Merge "Unit test base"
[dmaap/datarouter.git] / datarouter-prov / src / main / java / org / onap / dmaap / datarouter / provisioning / DRFeedsServlet.java
1 /*******************************************************************************
2  * ============LICENSE_START==================================================
3  * * org.onap.dmaap
4  * * ===========================================================================
5  * * Copyright © 2017 AT&T Intellectual Property. All rights reserved.
6  * * ===========================================================================
7  * * Licensed under the Apache License, Version 2.0 (the "License");
8  * * you may not use this file except in compliance with the License.
9  * * You may obtain a copy of the License at
10  * *
11  *  *      http://www.apache.org/licenses/LICENSE-2.0
12  * *
13  *  * Unless required by applicable law or agreed to in writing, software
14  * * distributed under the License is distributed on an "AS IS" BASIS,
15  * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16  * * See the License for the specific language governing permissions and
17  * * limitations under the License.
18  * * ============LICENSE_END====================================================
19  * *
20  * * ECOMP is a trademark and service mark of AT&T Intellectual Property.
21  * *
22  ******************************************************************************/
23
24
25 package org.onap.dmaap.datarouter.provisioning;
26
27 import java.io.IOException;
28 import java.io.InvalidObjectException;
29 import java.util.List;
30
31 import javax.servlet.http.HttpServletRequest;
32 import javax.servlet.http.HttpServletResponse;
33
34 import org.json.JSONObject;
35 import org.onap.dmaap.datarouter.authz.AuthorizationResponse;
36 import org.onap.dmaap.datarouter.provisioning.beans.EventLogRecord;
37 import org.onap.dmaap.datarouter.provisioning.beans.Feed;
38 import org.onap.dmaap.datarouter.provisioning.eelf.EelfMsgs;
39 import org.onap.dmaap.datarouter.provisioning.utils.JSONUtilities;
40
41 import com.att.eelf.configuration.EELFLogger;
42 import com.att.eelf.configuration.EELFManager;
43
44 /**
45  * This servlet handles provisioning for the <drFeedsURL> which is the URL on the
46  * provisioning server used to create new feeds.  It supports POST to create new feeds,
47  * and GET to support the Feeds Collection Query function.
48  *
49  * @author Robert Eby
50  * @version $Id$
51  */
52 @SuppressWarnings("serial")
53 public class DRFeedsServlet extends ProxyServlet {
54     //Adding EELF Logger Rally:US664892
55     private static EELFLogger eelflogger = EELFManager.getInstance().getLogger("org.onap.dmaap.datarouter.provisioning.DRFeedsServlet");
56
57     /**
58      * DELETE on the <drFeedsURL> -- not supported.
59      */
60     @Override
61     public void doDelete(HttpServletRequest req, HttpServletResponse resp) throws IOException {
62         setIpAndFqdnForEelf("doDelete");
63         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_FEEDID, req.getHeader(BEHALF_HEADER),getIdFromPath(req)+"");
64         String message = "DELETE not allowed for the drFeedsURL.";
65         EventLogRecord elr = new EventLogRecord(req);
66         elr.setMessage(message);
67         elr.setResult(HttpServletResponse.SC_METHOD_NOT_ALLOWED);
68         eventlogger.info(elr);
69         resp.sendError(HttpServletResponse.SC_METHOD_NOT_ALLOWED, message);
70     }
71     /**
72      * GET on the <drFeedsURL> -- query the list of feeds already existing in the DB.
73      * See the <i>Feeds Collection Queries</i> section in the <b>Provisioning API</b>
74      * document for details on how this method should be invoked.
75      */
76     @Override
77     public void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {
78         setIpAndFqdnForEelf("doGet");
79         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_FEEDID, req.getHeader(BEHALF_HEADER),getIdFromPath(req)+"");
80         EventLogRecord elr = new EventLogRecord(req);
81         String message = isAuthorizedForProvisioning(req);
82         if (message != null) {
83             elr.setMessage(message);
84             elr.setResult(HttpServletResponse.SC_FORBIDDEN);
85             eventlogger.info(elr);
86             resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);
87             return;
88         }
89         if (isProxyServer()) {
90             super.doGet(req, resp);
91             return;
92         }
93         String bhdr = req.getHeader(BEHALF_HEADER);
94         if (bhdr == null) {
95             message = "Missing "+BEHALF_HEADER+" header.";
96             elr.setMessage(message);
97             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
98             eventlogger.info(elr);
99             resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
100             return;
101         }
102         String path = req.getRequestURI(); // Note: I think this should be getPathInfo(), but that doesn't work (Jetty bug?)
