Fix Vulnerabilities in SubscriptionServlet 47/66647/7
authorConor Ward <conor.ward@ericsson.com>
Fri, 14 Sep 2018 13:22:18 +0000 (13:22 +0000)
committerConor Ward <conor.ward@ericsson.com>
Mon, 17 Sep 2018 10:17:01 +0000 (10:17 +0000)
Change-Id: I3ba9192d334a6023756eaac217999b01e598d7cb
Signed-off-by: Conor Ward <conor.ward@ericsson.com>
Issue-ID: DMAAP-775

datarouter-prov/src/main/java/org/onap/dmaap/datarouter/provisioning/SubscriptionServlet.java
datarouter-prov/src/main/java/org/onap/dmaap/datarouter/provisioning/utils/HttpServletUtils.java [new file with mode: 0644]

index 3294580..3bfa750 100644 (file)
@@ -44,6 +44,8 @@ import org.onap.dmaap.datarouter.provisioning.eelf.EelfMsgs;
 import com.att.eelf.configuration.EELFLogger;\r
 import com.att.eelf.configuration.EELFManager;\r
 \r
+import static org.onap.dmaap.datarouter.provisioning.utils.HttpServletUtils.sendResponseError;\r
+\r
 /**\r
  * This servlet handles provisioning for the &lt;subscriptionURL&gt; which is generated by the provisioning server to\r
  * handle the inspection, modification, and deletion of a particular subscription to a feed. It supports DELETE to\r
@@ -66,7 +68,7 @@ public class SubscriptionServlet extends ProxyServlet {
      * the <b>Provisioning API</b> document for details on how this method should be invoked.\r
      */\r
     @Override\r
-    public void doDelete(HttpServletRequest req, HttpServletResponse resp) throws IOException {\r
+    public void doDelete(HttpServletRequest req, HttpServletResponse resp) {\r
         setIpAndFqdnForEelf("doDelete");\r
         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_SUBID, req.getHeader(BEHALF_HEADER), getIdFromPath(req) + "");\r
         EventLogRecord elr = new EventLogRecord(req);\r
@@ -75,11 +77,15 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         if (isProxyServer()) {\r
-            super.doDelete(req, resp);\r
+            try {\r
+                super.doDelete(req, resp);\r
+            } catch (IOException ioe) {\r
+                eventlogger.error("IOException: " + ioe.getMessage());\r
+            }\r
             return;\r
         }\r
         String bhdr = req.getHeader(BEHALF_HEADER);\r
@@ -88,7 +94,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         int subid = getIdFromPath(req);\r
@@ -97,7 +103,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         Subscription sub = Subscription.getSubscriptionById(subid);\r
@@ -106,7 +112,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_NOT_FOUND);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_NOT_FOUND, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_NOT_FOUND, message, eventlogger);\r
             return;\r
         }\r
         // Check with the Authorizer\r
@@ -116,7 +122,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
 \r
@@ -132,7 +138,7 @@ public class SubscriptionServlet extends ProxyServlet {
             // Something went wrong with the DELETE\r
             elr.setResult(HttpServletResponse.SC_INTERNAL_SERVER_ERROR);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, DB_PROBLEM_MSG);\r
+            sendResponseError(resp, HttpServletResponse.SC_INTERNAL_SERVER_ERROR, DB_PROBLEM_MSG, intlogger);\r
         }\r
     }\r
 \r
@@ -142,7 +148,7 @@ public class SubscriptionServlet extends ProxyServlet {
      * invoked.\r
      */\r
     @Override\r
-    public void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {\r
+    public void doGet(HttpServletRequest req, HttpServletResponse resp) {\r
         setIpAndFqdnForEelf("doGet");\r
         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_SUBID, req.getHeader(BEHALF_HEADER), getIdFromPath(req) + "");\r
         EventLogRecord elr = new EventLogRecord(req);\r
@@ -151,11 +157,15 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         if (isProxyServer()) {\r
-            super.doGet(req, resp);\r
+            try {\r
+                super.doGet(req, resp);\r
+            } catch (IOException ioe) {\r
+                eventlogger.error("IOException: " + ioe.getMessage());\r
+            }\r
             return;\r
         }\r
         String bhdr = req.getHeader(BEHALF_HEADER);\r
@@ -164,7 +174,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         int subid = getIdFromPath(req);\r
@@ -173,7 +183,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         Subscription sub = Subscription.getSubscriptionById(subid);\r
@@ -182,7 +192,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_NOT_FOUND);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_NOT_FOUND, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_NOT_FOUND, message, eventlogger);\r
             return;\r
         }\r
