Issue-ID: AAF-655
Change-Id: I1e1439efbee5900c82a6065a0581faae15622581
Signed-off-by: Sai Gandham <sg481n@att.com>
<modelVersion>4.0.0</modelVersion>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
<modelVersion>4.0.0</modelVersion>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
<name>CADI Plugins Parent</name>
<packaging>pom</packaging>
<name>CADI Plugins Parent</name>
<packaging>pom</packaging>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
<relativePath>..</relativePath>
</parent>
<relativePath>..</relativePath>
</parent>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
<relativePath>..</relativePath>
</parent>
<relativePath>..</relativePath>
</parent>
import java.security.NoSuchAlgorithmException;
import java.security.SecureRandom;
import java.security.NoSuchAlgorithmException;
import java.security.SecureRandom;
-import org.apache.log4j.Logger;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.UsernamePasswordToken;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.shiro.authc.AuthenticationToken;
import org.apache.shiro.authc.UsernamePasswordToken;
public class AAFAuthenticationInfo implements AuthenticationInfo {
private static final long serialVersionUID = -1502704556864321020L;
public class AAFAuthenticationInfo implements AuthenticationInfo {
private static final long serialVersionUID = -1502704556864321020L;
- final static Logger logger = Logger.getLogger(AAFAuthenticationInfo.class);
+ final static Logger logger = LoggerFactory.getLogger(AAFAuthenticationInfo.class);
// We assume that Shiro is doing Memory Only, and this salt is not needed cross process
private final static int salt = new SecureRandom().nextInt();
// We assume that Shiro is doing Memory Only, and this salt is not needed cross process
private final static int salt = new SecureRandom().nextInt();
hash = getSaltedCred(password);
}
@Override
hash = getSaltedCred(password);
}
@Override
- public byte[] getCredentials() {
- logger.debug("AAFAuthenticationInfo.getCredentials");
+ public byte[] getCredentials() {
return hash;
}
@Override
public PrincipalCollection getPrincipals() {
return hash;
}
@Override
public PrincipalCollection getPrincipals() {
- logger.debug( "AAFAuthenticationInfo.getPrincipals");
import org.apache.shiro.authz.Permission;
import org.onap.aaf.cadi.Access;
import org.onap.aaf.cadi.Access.Level;
import org.apache.shiro.authz.Permission;
import org.onap.aaf.cadi.Access;
import org.onap.aaf.cadi.Access.Level;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
/**
* We treat "roles" and "permissions" in a similar way for first pass.
*
/**
* We treat "roles" and "permissions" in a similar way for first pass.
*
*/
public class AAFAuthorizationInfo implements AuthorizationInfo {
private static final long serialVersionUID = -4805388954462426018L;
*/
public class AAFAuthorizationInfo implements AuthorizationInfo {
private static final long serialVersionUID = -4805388954462426018L;
+
+ final static Logger logger = LoggerFactory.getLogger(AAFAuthorizationInfo.class);
+
private Access access;
private Principal bait;
private List<org.onap.aaf.cadi.Permission> pond;
private Access access;
private Principal bait;
private List<org.onap.aaf.cadi.Permission> pond;
this.pond = pond;
sPerms=null;
oPerms=null;
this.pond = pond;
sPerms=null;
oPerms=null;
}
public Principal principal() {
}
public Principal principal() {
oPerms = new ArrayList<Permission>();
for(final org.onap.aaf.cadi.Permission p : pond) {
oPerms.add(new AAFShiroPermission(p));
oPerms = new ArrayList<Permission>();
for(final org.onap.aaf.cadi.Permission p : pond) {
oPerms.add(new AAFShiroPermission(p));
- System.out.println("List user" + p);
@Override
public Collection<String> getRoles() {
@Override
public Collection<String> getRoles() {
-// access.log(Level.DEBUG, "AAFAuthorizationInfo.getRoles");
// Until we decide to make Roles available, tie into String based permissions.
