2 * ============LICENSE_START=======================================================
4 * ================================================================================
5 * Copyright © 2017-2019 AT&T Intellectual Property. All rights reserved.
6 * Copyright © 2017-2019 European Software Marketing Ltd.
7 * ================================================================================
8 * Licensed under the Apache License, Version 2.0 (the "License");
9 * you may not use this file except in compliance with the License.
10 * You may obtain a copy of the License at
12 * http://www.apache.org/licenses/LICENSE-2.0
14 * Unless required by applicable law or agreed to in writing, software
15 * distributed under the License is distributed on an "AS IS" BASIS,
16 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17 * See the License for the specific language governing permissions and
18 * limitations under the License.
19 * ============LICENSE_END=========================================================
22 package org.onap.aai.auth;
24 import java.security.cert.X509Certificate;
25 import javax.inject.Inject;
26 import javax.security.auth.x500.X500Principal;
27 import javax.servlet.http.HttpServletRequest;
28 import javax.ws.rs.core.HttpHeaders;
29 import org.onap.aai.babel.config.BabelAuthConfig;
30 import org.onap.aai.babel.logging.LogHelper;
31 import org.onap.aai.cl.api.Logger;
34 * Public class for authentication and authorization operations. Authorization is applied according to user and role
36 public class AAIMicroServiceAuth {
38 private static final Logger applicationLogger = LogHelper.INSTANCE;
40 private BabelAuthConfig babelAuthConfig;
43 * @param babelAuthConfig
44 * @throws AAIAuthException
45 * if the Auth Policy cannot be loaded
48 public AAIMicroServiceAuth(final BabelAuthConfig babelAuthConfig) throws AAIAuthException {
49 this.babelAuthConfig = babelAuthConfig;
50 if (!babelAuthConfig.isAuthenticationDisable()) {
51 AAIMicroServiceAuthCore.init(babelAuthConfig.getAuthPolicyFile());
61 * @throws AAIAuthException
63 public boolean validateRequest(HttpHeaders headers /* NOSONAR */, HttpServletRequest req,
64 AAIMicroServiceAuthCore.HTTP_METHODS action, String apiPath) throws AAIAuthException {
66 applicationLogger.debug("validateRequest: " + apiPath);
68 .debug("babelAuthConfig.isAuthenticationDisable(): " + babelAuthConfig.isAuthenticationDisable());
70 if (babelAuthConfig.isAuthenticationDisable()) {
74 String[] ps = apiPath.split("/");
75 String authPolicyFunctionName = ps[ps.length - 1];
76 String cipherSuite = (String) req.getAttribute("javax.servlet.request.cipher_suite");
77 String authUser = null;
79 if (cipherSuite != null) {
80 X509Certificate[] certChain = (X509Certificate[]) req.getAttribute("javax.servlet.request.X509Certificate");
81 X509Certificate clientCert = certChain[0];
82 X500Principal subjectDN = clientCert.getSubjectX500Principal();
83 authUser = subjectDN.toString();
86 if (authUser != null) {
87 return AAIMicroServiceAuthCore.authorize(authUser.toLowerCase(),
88 action.toString() + ":" + authPolicyFunctionName);