package org.openecomp.sdc.fe.servlets;
+import org.onap.portalsdk.core.onboarding.exception.CipherUtilException;
import org.onap.portalsdk.core.onboarding.util.CipherUtil;
import org.openecomp.sdc.common.impl.MutableHttpServletRequest;
import org.openecomp.sdc.fe.Constants;
*/
@GET
@Path("/portal")
+ @Override
public void doGet(@Context final HttpServletRequest request, @Context final HttpServletResponse response) {
try {
addRequestHeadersUsingWebseal(request, response);
String currHeader = headers[i];
String headerValue = request.getHeader(currHeader);
if (headerValue != null) {
- response.addCookie(new Cookie(currHeader, headerValue));
+ final Cookie cookie = new Cookie(currHeader, headerValue);
+ cookie.setSecure(true);
+ response.addCookie(cookie);
}
}
}
return newHeaderIsSet;
}
- private static String getUserIdFromCookie(HttpServletRequest request) throws Exception {
+ private static String getUserIdFromCookie(HttpServletRequest request) throws CipherUtilException {
String userId = "";
Cookie[] cookies = request.getCookies();
Cookie userIdcookie = null;
private static final Logger log = LoggerFactory.getLogger(SessionValidationFilter.class.getName());
+ private AuthenticationCookieUtils() {
+ }
+
/**
* Update given cookie session time value to current time
*
*/
public static Cookie createUpdatedCookie(Cookie cookie, String encryptedCookie, ISessionValidationCookieConfiguration cookieConfiguration) {
Cookie updatedCookie = new Cookie(cookie.getName(), encryptedCookie );
+ updatedCookie.setSecure(true);
updatedCookie.setPath(cookieConfiguration.getCookiePath());
updatedCookie.setDomain(cookieConfiguration.getCookieDomain());
updatedCookie.setHttpOnly(cookieConfiguration.isCookieHttpOnly());
* @param filterConfiguration
* @return
*/
- public static boolean isSessionIdle(long sessionTimeValue, long currentTime, ISessionValidationFilterConfiguration filterConfiguration) {
+ private static boolean isSessionIdle(long sessionTimeValue, long currentTime, ISessionValidationFilterConfiguration filterConfiguration) {
long currentIdleTime = currentTime - sessionTimeValue;
long maxIdleTime = filterConfiguration.getSessionIdleTimeOut();
log.debug("SessionValidationFilter: Checking if session idle: session time: {}, current idle time: {}, max idle time: {}", currentTime, currentIdleTime, maxIdleTime);
return currentIdleTime >= maxIdleTime;
}
-
}