Fix Security Vulnerabilities
[sdc.git] / catalog-be / src / main / java / org / openecomp / sdc / be / servlets / LifecycleServlet.java
1 /*-
2  * ============LICENSE_START=======================================================
3  * SDC
4  * ================================================================================
5  * Copyright (C) 2017 AT&T Intellectual Property. All rights reserved.
6  * ================================================================================
7  * Licensed under the Apache License, Version 2.0 (the "License");
8  * you may not use this file except in compliance with the License.
9  * You may obtain a copy of the License at
10  *
11  *      http://www.apache.org/licenses/LICENSE-2.0
12  *
13  * Unless required by applicable law or agreed to in writing, software
14  * distributed under the License is distributed on an "AS IS" BASIS,
15  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16  * See the License for the specific language governing permissions and
17  * limitations under the License.
18  * ============LICENSE_END=========================================================
19  */
20
21 package org.openecomp.sdc.be.servlets;
22
23 import com.fasterxml.jackson.databind.ObjectMapper;
24 import com.jcabi.aspects.Loggable;
25 import fj.data.Either;
26 import io.swagger.v3.oas.annotations.Operation;
27 import io.swagger.v3.oas.annotations.Parameter;
28 import io.swagger.v3.oas.annotations.media.ArraySchema;
29 import io.swagger.v3.oas.annotations.media.Content;
30 import io.swagger.v3.oas.annotations.media.Schema;
31 import io.swagger.v3.oas.annotations.responses.ApiResponse;
32 import io.swagger.v3.oas.annotations.servers.Server;
33 import io.swagger.v3.oas.annotations.servers.Servers;
34 import io.swagger.v3.oas.annotations.tags.Tag;
35 import io.swagger.v3.oas.annotations.tags.Tags;
36 import java.io.IOException;
37 import javax.inject.Inject;
38 import javax.servlet.http.HttpServletRequest;
39 import javax.ws.rs.Consumes;
40 import javax.ws.rs.HeaderParam;
41 import javax.ws.rs.POST;
42 import javax.ws.rs.Path;
43 import javax.ws.rs.PathParam;
44 import javax.ws.rs.Produces;
45 import javax.ws.rs.core.Context;
46 import javax.ws.rs.core.MediaType;
47 import javax.ws.rs.core.Response;
48 import org.openecomp.sdc.be.components.impl.aaf.AafPermission;
49 import org.openecomp.sdc.be.components.impl.aaf.PermissionAllowed;
50 import org.openecomp.sdc.be.components.lifecycle.LifecycleBusinessLogic;
51 import org.openecomp.sdc.be.components.lifecycle.LifecycleChangeInfoBase;
52 import org.openecomp.sdc.be.components.lifecycle.LifecycleChangeInfoWithAction;
53 import org.openecomp.sdc.be.config.BeEcompErrorManager;
54 import org.openecomp.sdc.be.dao.api.ActionStatus;
55 import org.openecomp.sdc.be.datamodel.utils.UiComponentDataConverter;
56 import org.openecomp.sdc.be.datatypes.enums.ComponentTypeEnum;
57 import org.openecomp.sdc.be.impl.ComponentsUtils;
58 import org.openecomp.sdc.be.model.Component;
59 import org.openecomp.sdc.be.model.LifeCycleTransitionEnum;
60 import org.openecomp.sdc.be.model.User;
61 import org.openecomp.sdc.be.resources.data.auditing.AuditingActionEnum;
62 import org.openecomp.sdc.be.ui.model.UiComponentMetadata;
63 import org.openecomp.sdc.be.user.UserBusinessLogic;
64 import org.openecomp.sdc.common.api.Constants;
65 import org.openecomp.sdc.common.log.elements.LoggerSupportability;
66 import org.openecomp.sdc.common.log.enums.LoggerSupportabilityActions;
67 import org.openecomp.sdc.common.log.enums.StatusCode;
68 import org.openecomp.sdc.common.log.wrappers.Logger;
69 import org.openecomp.sdc.common.util.ValidationUtils;
70 import org.openecomp.sdc.exception.ResponseFormat;
71 import org.springframework.stereotype.Controller;
72
73 @Loggable(prepend = true, value = Loggable.DEBUG, trim = false)
74 @Path("/v1/catalog")
75 @Tags({@Tag(name = "SDC Internal APIs")})
76 @Servers({@Server(url = "/sdc2/rest")})
77 @Controller