103         if (path != null && !path.equals("/")) {
104             message = "Bad URL.";
105             elr.setMessage(message);
106             elr.setResult(HttpServletResponse.SC_NOT_FOUND);
107             eventlogger.info(elr);
108             resp.sendError(HttpServletResponse.SC_NOT_FOUND, message);
109             return;
110         }
111         // Check with the Authorizer
112         AuthorizationResponse aresp = authz.decide(req);
113         if (! aresp.isAuthorized()) {
114             message = "Policy Engine disallows access.";
115             elr.setMessage(message);
116             elr.setResult(HttpServletResponse.SC_FORBIDDEN);
117             eventlogger.info(elr);
118             resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);
119             return;
120         }
121
122         String name = req.getParameter("name");
123         String vers = req.getParameter("version");
124         String publ = req.getParameter("publisher");
125         String subs = req.getParameter("subscriber");
126         if (name != null && vers != null) {
127             // Display a specific feed
128             Feed feed = Feed.getFeedByNameVersion(name, vers);
129             if (feed == null || feed.isDeleted()) {
130                 message = "This feed does not exist in the database.";
131                 elr.setMessage(message);
132                 elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
133                 eventlogger.info(elr);
134                 resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
135             } else {
136                 // send response
137                 elr.setResult(HttpServletResponse.SC_OK);
138                 eventlogger.info(elr);
139                 resp.setStatus(HttpServletResponse.SC_OK);
140                 resp.setContentType(FEEDFULL_CONTENT_TYPE);
141                 resp.getOutputStream().print(feed.asJSONObject(true).toString());
142             }
143         } else {
144             // Display a list of URLs
145             List<String> list = null;
146             if (name != null) {
147                 list = Feed.getFilteredFeedUrlList("name", name);
148             } else if (publ != null) {
149                 list = Feed.getFilteredFeedUrlList("publ", publ);
150             } else if (subs != null) {
151                 list = Feed.getFilteredFeedUrlList("subs", subs);
152             } else {
153                 list = Feed.getFilteredFeedUrlList("all", null);
154             }
155             String t = JSONUtilities.createJSONArray(list);
156             // send response
157             elr.setResult(HttpServletResponse.SC_OK);
158             eventlogger.info(elr);
159             resp.setStatus(HttpServletResponse.SC_OK);
160             resp.setContentType(FEEDLIST_CONTENT_TYPE);
161             resp.getOutputStream().print(t);
162         }
163     }
164     /**
165      * PUT on the &lt;drFeedsURL&gt; -- not supported.
166      */
167     @Override
168     public void doPut(HttpServletRequest req, HttpServletResponse resp) throws IOException {
169         setIpAndFqdnForEelf("doPut");
170         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_FEEDID, req.getHeader(BEHALF_HEADER),getIdFromPath(req)+"");
171         String message = "PUT not allowed for the drFeedsURL.";
172         EventLogRecord elr = new EventLogRecord(req);
173         elr.setMessage(message);
174         elr.setResult(HttpServletResponse.SC_METHOD_NOT_ALLOWED);
175         eventlogger.info(elr);
176         resp.sendError(HttpServletResponse.SC_METHOD_NOT_ALLOWED, message);
177     }
178     /**
179      * POST on the &lt;drFeedsURL&gt; -- create a new feed.
180      * See the <i>Creating a Feed</i> section in the <b>Provisioning API</b>
181      * document for details on how this method should be invoked.
