SessionToken.java

/*
** Module   : SessionToken.java
** Abstract : unique object which identifies a security context by subject
**            and session ID  
**
** Copyright (c) 2009-2021, Golden Code Development Corporation.
**
** -#- -I- --Date-- --JPRM-- -----------------------------------Description-----------------------------------
** 001 CA  20091119   @44434 Initial version. Unique session token describing 
**                           a security context.
** 002 SBI 20170225          Changed to be a simple DTO, GWT serializable.
**         20170705          Fixed toString().
** 003 CA  20211016          Fixed toString() for negative session IDs.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import java.io.Serializable;


/**
 * Unique object describing a security context, by its session ID and authenticated subject.
 */
public final class SessionToken
implements Serializable
{
   /** Unique session ID - always non-zero for user sessions */
   private int sessionID;
   
   /** The subject name. */
   private String subject;

   /**
    * Default constructor
    */
   public SessionToken()
   {
      this.subject = "<system>";
   }

   /**
    * Create a session token for the given session ID and subject.
    * 
    * @param    sessionID
    *           the session ID 
    * @param    subject
    *           the subject name; may be null for {@link SecurityContext#SYSTEM_SESSION sessions}
    */
   public SessionToken(int sessionID, String subject)
   {
      this.sessionID = sessionID;
      this.subject = subject == null ? "<system>" : subject.intern();
   }

   /**
    * Gets session ID.
    *
    * @return   The session ID.
    */
   public int getSessionID()
   {
      return sessionID;
   }

   /**
    * Gets subject name.
    *
    * @return   The subject name.
    */
   public String getSubject()
   {
      return subject;
   }
   
   /**
    * Sets the unique session ID - always non-zero for user sessions.
    *
    * @param    sessionID
    *           The new unique session ID - always non-zero for user sessions
    */
   public void setSessionID(int sessionID)
   {
      this.sessionID = sessionID;
   }
   
   /**
    * Sets the subject name.
    *
    * @param    subject
    *           The new subject name
    */
   public void setSubject(String subject)
   {
      this.subject = subject;
   }
   
   /**
    * Gets the string representation of this token.
    * 
    * @return   The description of this token
    */
   public String toString()
   {
      StringBuilder buf = new StringBuilder(subject);
      buf.append(':');
      /** GWT String emulation doesn't support format(String, int) */ 
      /*buf.append(String.format("%08X", sessionID));*/
      byte hexMask = 0x0f;
      int byteMask = 0xff;
      char[] hex = new char[] {'0','1','2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F'};
      int[] bytes = new int[4];
      int i = sessionID;
      for (int k = 0; k < 4; k++)
      {
         bytes[3 - k] =  i & byteMask;
         i = (i >> 8);
      }
      for (int k = 0; k < 4; k++)
      {
         buf.append(hex[bytes[k] >> 4]).append(hex[bytes[k] & hexMask]);
      }
      
      return buf.toString();
   }
}