2 * ============LICENSE_START=======================================================
4 * ================================================================================
5 * Copyright © 2017-2018 AT&T Intellectual Property. All rights reserved.
6 * Copyright © 2017-2018 European Software Marketing Ltd.
7 * ================================================================================
8 * Licensed under the Apache License, Version 2.0 (the "License");
9 * you may not use this file except in compliance with the License.
10 * You may obtain a copy of the License at
12 * http://www.apache.org/licenses/LICENSE-2.0
14 * Unless required by applicable law or agreed to in writing, software
15 * distributed under the License is distributed on an "AS IS" BASIS,
16 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17 * See the License for the specific language governing permissions and
18 * limitations under the License.
19 * ============LICENSE_END=========================================================
21 package org.onap.aai.auth;
23 import java.security.cert.X509Certificate;
24 import javax.inject.Inject;
25 import javax.security.auth.x500.X500Principal;
26 import javax.servlet.http.HttpServletRequest;
27 import javax.ws.rs.core.HttpHeaders;
28 import org.onap.aai.babel.config.BabelAuthConfig;
29 import org.onap.aai.babel.logging.LogHelper;
30 import org.onap.aai.cl.api.Logger;
33 * Public class for authentication and authorization operations. Authorization is applied according to user and role
35 public class AAIMicroServiceAuth {
37 private static final Logger applicationLogger = LogHelper.INSTANCE;
39 private BabelAuthConfig babelAuthConfig;
42 * @param babelAuthConfig
43 * @throws AAIAuthException
46 public AAIMicroServiceAuth(final BabelAuthConfig babelAuthConfig) throws AAIAuthException {
47 this.babelAuthConfig = babelAuthConfig;
48 if (!babelAuthConfig.isAuthenticationDisable()) {
49 AAIMicroServiceAuthCore.init(babelAuthConfig.getAuthPolicyFile());
55 * @param policyFunction
57 * @throws AAIAuthException
59 public boolean authorize(String username, String policyFunction) throws AAIAuthException {
60 return AAIMicroServiceAuthCore.authorize(username, policyFunction);
65 * @param policyFunction
67 * @throws AAIAuthException
69 public String authenticate(String authUser, String policyFunction) throws AAIAuthException {
70 if (authorize(authUser, policyFunction)) {
83 * @throws AAIAuthException
85 public boolean validateRequest(HttpHeaders headers /* NOSONAR */, HttpServletRequest req,
86 AAIMicroServiceAuthCore.HTTP_METHODS action, String apiPath) throws AAIAuthException {
88 applicationLogger.debug("validateRequest: " + apiPath);
90 .debug("babelAuthConfig.isAuthenticationDisable(): " + babelAuthConfig.isAuthenticationDisable());
92 if (babelAuthConfig.isAuthenticationDisable()) {
96 String[] ps = apiPath.split("/");
97 String authPolicyFunctionName = ps[0];
98 if (ps.length > 1 && authPolicyFunctionName.matches("v\\d+")) {
99 authPolicyFunctionName = ps[1];
102 String cipherSuite = (String) req.getAttribute("javax.servlet.request.cipher_suite");
103 String authUser = null;
105 if (cipherSuite != null) {
106 X509Certificate[] certChain = (X509Certificate[]) req.getAttribute("javax.servlet.request.X509Certificate");
107 X509Certificate clientCert = certChain[0];
108 X500Principal subjectDN = clientCert.getSubjectX500Principal();
109 authUser = subjectDN.toString();
112 if (authUser != null) {
113 return "OK".equals(authenticate(authUser.toLowerCase(), action.toString() + ":" + authPolicyFunctionName));