78 public class LifecycleServlet extends BeGenericServlet {
79
80     private static final Logger log = Logger.getLogger(LifecycleServlet.class);
81     private static final LoggerSupportability loggerSupportability = LoggerSupportability.getLogger(LifecycleServlet.class.getName());
82     private LifecycleBusinessLogic lifecycleBusinessLogic;
83
84     @Inject
85     public LifecycleServlet(UserBusinessLogic userBusinessLogic,
86         ComponentsUtils componentsUtils,
87         LifecycleBusinessLogic lifecycleBusinessLogic) {
88         super(userBusinessLogic, componentsUtils);
89         this.lifecycleBusinessLogic = lifecycleBusinessLogic;
90     }
91
92
93     @POST
94     @Path("/{componentCollection}/{componentId}/lifecycleState/{lifecycleOperation}")
95     @Consumes(MediaType.APPLICATION_JSON)
96     @Produces(MediaType.APPLICATION_JSON)
97     @Operation(description = "Change Resource lifecycle State", method = "POST", responses = {
98             @ApiResponse(content = @Content(array = @ArraySchema(schema = @Schema(implementation = Response.class)))),
99             @ApiResponse(responseCode = "200", description = "Resource state changed"),
100             @ApiResponse(responseCode = "403", description = "Restricted operation"),
101             @ApiResponse(responseCode = "409", description = "Resource already exist")})
102     @PermissionAllowed(AafPermission.PermNames.INTERNAL_ALL_VALUE)
103     public Response changeResourceState(
104             @Parameter(description = "LifecycleChangeInfo - relevant for checkin, failCertification, cancelCertification")
105                 String jsonChangeInfo,
106             @Parameter(description = "validValues: resources / services / products",
107                     schema = @Schema(allowableValues = {ComponentTypeEnum.RESOURCE_PARAM_NAME,
108                             ComponentTypeEnum.SERVICE_PARAM_NAME, ComponentTypeEnum.PRODUCT_PARAM_NAME})) @PathParam(
109                                     value = "componentCollection") final String componentCollection,
110             @Parameter(schema = @Schema(allowableValues = {
111                     "checkout, undoCheckout, checkin, certificationRequest, startCertification, failCertification,  cancelCertification, certify"}),
112                     required = true) @PathParam(value = "lifecycleOperation") final String lifecycleTransition,
113             @Parameter(description = "id of component to be changed") @PathParam(
114                     value = "componentId") final String componentId,
115             @Context final HttpServletRequest request,
116             @Parameter(description = "id of user initiating the operation") @HeaderParam(
117                     value = Constants.USER_ID_HEADER) String userId) throws IOException {
118         String url = request.getMethod() + " " + request.getRequestURI();
119         log.debug("Start handle request of {}", url);
120         loggerSupportability.log(LoggerSupportabilityActions.CHANGELIFECYCLESTATE, StatusCode.STARTED,"Starting to change lifecycle state to " + lifecycleTransition + " by user " + userId);
121
122         Response response = null;
123
124         // get modifier from graph
125         log.debug("get modifier properties");
126         Either<User, ResponseFormat> eitherGetUser = getUser(request, userId);
127         if (eitherGetUser.isRight()) {
128             return buildErrorResponse(eitherGetUser.right().value());
129         }
130         User user = eitherGetUser.left().value();
131
132         String resourceIdLower = componentId.toLowerCase();
133         log.debug("perform {} operation to resource with id {} ", lifecycleTransition, resourceIdLower);
134         Either<LifeCycleTransitionEnum, Response> validateEnum = validateTransitionEnum(lifecycleTransition, user);
135         if (validateEnum.isRight()) {
136             return validateEnum.right().value();
137         }
138
