ContextSwitcher.java
/*
** Module : ContextSwitcher.java
** Abstract : Allows access to a worker to switch contexts, but only if first it could authenticate first.
**
** Copyright (c) 2019-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------------Description----------------------------------------
** 001 CA 20190719 Created initial version.
** 002 CA 20220405 Added authentication and authorization for web requests. When this is enabled, the target
** API call will be executed under the authenticated FWD context, and not the agent's context.
** 003 GBB 20230825 SecurityManager context methods calls updated.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
/**
* Instance to allow a thread to switch context to another session. This will be provided only
* if the thread can authenticate first.
*
*/
public final class ContextSwitcher
{
/** Security manager cache. */
private final SecurityManager sm;
/**
* If this context had an additional security context when {@link #setContext context was switched}, this
* will be restored on {@link #releaseContext release}.
*/
private SecurityContext additional = null;
/**
* Create a new instance, allow only by the security package.
*/
ContextSwitcher()
{
sm = SecurityManager.getInstance();
}
/**
* Switch the context to the specified session ID.
*
* @param sessionId
* The session ID.
*/
public void setContext(Object sessionId)
{
setContext(sessionId, true);
}
/**
* Release the current context.
*/
public void releaseContext()
{
releaseContext(true);
}
/**
* Switch the context to the specified session ID.
*
* @param sessionId
* The session ID.
* @param useInitial
* Flag indicating to create an initial security context.
*/
void setContext(Object sessionId, boolean useInitial)
{
try
{
if (!useInitial)
{
SecurityContextStack cts = SecurityContextStack.getContext();
if (cts == null)
{
throw new RestrictedUseException("no security context established");
}
additional = cts.pop();
// there may be no additional context to pop
}
else
{
sm.contextSm.setUniqueInitialSecurityContext();
}
sm.contextSm.pushAndSwitchSecurityContextBySessionId(sessionId);
}
catch (RestrictedUseException ru)
{
throw new RuntimeException("Invalid security context switch");
}
}
/**
* Release the current context.
*
* @param useInitial
* Flag indicating to drop the initial security context.
*/
void releaseContext(boolean useInitial)
{
try
{
sm.contextSm.popAndRestoreSecurityContext();
if (!useInitial)
{
SecurityContext ctx = additional;
additional = null;
SecurityContextStack cts = SecurityContextStack.getContext();
if (cts == null)
{
throw new RestrictedUseException("no security context established");
}
// if there was an additional context, restore it.
if (ctx != null && !cts.push(ctx))
{
throw new RestrictedUseException("illegal context switch");
}
}
else
{
sm.contextSm.dropInitialSecurityContext();
}
}
catch (RestrictedUseException exc)
{
throw new RuntimeException("Invalid security context switch");
}
}
}