2 * ============LICENSE_START====================================================
4 * ===========================================================================
5 * Copyright (c) 2018 AT&T Intellectual Property. All rights reserved.
6 * ===========================================================================
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ============LICENSE_END====================================================
22 package org.onap.aaf.cadi.aaf.v2_0;
24 import java.io.IOException;
26 import org.onap.aaf.cadi.AbsUserCache;
27 import org.onap.aaf.cadi.CachedPrincipal;
28 import org.onap.aaf.cadi.CadiException;
29 import org.onap.aaf.cadi.User;
30 import org.onap.aaf.cadi.aaf.AAFPermission;
31 import org.onap.aaf.cadi.client.Future;
32 import org.onap.aaf.cadi.lur.ConfigPrincipal;
34 import aaf.v2_0.CredRequest;
36 public class AAFAuthn<CLIENT> extends AbsUserCache<AAFPermission> {
37 private AAFCon<CLIENT> con;
41 * Configure with Standard AAF properties, Stand alone
43 * @throws Exception ..
46 AAFAuthn(AAFCon<CLIENT> con) {
47 super(con.access,con.cleanInterval,con.highCount,con.usageRefreshTriggerCount);
52 * Configure with Standard AAF properties, but share the Cache (with AAF Lur)
57 AAFAuthn(AAFCon<CLIENT> con, AbsUserCache<AAFPermission> cache) {
63 * Return Native Realm of AAF Instance.
67 public String getRealm() {
72 * Returns null if ok, or an Error String;
74 * Convenience function. Passes "null" for State object
76 public String validate(String user, String password) throws IOException {
77 return validate(user,password,null);
81 * Returns null if ok, or an Error String;
83 * For State Object, you may put in HTTPServletRequest or AuthzTrans, if available. Otherwise,
90 * @throws CadiException
93 public String validate(String user, String password, Object state) throws IOException {
94 password = access.decrypt(password, false);
95 byte[] bytes = password.getBytes();
96 User<AAFPermission> usr = getUser(user,bytes);
98 if (usr != null && !usr.permExpired()) {
99 if (usr.principal==null) {
100 return "User already denied";
106 AAFCachedPrincipal cp = new AAFCachedPrincipal(user, bytes, con.cleanInterval);
107 // Since I've relocated the Validation piece in the Principal, just revalidate, then do Switch
109 switch(cp.revalidate(state)) {
114 addUser(new User<AAFPermission>(cp,con.timeout));
118 return "AAF Inaccessible";
120 addUser(new User<AAFPermission>(user,bytes,con.timeout));
121 return "user/pass combo invalid for " + user;
123 return "AAF denies API for " + user;
125 return "AAFAuthn doesn't handle Principal " + user;
129 private class AAFCachedPrincipal extends ConfigPrincipal implements CachedPrincipal {
130 private long expires;
131 private long timeToLive;
133 private AAFCachedPrincipal(String name, byte[] pass, int timeToLive) {
135 this.timeToLive = timeToLive;
136 expires = timeToLive + System.currentTimeMillis();
139 public Resp revalidate(Object state) {
141 Miss missed = missed(getName(),getCred());
142 if (missed==null || missed.mayContinue()) {
143 CredRequest cr = new CredRequest();
145 cr.setPassword(new String(getCred()));
146 Future<String> fp = con.client().readPost("/authn/validate", con.credReqDF, cr);
147 //Rcli<CLIENT> client = con.client().forUser(con.basicAuth(getName(), new String(getCred())));
148 //Future<String> fp = client.read(
149 // "/authn/basicAuth",
152 if (fp.get(con.timeout)) {
153 expires = System.currentTimeMillis() + timeToLive;
154 addUser(new User<AAFPermission>(this, expires));
155 return Resp.REVALIDATED;
157 addMiss(getName(), getCred());
158 return Resp.UNVALIDATED;
161 return Resp.UNVALIDATED;
163 } catch (Exception e) {
165 return Resp.INACCESSIBLE;
169 public long expires() {