139         LifecycleChangeInfoWithAction changeInfo = new LifecycleChangeInfoWithAction();
140
141         try {
142             if (jsonChangeInfo != null && !jsonChangeInfo.isEmpty()) {
143                 ObjectMapper mapper = new ObjectMapper();
144                 changeInfo = new LifecycleChangeInfoWithAction(mapper
145                     .readValue(ValidationUtils.sanitizeInputString(jsonChangeInfo), LifecycleChangeInfoBase.class)
146                     .getUserRemarks());
147             }
148         }
149
150         catch (Exception e) {
151             BeEcompErrorManager.getInstance().logBeInvalidJsonInput("convertJsonToObject");
152             log.debug("failed to convert from json {}", jsonChangeInfo, e);
153             getComponentsUtils().getInvalidContentErrorAndAudit(user, componentId, AuditingActionEnum.CHECKOUT_RESOURCE);
154             throw e;
155         }
156
157         LifeCycleTransitionEnum transitionEnum = validateEnum.left().value();
158         ComponentTypeEnum componentType = ComponentTypeEnum.findByParamName(componentCollection);
159         if (componentType != null) {
160             Either<? extends Component, ResponseFormat> actionResponse = lifecycleBusinessLogic.changeComponentState(componentType, componentId, user, transitionEnum, changeInfo, false, true);
161
162             if (actionResponse.isRight()) {
163                 log.info("failed to change resource state");
164                 loggerSupportability.log(LoggerSupportabilityActions.CHANGELIFECYCLESTATE, StatusCode.ERROR,"failed to change resource state " + lifecycleTransition + " with error " + actionResponse.isRight() +  " by user " + userId);
165                 response = buildErrorResponse(actionResponse.right().value());
166                 return response;
167             }
168
169             log.debug("change state successful !!!");
170             UiComponentMetadata componentMetatdata = UiComponentDataConverter.convertToUiComponentMetadata(actionResponse.left().value());
171             Object value = null;
172             try {
173             value = RepresentationUtils.toRepresentation(componentMetatdata);
174             } catch (IOException e) {
175                 e.printStackTrace();
176             }
177             response = buildOkResponse(getComponentsUtils().getResponseFormat(ActionStatus.OK), value);
178             loggerSupportability.log(LoggerSupportabilityActions.CHANGELIFECYCLESTATE,actionResponse.left().value().getComponentMetadataForSupportLog(),StatusCode.COMPLETE," change state to " + lifecycleTransition + " was successful by user" + userId);
179             return response;
180         } else {
181             log.info("componentCollection \"{}\" is not valid. Supported componentCollection values are \"{}\", \"{}\" or \"{}\"", componentCollection, ComponentTypeEnum.RESOURCE_PARAM_NAME, ComponentTypeEnum.SERVICE_PARAM_NAME,
182                     ComponentTypeEnum.PRODUCT_PARAM_NAME);
183             ResponseFormat error = getComponentsUtils().getInvalidContentErrorAndAudit(user, componentId, AuditingActionEnum.CHECKOUT_RESOURCE);
184             return buildErrorResponse(error);
185         }
186     }
187
188     private Either<LifeCycleTransitionEnum, Response> validateTransitionEnum(final String lifecycleTransition, User user) {
189         LifeCycleTransitionEnum transitionEnum;
190         try {
191             transitionEnum = LifeCycleTransitionEnum.getFromDisplayName(lifecycleTransition);
192         } catch (IllegalArgumentException e) {
193             log.info("state operation is not valid. operations allowed are: {}", LifeCycleTransitionEnum.valuesAsString(), e);
194             ResponseFormat error = getComponentsUtils().getInvalidContentErrorAndAudit(user, "", AuditingActionEnum.CHECKOUT_RESOURCE);
195             return Either.right(buildErrorResponse(error));
196         }
197         return Either.left(transitionEnum);
198     }
199
200 }