WebServiceResource.java

/*
** Module   : WebServiceResource.java
** Abstract : plugin to manage access to application web resources. 
**
** Copyright (c) 2022-2025, Golden Code Development Corporation.
**
** -#- -I- --Date-- ------------------------------------Description-------------------------------------------
** 001 CA  20220404 Created the first version.
** 002 RAA 20240406 Allow TENANT to be a valid instance name for multi-tenancy cases.
** 003 RNC 20250108 Allow SESSION to be a valid instance name.
** 004 OM  20250206 Renamed TENANT to ADMIN since that handles all admin requests using REST API calls.
*/

/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import org.eclipse.jetty.http.*;
import com.goldencode.p2j.main.*;
import com.goldencode.p2j.util.LegacyService;

/**
 * Implements the resource to set permissions for web services.  Instances of this resource control access 
 * to web services, based on their type, API path and for SOAP, the target operation.
 * <p>
 * The supported web services are REST, WEBHANDLER and SOAP.  The syntax is enforced only for exact matches:
 * <ul>
 *    <li>For REST, it is <code>REST:HTTP-METHOD:/path/to/api</code></li>
 *    <li>For WEBHANDLER, it is <code>WEBHANDLER:HTTP-METHOD:/path/to/api</code></li>
 *    <li>For SOAP, it is <code>SOAP:HTTP-METHOD:/path/to/endpoint:namespace/binding/operation</code></li>
 * </ul>  
 * For all cases, the first part with the service type (REST, SOAP or WEBHANDLER) and the second part with the
 * HTTP Method (PUT, GET, DELETE, etc) is mandatory.
 * <p>
 * The web service path or SOAP endpoint are all relative to the basepath, and any <code>address</code> set
 * at the service implementation {@link LegacyService#address()} annotation.  So, if the basepath is 
 * <code>/rest/</code> and the address set is <code>foo</code>, the resolved path is 
 * <code>/rest/foo/path/to/api</code>.
 * <p>
 * For SOAP, the target operation must be specified via the <code>namespace/binding/operation</code> triplet.
 */
public class WebServiceResource
extends StringConditionResource
{
   /**
    * Returns the plugin resource type name as a string.
    *
    * @return plugin resource type name
    */
   @Override
   public String getTypeName()
   {
      return "webservice";
   }

   /**
    * Instantiates a plugin's class that implements the <code>Rights</code> interface, using
    * the array of objects representing a set of access rights fields.
    *
    * @param    rights
    *           The objects needed to create an access rights instance.
    *           
    * @return   The newly created rights instance.
    */
   @Override
   public Rights getRightsInstance(Object[] rights)
   {
      return new WebServiceRights((String) rights[0]);
   }

   /**
    * Checks whether a given string is a valid resource name for this resource type.
    *
    * @param    resource
    *           A string naming a resource.
    *
    * @return   <code>true</code> if the name is syntactically correct. 
    */
   @Override
   public boolean isInstanceNameValid(String resource)
   {
      // the syntax is:
      // 1. SOAP:HTTP-METHOD:endpoint:namespace/binding/operation
      // 2. REST:HTTP-METHOD:path/to/*/api/*
      // 3. WEBHANDLER:METHOD:path/to/*/api/*
      // 4. ADMIN:METHOD:admin/<path/to/*/api/*>
      
      // validation is not done for regex mode
      
      int idx = resource.indexOf(':');
      if (idx <= 0)
      {
         // service not set
         return false;
      }
      String service = resource.substring(0, idx);
      if (!("SOAP".equals(service)       ||
            "REST".equals(service)       ||
            "WEBHANDLER".equals(service) ||
            "ADMIN".equals(service)))
      {
         // service not known
         return false;
      }
      resource = resource.substring(idx + 1);
      
      idx = resource.indexOf(':');
      if (idx <= 0)
      {
         // http method not set
         return false;
      }
      
      String method = resource.substring(0, idx);
      if (HttpMethod.fromString(method) == null)
      {
         // HTTP method invalid
         return false;
      }
      resource = resource.substring(idx + 1);
      
      String uri = resource;
      if ("SOAP".equals(service))
      {
         idx = resource.indexOf(':');
         if (idx <= 0)
         {
            // SOAP target not set
            return false;
         }
         uri = resource.substring(0, idx);
         resource = resource.substring(idx + 1);
      }
      
      return true;
   }
}