         // Check with the Authorizer\r
@@ -192,7 +202,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
 \r
@@ -201,7 +211,11 @@ public class SubscriptionServlet extends ProxyServlet {
         eventlogger.info(elr);\r
         resp.setStatus(HttpServletResponse.SC_OK);\r
         resp.setContentType(SUBFULL_CONTENT_TYPE);\r
-        resp.getOutputStream().print(sub.asJSONObject(true).toString());\r
+        try {\r
+            resp.getOutputStream().print(sub.asJSONObject(true).toString());\r
+        } catch (IOException ioe) {\r
+            eventlogger.error("IOException: " + ioe.getMessage());\r
+        }\r
     }\r
 \r
     /**\r
@@ -209,7 +223,7 @@ public class SubscriptionServlet extends ProxyServlet {
      * the <b>Provisioning API</b> document for details on how this method should be invoked.\r
      */\r
     @Override\r
-    public void doPut(HttpServletRequest req, HttpServletResponse resp) throws IOException {\r
+    public void doPut(HttpServletRequest req, HttpServletResponse resp) {\r
         setIpAndFqdnForEelf("doPut");\r
         eelflogger.info(EelfMsgs.MESSAGE_WITH_BEHALF_AND_SUBID, req.getHeader(BEHALF_HEADER), getIdFromPath(req) + "");\r
         EventLogRecord elr = new EventLogRecord(req);\r
@@ -218,11 +232,15 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         if (isProxyServer()) {\r
-            super.doPut(req, resp);\r
+            try {\r
+                super.doPut(req, resp);\r
+            } catch (IOException ioe) {\r
+                eventlogger.error("IOException: " + ioe.getMessage());\r
+            }\r
             return;\r
         }\r
         String bhdr = req.getHeader(BEHALF_HEADER);\r
@@ -231,7 +249,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         int subid = getIdFromPath(req);\r
@@ -240,7 +258,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         Subscription oldsub = Subscription.getSubscriptionById(subid);\r
@@ -249,7 +267,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_NOT_FOUND);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_NOT_FOUND, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_NOT_FOUND, message, eventlogger);\r
             return;\r
         }\r
         // Check with the Authorizer\r
@@ -259,7 +277,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         // check content type is SUB_CONTENT_TYPE, version 1.0\r
@@ -270,7 +288,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE, message, eventlogger);\r
             return;\r
         }\r
         JSONObject jo = getJSONfromInput(req);\r
@@ -279,7 +297,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         if (intlogger.isDebugEnabled()) {\r
@@ -293,7 +311,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         sub.setSubid(oldsub.getSubid());\r
@@ -306,7 +324,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
 \r
@@ -317,14 +335,22 @@ public class SubscriptionServlet extends ProxyServlet {
             eventlogger.info(elr);\r
             resp.setStatus(HttpServletResponse.SC_OK);\r
             resp.setContentType(SUBFULL_CONTENT_TYPE);\r
-            resp.getOutputStream().print(sub.asLimitedJSONObject().toString());\r
+            try {\r
+                resp.getOutputStream().print(sub.asLimitedJSONObject().toString());\r
+            } catch (IOException ioe) {\r
+                eventlogger.error("IOException: " + ioe.getMessage());\r
+            }\r
 \r
             /**Change Owner ship of Subscriber     Adding for group feature:Rally US708115*/\r
             if (jo.has("changeowner") && subjectgroup != null) {\r
-                Boolean changeowner = (Boolean) jo.get("changeowner");\r
-                if (changeowner != null && changeowner.equals(true)) {\r
-                    sub.setSubscriber(req.getHeader(BEHALF_HEADER));\r
-                    sub.changeOwnerShip();\r
+                try {\r
+                    Boolean changeowner = (Boolean) jo.get("changeowner");\r
+                    if (changeowner != null && changeowner.equals(true)) {\r
+                        sub.setSubscriber(req.getHeader(BEHALF_HEADER));\r
+                        sub.changeOwnerShip();\r
+                    }\r
+                } catch (JSONException je) {\r
+                    eventlogger.error("JSONException: " + je.getMessage());\r
                 }\r
             }\r
             /***End of change ownership*/\r
@@ -334,7 +360,7 @@ public class SubscriptionServlet extends ProxyServlet {
             // Something went wrong with the UPDATE\r
             elr.setResult(HttpServletResponse.SC_INTERNAL_SERVER_ERROR);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, DB_PROBLEM_MSG);\r
