2 * ============LICENSE_START==========================================
4 * ===================================================================
5 * Copyright (C) 2017 AT&T Intellectual Property. All rights reserved.
6 * ===================================================================
8 * Unless otherwise specified, all software contained herein is licensed
9 * under the Apache License, Version 2.0 (the "License");
10 * you may not use this software except in compliance with the License.
11 * You may obtain a copy of the License at
13 * http://www.apache.org/licenses/LICENSE-2.0
15 * Unless required by applicable law or agreed to in writing, software
16 * distributed under the License is distributed on an "AS IS" BASIS,
17 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
18 * See the License for the specific language governing permissions and
19 * limitations under the License.
21 * Unless otherwise specified, all documentation contained herein is licensed
22 * under the Creative Commons License, Attribution 4.0 Intl. (the "License");
23 * you may not use this documentation except in compliance with the License.
24 * You may obtain a copy of the License at
26 * https://creativecommons.org/licenses/by/4.0/
28 * Unless required by applicable law or agreed to in writing, documentation
29 * distributed under the License is distributed on an "AS IS" BASIS,
30 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
31 * See the License for the specific language governing permissions and
32 * limitations under the License.
34 * ============LICENSE_END============================================
38 package org.onap.portalapp.portal.controller;
40 import java.text.SimpleDateFormat;
41 import java.util.Date;
42 import java.util.UUID;
44 import javax.servlet.http.HttpServletRequest;
46 import org.onap.portalapp.validation.DataValidator;
47 import org.onap.portalapp.validation.SecureString;
49 import org.springframework.beans.factory.annotation.Autowired;
50 import org.springframework.web.bind.annotation.RequestMapping;
51 import org.springframework.web.bind.annotation.GetMapping;
52 import org.springframework.web.bind.annotation.RequestMethod;
53 import org.springframework.web.bind.annotation.RequestParam;
54 import org.springframework.web.bind.annotation.RestController;
56 import com.att.eelf.configuration.Configuration;
58 import org.onap.portalapp.controller.EPRestrictedBaseController;
59 import org.onap.portalapp.portal.domain.EPUser;
60 import org.onap.portalapp.portal.logging.aop.EPEELFLoggerAdvice;
61 import org.onap.portalapp.portal.logging.logic.EPLogUtil;
62 import org.onap.portalapp.portal.utils.EPCommonSystemProperties;
63 import org.onap.portalapp.portal.utils.EcompPortalUtils;
64 import org.onap.portalapp.portal.utils.PortalConstants;
65 import org.onap.portalapp.util.EPUserUtils;
66 import org.onap.portalsdk.core.domain.AuditLog;
67 import org.onap.portalsdk.core.logging.logic.EELFLoggerDelegate;
68 import org.onap.portalsdk.core.service.AuditService;
69 import org.onap.portalsdk.core.util.SystemProperties;
72 @RequestMapping("/portalApi/auditLog")
73 public class AuditLogController extends EPRestrictedBaseController {
74 private static final EELFLoggerDelegate logger = EELFLoggerDelegate.getLogger(DashboardController.class);
75 private static final DataValidator dataValidator = new DataValidator();
77 private AuditService auditService;
79 public AuditLogController(AuditService auditService) {
80 this.auditService = auditService;
84 * Store audit log of the specified access type.
