The session ID.
    * @param    useInitial
    *           Flag indicating to create an initial security context.
    */
   void setContext(Object sessionId, boolean useInitial)
   {
      try
      {
         if (!useInitial)
         {
            SecurityContextStack cts = SecurityContextStack.getContext();
            
            if (cts == null)
            {
               throw new RestrictedUseException("no security context established");
            }

            additional = cts.pop();
            
            // there may be no additional context to pop
         }
         else
         {
            sm.contextSm.setUniqueInitialSecurityContext();
         }
         
         sm.contextSm.pushAndSwitchSecurityContextBySessionId(sessionId);
      }
      catch (RestrictedUseException ru)
      {
         throw new RuntimeException("Invalid security context switch");
      }
   }
   
   /**
    * Release the current context.
    * 
    * @param    useInitial
    *           Flag indicating to drop the initial security context.
    */
   void releaseContext(boolean useInitial)
   {
      try
      {
         sm.contextSm.popAndRestoreSecurityContext();
         
         if (!useInitial)
         {
            SecurityContext ctx = additional;
            additional = null;
            
            SecurityContextStack cts = SecurityContextStack.getContext();
            
            if (cts == null)
            {
               throw new RestrictedUseException("no security context established");
            }

            // if there was an additional context, restore it.
            if (ctx != null && !cts.push(ctx))
            {
               throw new RestrictedUseException("illegal context switch");
            }
         }
         else
         {
            sm.contextSm.dropInitialSecurityContext();
         }
      }
      catch (RestrictedUseException exc)
      {
         throw new RuntimeException("Invalid security context switch");
      }
   }
}