+            sendResponseError(resp, HttpServletResponse.SC_INTERNAL_SERVER_ERROR, DB_PROBLEM_MSG, intlogger);\r
         }\r
     }\r
 \r
@@ -343,7 +369,7 @@ public class SubscriptionServlet extends ProxyServlet {
      * Schedule</i> section in the <b>Provisioning API</b> document for details on how this method should be invoked.\r
      */\r
     @Override\r
-    public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {\r
+    public void doPost(HttpServletRequest req, HttpServletResponse resp) {\r
 // OLD pre-3.0 code\r
 //        String message = "POST not allowed for the subscriptionURL.";\r
 //        EventLogRecord elr = new EventLogRecord(req);\r
@@ -360,11 +386,15 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         if (isProxyServer()) {\r
-            super.doPost(req, resp);\r
+            try {\r
+                super.doPost(req, resp);\r
+            } catch (IOException ioe) {\r
+                eventlogger.error("IOException: " + ioe.getMessage());\r
+            }\r
             return;\r
         }\r
         String bhdr = req.getHeader(BEHALF_HEADER);\r
@@ -373,7 +403,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         final int subid = getIdFromPath(req);\r
@@ -382,7 +412,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         // check content type is SUBCNTRL_CONTENT_TYPE, version 1.0\r
@@ -393,7 +423,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_UNSUPPORTED_MEDIA_TYPE, message, eventlogger);\r
             return;\r
         }\r
         // Check with the Authorizer\r
@@ -403,7 +433,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_FORBIDDEN);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_FORBIDDEN, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_FORBIDDEN, message, eventlogger);\r
             return;\r
         }\r
         JSONObject jo = getJSONfromInput(req);\r
@@ -412,7 +442,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
             return;\r
         }\r
         try {\r
@@ -434,7 +464,7 @@ public class SubscriptionServlet extends ProxyServlet {
             elr.setMessage(message);\r
             elr.setResult(HttpServletResponse.SC_BAD_REQUEST);\r
             eventlogger.info(elr);\r
-            resp.sendError(HttpServletResponse.SC_BAD_REQUEST, message);\r
+            sendResponseError(resp, HttpServletResponse.SC_BAD_REQUEST, message, eventlogger);\r
         }\r
     }\r
 \r
@@ -474,7 +504,6 @@ public class SubscriptionServlet extends ProxyServlet {
                 }\r
             } catch (Exception e) {\r
                 intlogger.warn("Caught exception in SubscriberNotifyThread: " + e);\r
-                e.printStackTrace();\r
             }\r
         }\r
     }\r
diff --git a/datarouter-prov/src/main/java/org/onap/dmaap/datarouter/provisioning/utils/HttpServletUtils.java b/datarouter-prov/src/main/java/org/onap/dmaap/datarouter/provisioning/utils/HttpServletUtils.java
new file mode 100644 (file)
index 0000000..ce287f4
--- /dev/null
@@ -0,0 +1,38 @@
+/*******************************************************************************
+ * ============LICENSE_START==================================================
+ * * org.onap.dmaap
+ * * ===========================================================================
+ * * Copyright © 2017 AT&T Intellectual Property. All rights reserved.
+ * * ===========================================================================
+ * * Licensed under the Apache License, Version 2.0 (the "License");
+ * * you may not use this file except in compliance with the License.
+ * * You may obtain a copy of the License at
+ * *
+ *  *      http://www.apache.org/licenses/LICENSE-2.0
+ * *
+ *  * Unless required by applicable law or agreed to in writing, software
+ * * distributed under the License is distributed on an "AS IS" BASIS,
+ * * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * * See the License for the specific language governing permissions and
+ * * limitations under the License.
+ * * ============LICENSE_END====================================================
+ * *
+ * * ECOMP is a trademark and service mark of AT&T Intellectual Property.
+ * *
+ ******************************************************************************/
+package org.onap.dmaap.datarouter.provisioning.utils;
+
+import javax.servlet.http.HttpServletResponse;
+import java.io.IOException;
+
+import org.apache.log4j.Logger;
+
+public class HttpServletUtils {
+    public static void sendResponseError(HttpServletResponse response, int errorCode, String message, Logger intlogger) {
+        try {
+            response.sendError(errorCode, message);
+        } catch (IOException ioe) {
+            intlogger.error("IOException" + ioe.getMessage());
+        }
+    }
+}