return getStringPermissions();
}
@Override
public Collection<String> getStringPermissions() {
// Until we decide to make Roles available, tie into String based permissions.
return getStringPermissions();
}
@Override
public Collection<String> getStringPermissions() {
-// access.log(Level.DEBUG, "AAFAuthorizationInfo.getStringPermissions");
synchronized(bait) {
if(sPerms == null) {
sPerms = new ArrayList<String>();
for(org.onap.aaf.cadi.Permission p : pond) {
sPerms.add(p.getKey().replace("|",":"));
synchronized(bait) {
if(sPerms == null) {
sPerms = new ArrayList<String>();
for(org.onap.aaf.cadi.Permission p : pond) {
sPerms.add(p.getKey().replace("|",":"));
- System.out.println("Replacing | to :" + p.getKey().replace("|",":"));
+// System.out.println("Replacing | to :" + p.getKey().replace("|",":"));
import java.util.Map.Entry;
import java.util.TreeMap;
import java.util.Map.Entry;
import java.util.TreeMap;
-import org.apache.log4j.Logger;
import org.apache.log4j.PropertyConfigurator;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.AuthenticationInfo;
import org.apache.log4j.PropertyConfigurator;
import org.apache.shiro.authc.AuthenticationException;
import org.apache.shiro.authc.AuthenticationInfo;
import org.onap.aaf.cadi.filter.MapBathConverter;
import org.onap.aaf.cadi.util.CSV;
import org.onap.aaf.misc.env.APIException;
import org.onap.aaf.cadi.filter.MapBathConverter;
import org.onap.aaf.cadi.util.CSV;
import org.onap.aaf.misc.env.APIException;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+
public class AAFRealm extends AuthorizingRealm {
public class AAFRealm extends AuthorizingRealm {
- final static Logger logger = Logger.getLogger(AAFRealm.class);
+ final static Logger logger = LoggerFactory.getLogger(AAFRealm.class);
public static final String AAF_REALM = "AAFRealm";
public static final String AAF_REALM = "AAFRealm";
String cadi_prop_files = access.getProperty(Config.CADI_PROP_FILES);
if(cadi_prop_files==null) {
String msg = Config.CADI_PROP_FILES + " in VM Args is required to initialize AAFRealm.";
String cadi_prop_files = access.getProperty(Config.CADI_PROP_FILES);
if(cadi_prop_files==null) {
String msg = Config.CADI_PROP_FILES + " in VM Args is required to initialize AAFRealm.";
- access.log(Level.INIT,msg);
+ access.log(Level.DEBUG,msg);
throw new RuntimeException(msg);
} else {
try {
String log4jConfigFile = "./etc/org.ops4j.pax.logging.cfg";
throw new RuntimeException(msg);
} else {
try {
String log4jConfigFile = "./etc/org.ops4j.pax.logging.cfg";
PropertyConfigurator.configure(log4jConfigFile);
System.setOut(createLoggingProxy(System.out));
System.setErr(createLoggingProxy(System.err));
PropertyConfigurator.configure(log4jConfigFile);
System.setOut(createLoggingProxy(System.out));
System.setErr(createLoggingProxy(System.err));
acon = AAFCon.newInstance(access);
authn = acon.newAuthn();
authz = acon.newLur(authn);
acon = AAFCon.newInstance(access);
authn = acon.newAuthn();
authz = acon.newLur(authn);
final String csv = access.getProperty(Config.CADI_BATH_CONVERT);
if(csv!=null) {
try {
final String csv = access.getProperty(Config.CADI_BATH_CONVERT);
if(csv!=null) {
try {
idMap.put(oldID,newID);
}
} catch (IOException e) {
idMap.put(oldID,newID);
}
} catch (IOException e) {
- logger.error(e.getMessage(), e);
}
}
} catch (APIException | CadiException | LocatorException e) {
String msg = "Cannot initiate AAFRealm";
}
}
} catch (APIException | CadiException | LocatorException e) {
String msg = "Cannot initiate AAFRealm";
- logger.info(msg + " "+ e.getMessage(), e);
+ access.log(Level.INIT,msg,e.getMessage());
