/*- * ============LICENSE_START======================================================= * ONAP : APPC * ================================================================================ * Copyright (C) 2017-2018 AT&T Intellectual Property. All rights reserved. * ================================================================================ * Copyright (C) 2017 Amdocs * ============================================================================= * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. * * ============LICENSE_END========================================================= */ package org.onap.appc.rest.client; import java.io.IOException; import java.io.UnsupportedEncodingException; import java.net.MalformedURLException; import java.net.Socket; import java.net.URL; import java.security.KeyManagementException; import java.security.KeyStore; import java.security.KeyStoreException; import java.security.NoSuchAlgorithmException; import java.security.UnrecoverableKeyException; import java.security.cert.CertificateException; import java.security.cert.X509Certificate; import javax.net.ssl.SSLContext; import javax.net.ssl.TrustManager; import javax.net.ssl.X509TrustManager; import org.apache.commons.codec.binary.Base64; import org.apache.http.HttpHeaders; import org.apache.http.HttpResponse; import org.apache.http.HttpVersion; import org.apache.http.client.HttpClient; import org.apache.http.client.methods.HttpGet; import org.apache.http.client.methods.HttpPost; import org.apache.http.client.methods.HttpPut; import org.apache.http.conn.ClientConnectionManager; import org.apache.http.conn.scheme.PlainSocketFactory; import org.apache.http.conn.scheme.Scheme; import org.apache.http.conn.scheme.SchemeRegistry; import org.apache.http.conn.ssl.SSLSocketFactory; import org.apache.http.entity.StringEntity; import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.DefaultHttpClient; import org.apache.http.impl.conn.tsccm.ThreadSafeClientConnManager; import org.apache.http.params.BasicHttpParams; import org.apache.http.params.HttpParams; import org.apache.http.params.HttpProtocolParams; import org.apache.http.protocol.HTTP; import org.onap.appc.exceptions.APPCException; import com.att.eelf.configuration.EELFLogger; import com.att.eelf.configuration.EELFManager; @SuppressWarnings("deprecation") public class RestClientInvoker { private static final EELFLogger LOG = EELFManager.getInstance().getLogger(RestClientInvoker.class); private static final String OPERATION_HTTPS = "https"; private static final String OPERATION_APPLICATION_JSON = " application/json"; private static final String BASIC = "Basic "; private URL url = null; private String basicAuth = null; public RestClientInvoker(URL url) { this.url = url; } /** * Sets the basic authentication header for the given user and password. If either entry is null * then does not set basic auth * * @param user The user with optional domain name (for AAF) * @param password The password for the user */ public void setAuthentication(String user, String password) { if (user != null && password != null) { String authStr = user + ":" + password; basicAuth = new String(Base64.encodeBase64(authStr.getBytes())); } } public HttpResponse doPost(String path, String body) throws APPCException { HttpPost post; try { URL postUrl = new URL(url.getProtocol(), url.getHost(), url.getPort(), path); post = new HttpPost(postUrl.toExternalForm()); post.setHeader(HttpHeaders.CONTENT_TYPE, OPERATION_APPLICATION_JSON); post.setHeader(HttpHeaders.ACCEPT, OPERATION_APPLICATION_JSON); if (basicAuth != null) { post.setHeader(HttpHeaders.AUTHORIZATION, BASIC + basicAuth); } StringEntity entity = new StringEntity(body); entity.setContentType(OPERATION_APPLICATION_JSON); post.setEntity(new StringEntity(body)); } catch (MalformedURLException | UnsupportedEncodingException e) { throw new APPCException(e); } HttpClient client = getHttpClient(); try { return client.execute(post); } catch (IOException e) { throw new APPCException(e); } } /** * This