2 * ============LICENSE_START====================================================
4 * ===========================================================================
5 * Copyright (c) 2018 AT&T Intellectual Property. All rights reserved.
6 * ===========================================================================
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ============LICENSE_END====================================================
22 package org.onap.aaf.cadi.aaf.v2_0;
24 import java.io.IOException;
26 import java.util.ArrayList;
27 import java.util.List;
29 import org.onap.aaf.cadi.AbsUserCache;
30 import org.onap.aaf.cadi.CachedPrincipal;
31 import org.onap.aaf.cadi.CadiException;
32 import org.onap.aaf.cadi.User;
33 import org.onap.aaf.cadi.aaf.AAFPermission;
34 import org.onap.aaf.cadi.client.Future;
35 import org.onap.aaf.cadi.client.Rcli;
36 import org.onap.aaf.cadi.lur.ConfigPrincipal;
38 import aaf.v2_0.CredRequest;
40 public class AAFAuthn<CLIENT> extends AbsUserCache<AAFPermission> {
41 private AAFCon<CLIENT> con;
45 * Configure with Standard AAF properties, Stand alone
47 * @throws Exception ..
50 AAFAuthn(AAFCon<CLIENT> con) {
51 super(con.access,con.cleanInterval,con.highCount,con.usageRefreshTriggerCount);
56 * Configure with Standard AAF properties, but share the Cache (with AAF Lur)
61 AAFAuthn(AAFCon<CLIENT> con, AbsUserCache<AAFPermission> cache) {
67 * Return Native Realm of AAF Instance.
71 public String getRealm() {
76 * Returns null if ok, or an Error String;
78 * Convenience function. Passes "null" for State object
80 public String validate(String user, String password) throws IOException {
81 return validate(user,password,null);
85 * Returns null if ok, or an Error String;
87 * For State Object, you may put in HTTPServletRequest or AuthzTrans, if available. Otherwise,
94 * @throws CadiException
97 public String validate(String user, String password, Object state) throws IOException {
98 password = access.decrypt(password, false);
99 byte[] bytes = password.getBytes();
100 User<AAFPermission> usr = getUser(user,bytes);
102 if (usr != null && !usr.permExpired()) {
103 if (usr.principal==null) {
104 return "User already denied";
110 AAFCachedPrincipal cp = new AAFCachedPrincipal(user, bytes, con.cleanInterval);
111 // Since I've relocated the Validation piece in the Principal, just revalidate, then do Switch
113 switch(cp.revalidate(state)) {
118 addUser(new User<AAFPermission>(cp,con.timeout));
122 return "AAF Inaccessible";
124 addUser(new User<AAFPermission>(user,bytes,con.timeout));
125 return "user/pass combo invalid for " + user;
127 return "AAF denies API for " + user;
129 return "AAFAuthn doesn't handle Principal " + user;
133 private class AAFCachedPrincipal extends ConfigPrincipal implements CachedPrincipal {
134 private long expires;
135 private long timeToLive;
137 private AAFCachedPrincipal(String name, byte[] pass, int timeToLive) {
139 this.timeToLive = timeToLive;
140 expires = timeToLive + System.currentTimeMillis();
143 public Resp revalidate(Object state) {
144 List<URI> attemptedUris = new ArrayList<>();
146 for (int retries = 0;; retries++) {
148 Miss missed = missed(getName(), getCred());
149 if (missed == null || missed.mayContinue()) {
150 CredRequest cr = new CredRequest();
152 cr.setPassword(new String(getCred()));
153 Rcli<CLIENT> client = con.clientIgnoreAlreadyAttempted(attemptedUris);
154 thisUri = client.getURI();
155 Future<String> fp = client.readPost("/authn/validate", con.credReqDF, cr);
156 //Rcli<CLIENT> client = con.client().forUser(con.basicAuth(getName(), new String(getCred())));
157 //Future<String> fp = client.read(
158 // "/authn/basicAuth",
161 if (fp.get(con.timeout)) {
162 expires = System.currentTimeMillis() + timeToLive;
163 addUser(new User<AAFPermission>(this, expires));
164 return Resp.REVALIDATED;
166 addMiss(getName(), getCred());
167 return Resp.UNVALIDATED;
170 return Resp.UNVALIDATED;
172 } catch (Exception e) {
173 if (thisUri != null) {
174 attemptedUris.add(thisUri);
178 return Resp.INACCESSIBLE;
184 public long expires() {