throw new RuntimeException(msg,e);
}
}
throw new RuntimeException(msg,e);
}
}
@Override
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
@Override
protected AuthenticationInfo doGetAuthenticationInfo(AuthenticationToken token) throws AuthenticationException {
- logger.debug("AAFRealm.doGetAuthenticationInfo :"+token);
-
final UsernamePasswordToken upt = (UsernamePasswordToken)token;
final String user = upt.getUsername();
String authUser = user;
final String password=new String(upt.getPassword());
String authPassword = password;
final UsernamePasswordToken upt = (UsernamePasswordToken)token;
final String user = upt.getUsername();
String authUser = user;
final String password=new String(upt.getPassword());
String authPassword = password;
final String oldBath = "Basic " + Symm.base64noSplit.encode(user+':'+password);
String bath = mbc.convert(access, oldBath);
if(bath!=oldBath) {
final String oldBath = "Basic " + Symm.base64noSplit.encode(user+':'+password);
String bath = mbc.convert(access, oldBath);
if(bath!=oldBath) {
int colon = bath.indexOf(':');
if(colon>=0) {
authUser = bath.substring(0, colon);
int colon = bath.indexOf(':');
if(colon>=0) {
authUser = bath.substring(0, colon);
- authPassword = bath.substring(colon+1);
+ authPassword = bath.substring(colon+1);
+ access.log(Level.DEBUG, authUser,"user authenticated");
+ access.log(Level.DEBUG, authn.validate(authUser,authPassword));
}
}
} catch (IOException e) {
}
}
} catch (IOException e) {
- logger.error(e.getMessage(), e);
err = authn.validate(authUser,authPassword);
} catch (IOException e) {
err = "Credential cannot be validated";
err = authn.validate(authUser,authPassword);
} catch (IOException e) {
err = "Credential cannot be validated";
+ access.log(Level.DEBUG, e, err);
+ access.log(Level.DEBUG, err, " - Credential cannot be validated");
throw new AuthenticationException(err);
}
throw new AuthenticationException(err);
}
@Override
protected AAFAuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
@Override
protected AAFAuthorizationInfo doGetAuthorizationInfo(PrincipalCollection principals) {
- logger.debug("AAFRealm.doGetAuthenthorizationInfo");
Principal bait = (Principal)principals.getPrimaryPrincipal();
Principal newBait = bait;
if(idMap!=null) {
Principal bait = (Principal)principals.getPrimaryPrincipal();
Principal newBait = bait;
if(idMap!=null) {
}
List<Permission> pond = new ArrayList<>();
authz.fishAll(newBait,pond);
}
List<Permission> pond = new ArrayList<>();
authz.fishAll(newBait,pond);
return new AAFAuthorizationInfo(access,bait,pond);
}
return new AAFAuthorizationInfo(access,bait,pond);
}
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
</parent>
<artifactId>fproxy</artifactId>
</parent>
<artifactId>fproxy</artifactId>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
<parent>
<groupId>org.onap.aaf.cadi</groupId>
<artifactId>parent</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
<relativePath>..</relativePath>
</parent>
<modelVersion>4.0.0</modelVersion>
<relativePath>..</relativePath>
</parent>
<modelVersion>4.0.0</modelVersion>
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
</parent>
<artifactId>rproxy</artifactId>
</parent>
<artifactId>rproxy</artifactId>
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
<parent>
<groupId>org.onap.aaf.cadi.sidecar</groupId>
<artifactId>sidecar</artifactId>
- <version>2.1.10-SNAPSHOT</version>
+ <version>2.1.11-SNAPSHOT</version>
</parent>
<artifactId>tproxy-config</artifactId>
</parent>
<artifactId>tproxy-config</artifactId>
base_version=${major}.${minor}.${patch}
base_version=${major}.${minor}.${patch}