88 * @param affectedAppId
95 @GetMapping(value = "/store", produces = "application/json")
96 public void auditLog(HttpServletRequest request, @RequestParam String affectedAppId, @RequestParam String type,
97 @RequestParam String comment) {
98 logger.debug(EELFLoggerDelegate.debugLogger, "auditLog: appId {}, type {}, comment {}", affectedAppId, type,
100 String cdType = null;
102 SecureString secureString0 = new SecureString(affectedAppId);
103 SecureString secureString1 = new SecureString(type);
104 SecureString secureString2 = new SecureString(comment);
105 if ( !dataValidator.isValid(secureString0)
106 ||!dataValidator.isValid(secureString1)
107 ||!dataValidator.isValid(secureString2)){
112 EPUser user = EPUserUtils.getUserSession(request);
113 /* Check type of Activity CD */
116 cdType = AuditLog.CD_ACTIVITY_APP_ACCESS;
119 cdType = AuditLog.CD_ACTIVITY_TAB_ACCESS;
122 cdType = AuditLog.CD_ACTIVITY_FUNCTIONAL_ACCESS;
125 cdType = AuditLog.CD_ACTIVITY_LEFT_MENU_ACCESS;
128 logger.error(EELFLoggerDelegate.errorLogger,
129 "Storing auditLog failed! Activity CD type is not correct.");
132 /* Store the audit log only if it contains valid Activity CD */
133 if (cdType != null) {
134 AuditLog auditLog = new AuditLog();
135 auditLog.setActivityCode(cdType);
137 * Check affectedAppId and comment and see if these two values
140 if (comment != null && !comment.isEmpty() && !"undefined".equals(comment))
141 auditLog.setComments(
142 EcompPortalUtils.truncateString(comment, PortalConstants.AUDIT_LOG_COMMENT_SIZE));
143 if (affectedAppId != null && !affectedAppId.isEmpty() && !"undefined".equals(affectedAppId))
144 auditLog.setAffectedRecordId(affectedAppId);
145 long userId = EPUserUtils.getUserId(request);
146 auditLog.setUserId(userId);
147 MDC.put(EPCommonSystemProperties.AUDITLOG_BEGIN_TIMESTAMP, EPEELFLoggerAdvice.getCurrentDateTimeUTC());
148 MDC.put(EPCommonSystemProperties.PARTNER_NAME, EPCommonSystemProperties.ECOMP_PORTAL_FE);
149 MDC.put(Configuration.MDC_SERVICE_NAME, EPCommonSystemProperties.ECOMP_PORTAL_BE);
150 if (MDC.get(Configuration.MDC_KEY_REQUEST_ID) == null) {
151 String requestId = UUID.randomUUID().toString();
152 MDC.put(Configuration.MDC_KEY_REQUEST_ID, requestId);
155 MDC.put(EPCommonSystemProperties.AUDITLOG_END_TIMESTAMP, EPEELFLoggerAdvice.getCurrentDateTimeUTC());
156 SimpleDateFormat ecompLogDateFormat = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ss.SSSXXX");
157 String beginDateTime = MDC.get(EPCommonSystemProperties.AUDITLOG_BEGIN_TIMESTAMP);
158 Date beginDate = ecompLogDateFormat.parse(beginDateTime);
159 auditService.logActivity(auditLog, null);
160 String endDateTime = MDC.get(EPCommonSystemProperties.AUDITLOG_END_TIMESTAMP);
161 Date endDate = ecompLogDateFormat.parse(endDateTime);
162 String timeDifference = String.format("%d", endDate.getTime() - beginDate.getTime());
163 MDC.put(SystemProperties.MDC_TIMER, timeDifference);
164 MDC.put(EPCommonSystemProperties.STATUS_CODE, "COMPLETE");
165 logger.info(EELFLoggerDelegate.auditLogger, EPLogUtil.formatAuditLogMessage(
166 "AuditLogController.auditLog", cdType, user.getOrgUserId(), affectedAppId, comment));
167 MDC.remove(EPCommonSystemProperties.AUDITLOG_BEGIN_TIMESTAMP);
168 MDC.remove(EPCommonSystemProperties.AUDITLOG_END_TIMESTAMP);
170 } catch (Exception e) {
171 logger.error(EELFLoggerDelegate.errorLogger, "auditLog failed", e);
172 MDC.put(EPCommonSystemProperties.STATUS_CODE, "ERROR");
174 MDC.remove(Configuration.MDC_SERVICE_NAME);
175 MDC.remove(EPCommonSystemProperties.PARTNER_NAME);
176 MDC.remove(SystemProperties.MDC_TIMER);
177 MDC.remove(Configuration.MDC_KEY_REQUEST_ID);
178 MDC.remove(EPCommonSystemProperties.STATUS_CODE);