182      */
183     @Override
184     public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
185         setIpAndFqdnForEelf("doPost");
186         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF, req.getHeader(BEHALF_HEADER));
187         EventLogRecord elr = new EventLogRecord(req);
188         String message = isAuthorizedForProvisioning(req);
189         if (message != null) {
190             elr.setMessage(message);
191             elr.setResult(HttpServletResponse.SC_FORBIDDEN);
192             eventlogger.info(elr);
193             resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);
194             return;
195         }
196         if (isProxyServer()) {
197             super.doPost(req, resp);
198             return;
199         }
200         String bhdr = req.getHeader(BEHALF_HEADER);
201         if (bhdr == null) {
202             message = "Missing "+BEHALF_HEADER+" header.";
203             elr.setMessage(message);
204             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
205             eventlogger.info(elr);
206             resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
207             return;
208         }
209         String path = req.getRequestURI(); // Note: I think this should be getPathInfo(), but that doesn't work (Jetty bug?)
210         if (path != null && !path.equals("/")) {
211             message = "Bad URL.";
212             elr.setMessage(message);
213             elr.setResult(HttpServletResponse.SC_NOT_FOUND);
214             eventlogger.info(elr);
215             resp.sendError(HttpServletResponse.SC_NOT_FOUND, message);
216             return;
217         }
218         // check content type is FEED_CONTENT_TYPE, version 1.0
219         ContentHeader ch = getContentHeader(req);
220         String ver = ch.getAttribute("version");
221         if (!ch.getType().equals(FEED_BASECONTENT_TYPE) || !(ver.equals("1.0") || ver.equals("2.0"))) {
222             message = "Incorrect content-type";
223             elr.setMessage(message);
224             elr.setResult(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);
225             eventlogger.info(elr);
226             resp.sendError(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE, message);
227             return;
228         }
229         // Check with the Authorizer
230         AuthorizationResponse aresp = authz.decide(req);
231         if (! aresp.isAuthorized()) {
232             message = "Policy Engine disallows access.";
233             elr.setMessage(message);
234             elr.setResult(HttpServletResponse.SC_FORBIDDEN);
235             eventlogger.info(elr);
236             resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);
237             return;
238         }
239         JSONObject jo = getJSONfromInput(req);
240         if (jo == null) {
241             message = "Badly formed JSON";
242             elr.setMessage(message);
243             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
244             eventlogger.info(elr);
245             resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
246             return;
247         }
248         if (intlogger.isDebugEnabled())
249             intlogger.debug(jo.toString());
250         if (++active_feeds > max_feeds) {
251             active_feeds--;
252             message = "Cannot create feed; the maximum number of feeds has been configured.";
253             elr.setMessage(message);
254             elr.setResult(HttpServletResponse.SC_CONFLICT);
255             eventlogger.info(elr);
256             resp.sendError(HttpServletResponse.SC_CONFLICT, message);
257             return;
258         }
259         Feed feed = null;
260         try {
261             feed = new Feed(jo);
262         } catch (InvalidObjectException e) {
263             message = e.getMessage();
264             elr.setMessage(message);
265             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
266             eventlogger.info(elr);
267             resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
268             return;
269         }
270         feed.setPublisher(bhdr);    // set from X-ATT-DR-ON-BEHALF-OF header
271
272         // Check if this feed already exists
273         Feed feed2 = Feed.getFeedByNameVersion(feed.getName(), feed.getVersion());
274         if (feed2 != null) {
275             message = "This feed already exists in the database.";
276             elr.setMessage(message);
277             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);
278             eventlogger.info(elr);
279             resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);
280             return;
281         }
282
283         // Create FEED table entries
284         if (doInsert(feed)) {
285             // send response
286             elr.setResult(HttpServletResponse.SC_CREATED);
287             eventlogger.info(elr);
288             resp.setStatus(HttpServletResponse.SC_CREATED);
289             resp.setContentType(FEEDFULL_CONTENT_TYPE);
290             resp.setHeader("Location", feed.getLinks().getSelf());
291             resp.getOutputStream().print(feed.asLimitedJSONObject().toString());
292             provisioningDataChanged();
293         } else {
294             // Something went wrong with the INSERT
295             elr.setResult(HttpServletResponse.SC_INTERNAL_SERVER_ERROR);
296             eventlogger.info(elr);
297             resp.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, DB_PROBLEM_MSG);
298         }
299     }
300 }