WebServiceResource.java
/*
** Module : WebServiceResource.java
** Abstract : plugin to manage access to application web resources.
**
** Copyright (c) 2022-2025, Golden Code Development Corporation.
**
** -#- -I- --Date-- ------------------------------------Description-------------------------------------------
** 001 CA 20220404 Created the first version.
** 002 RAA 20240406 Allow TENANT to be a valid instance name for multi-tenancy cases.
** 003 RNC 20250108 Allow SESSION to be a valid instance name.
** 004 OM 20250206 Renamed TENANT to ADMIN since that handles all admin requests using REST API calls.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
import org.eclipse.jetty.http.*;
import com.goldencode.p2j.main.*;
import com.goldencode.p2j.util.LegacyService;
/**
* Implements the resource to set permissions for web services. Instances of this resource control access
* to web services, based on their type, API path and for SOAP, the target operation.
* <p>
* The supported web services are REST, WEBHANDLER and SOAP. The syntax is enforced only for exact matches:
* <ul>
* <li>For REST, it is <code>REST:HTTP-METHOD:/path/to/api</code></li>
* <li>For WEBHANDLER, it is <code>WEBHANDLER:HTTP-METHOD:/path/to/api</code></li>
* <li>For SOAP, it is <code>SOAP:HTTP-METHOD:/path/to/endpoint:namespace/binding/operation</code></li>
* </ul>
* For all cases, the first part with the service type (REST, SOAP or WEBHANDLER) and the second part with the
* HTTP Method (PUT, GET, DELETE, etc) is mandatory.
* <p>
* The web service path or SOAP endpoint are all relative to the basepath, and any <code>address</code> set
* at the service implementation {@link LegacyService#address()} annotation. So, if the basepath is
* <code>/rest/</code> and the address set is <code>foo</code>, the resolved path is
* <code>/rest/foo/path/to/api</code>.
* <p>
* For SOAP, the target operation must be specified via the <code>namespace/binding/operation</code> triplet.
*/
public class WebServiceResource
extends StringConditionResource
{
/**
* Returns the plugin resource type name as a string.
*
* @return plugin resource type name
*/
@Override
public String getTypeName()
{
return "webservice";
}
/**
* Instantiates a plugin's class that implements the <code>Rights</code> interface, using
* the array of objects representing a set of access rights fields.
*
* @param rights
* The objects needed to create an access rights instance.
*
* @return The newly created rights instance.
*/
@Override
public Rights getRightsInstance(Object[] rights)
{
return new WebServiceRights((String) rights[0]);
}
/**
* Checks whether a given string is a valid resource name for this resource type.
*
* @param resource
* A string naming a resource.
*
* @return <code>true</code> if the name is syntactically correct.
*/
@Override
public boolean isInstanceNameValid(String resource)
{
// the syntax is:
// 1. SOAP:HTTP-METHOD:endpoint:namespace/binding/operation
// 2. REST:HTTP-METHOD:path/to/*/api/*
// 3. WEBHANDLER:METHOD:path/to/*/api/*
// 4. ADMIN:METHOD:admin/<path/to/*/api/*>
// validation is not done for regex mode
int idx = resource.indexOf(':');
if (idx <= 0)
{
// service not set
return false;
}
String service = resource.substring(0, idx);
if (!("SOAP".equals(service) ||
"REST".equals(service) ||
"WEBHANDLER".equals(service) ||
"ADMIN".equals(service)))
{
// service not known
return false;
}
resource = resource.substring(idx + 1);
idx = resource.indexOf(':');
if (idx <= 0)
{
// http method not set
return false;
}
String method = resource.substring(0, idx);
if (HttpMethod.fromString(method) == null)
{
// HTTP method invalid
return false;
}
resource = resource.substring(idx + 1);
String uri = resource;
if ("SOAP".equals(service))
{
idx = resource.indexOf(':');
if (idx <= 0)
{
// SOAP target not set
return false;
}
uri = resource.substring(0, idx);
resource = resource.substring(idx + 1);
}
return true;
}
}