is Generic method that can be used to perform REST Put operation * * @param path - path for put * @param body - payload for put action which will be sent as request body. * @return - HttpResponse object which is returned from put REST call. * @throws APPCException when error occurs */ public HttpResponse doPut(String path, String body) throws APPCException { HttpPut put; try { URL putUrl = new URL(url.getProtocol(), url.getHost(), url.getPort(), path); put = new HttpPut(putUrl.toExternalForm()); put.setHeader(HttpHeaders.CONTENT_TYPE, OPERATION_APPLICATION_JSON); put.setHeader(HttpHeaders.ACCEPT, OPERATION_APPLICATION_JSON); if (basicAuth != null) { put.setHeader(HttpHeaders.AUTHORIZATION, BASIC + basicAuth); } StringEntity entity = new StringEntity(body); entity.setContentType(OPERATION_APPLICATION_JSON); put.setEntity(new StringEntity(body)); } catch (UnsupportedEncodingException | MalformedURLException e) { throw new APPCException(e); } HttpClient client = getHttpClient(); try { return client.execute(put); } catch (IOException e) { throw new APPCException(e); } } public HttpResponse doGet(String path) throws APPCException { HttpGet get; try { URL getUrl = new URL(url.getProtocol(), url.getHost(), url.getPort(), path); get = new HttpGet(getUrl.toExternalForm()); get.setHeader(HttpHeaders.CONTENT_TYPE, OPERATION_APPLICATION_JSON); get.setHeader(HttpHeaders.ACCEPT, OPERATION_APPLICATION_JSON); if (basicAuth != null) { get.setHeader(HttpHeaders.AUTHORIZATION, BASIC + basicAuth); } } catch (Exception e) { throw new APPCException(e); } try (CloseableHttpClient client = getHttpClient()) { return client.execute(get); } catch (IOException e) { throw new APPCException(e); } } private CloseableHttpClient getHttpClient() throws APPCException { switch (url.getProtocol()) { case OPERATION_HTTPS: return createHttpsClient(); case "http": return new DefaultHttpClient(); default: throw new APPCException("The url did not start with http[s]"); } } private CloseableHttpClient createHttpsClient() { try { KeyStore trustStore = KeyStore.getInstance(KeyStore.getDefaultType()); trustStore.load(null, null); MySSLSocketFactory sf = new MySSLSocketFactory(trustStore); sf.setHostnameVerifier(MySSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER); HttpParams params = new BasicHttpParams(); HttpProtocolParams.setVersion(params, HttpVersion.HTTP_1_1); HttpProtocolParams.setContentCharset(params, HTTP.UTF_8); SchemeRegistry registry = new SchemeRegistry(); registry.register(new Scheme("http", PlainSocketFactory.getSocketFactory(), 80)); registry.register(new Scheme(OPERATION_HTTPS, sf, 443)); registry.register(new Scheme(OPERATION_HTTPS, sf, 8443)); registry.register(new Scheme("http", sf, 8181)); ClientConnectionManager ccm = new ThreadSafeClientConnManager(params, registry); return new DefaultHttpClient(ccm, params); } catch (Exception e) { LOG.error("Error creating HTTPs Client. Creating default client.", e); return new DefaultHttpClient(); } } private static class MySSLSocketFactory extends SSLSocketFactory { private SSLContext sslContext = SSLContext.getInstance("TLS"); private MySSLSocketFactory(KeyStore truststore) throws NoSuchAlgorithmException, KeyManagementException, KeyStoreException, UnrecoverableKeyException { super(truststore); TrustManager tm = new X509TrustManager() { @Override public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { LOG.debug("Inside checkClientTrusted"); } @Override public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { LOG.debug("Inside checkServerTrusted"); } @Override public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[1]; } }; sslContext.init(null, new TrustManager[] {tm}, null); } @Override public Socket createSocket(Socket socket, String host, int port, boolean autoClose) throws IOException { return sslContext.getSocketFactory().createSocket(socket, host, port, autoClose); } @Override public Socket createSocket() throws IOException { return sslContext.getSocketFactory().createSocket(); } } }