Class AbstractAuthenticationServlet
- java.lang.Object
-
- javax.servlet.GenericServlet
-
- javax.servlet.http.HttpServlet
-
- edu.uiuc.ncsa.security.servlet.AbstractServlet
-
- org.oa4mp.server.api.storage.servlet.EnvServlet
-
- org.oa4mp.server.api.storage.servlet.OA4MPServlet
-
- org.oa4mp.server.api.storage.servlet.AbstractAuthenticationServlet
-
- All Implemented Interfaces:
edu.uiuc.ncsa.security.core.Logable,edu.uiuc.ncsa.security.servlet.Presentable,Serializable,javax.servlet.Servlet,javax.servlet.ServletConfig,TransactionFilter
- Direct Known Subclasses:
OA2AuthenticationServer
public abstract class AbstractAuthenticationServlet extends OA4MPServlet implements edu.uiuc.ncsa.security.servlet.Presentable
Created by Jeff Gaynor
on 1/14/14 at 11:50 AM- See Also:
- Serialized Form
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classAbstractAuthenticationServlet.AuthorizedStateState object after authorization has worked.static classAbstractAuthenticationServlet.MyHttpServletResponseWrapperThis class is needed to pass information between servlets, where one servlet calls another.static classAbstractAuthenticationServlet.UserLoginException
-
Field Summary
Fields Modifier and Type Field Description static StringAUTHORIZATION_ACTION_DF_CONSENT_VALUEstatic intAUTHORIZATION_ACTION_DONEstatic StringAUTHORIZATION_ACTION_DONE_VALUEstatic StringAUTHORIZATION_ACTION_KEYstatic intAUTHORIZATION_ACTION_OKstatic StringAUTHORIZATION_ACTION_OK_VALUEstatic intAUTHORIZATION_ACTION_PROXY_DF_CONSENTstatic intAUTHORIZATION_ACTION_STARTstatic StringAUTHORIZATION_GRANT_KEYstatic StringAUTHORIZATION_PASSWORD_KEYstatic StringAUTHORIZATION_STATE_KEYstatic StringAUTHORIZATION_USER_NAME_KEYstatic StringAUTHORIZATION_USER_NAME_VALUEstatic StringDF_USER_CODE_KEYstatic StringERROR_PAGEstatic StringINITIAL_PAGEstatic StringOK_PAGEstatic StringPROXY_KEYstatic StringREMOTE_USER_INITIAL_PAGEstatic StringRESPONSE_TYPE_DF_VALUEstatic StringRESPONSE_TYPE_KEYstatic StringRESPONSE_TYPE_TOKEN_VALUEstatic StringRETRY_MESSAGEstatic StringTOKEN_KEY_KEY-
Fields inherited from class org.oa4mp.server.api.storage.servlet.OA4MPServlet
caThread, kpt, lastAccessedThread, transactionCleanup
-
Fields inherited from class org.oa4mp.server.api.storage.servlet.EnvServlet
ERROR_NOTIFICATION_BODY_KEY, ERROR_NOTIFICATION_SUBJECT_KEY, notificationListeners, storeUpdatesDone
-
-
Constructor Summary
Constructors Constructor Description AbstractAuthenticationServlet()
-
Method Summary
All Methods Static Methods Instance Methods Abstract Methods Concrete Methods Modifier and Type Method Description voidcheckUser(String username, String password)If OA4MP has been extended to have a native concept of a user, this is the method that is used to verify them.abstract StringcreateCallback(ServiceTransaction transaction, Map<String,String> params)This will take whatever the passed in callback from the client is and append any parameters needed.protected voidcreateRedirect(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response, ServiceTransaction trans)protected abstract voidcreateRedirectInit(ServiceTransaction trans, String userName, String password)Additional setup for the callback.protected voiddoIt(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response)protected voiddoProxy(AbstractAuthenticationServlet.AuthorizedState state)protected ServiceTransactiongetAndCheckTransaction(String token)protected StringgetInitialPage()protected StringgetOkPage()protected StringgetParam(javax.servlet.http.HttpServletRequest request, String key)protected StringgetRemoteUserInitialPage()static intgetState(javax.servlet.http.HttpServletRequest request)Basically a switch statement for the auth actions, but with the special case that no action meansAUTHORIZATION_ACTION_START, since that is an initial request with no state.voidhandleError(edu.uiuc.ncsa.security.servlet.PresentableState state, Throwable t)voidprepare(edu.uiuc.ncsa.security.servlet.PresentableState state)voidpresent(edu.uiuc.ncsa.security.servlet.PresentableState state)protected voidsetClientRequestAttributes(AbstractAuthenticationServlet.AuthorizedState aState)ServiceTransactionverifyAndGet(IssuerResponse iResponse)This is called after the response is received so that the system can get the approproate transaction.-
Methods inherited from class org.oa4mp.server.api.storage.servlet.OA4MPServlet
checkAdminClientStatus, checkClientApproval, createDebugger, destroy, findSigningKey, getAGI, getATI, getClient, getClient, getClient, getFirstParameters, getFirstParameterValue, getGrantIDFromRequest, getServiceEnvironment, getTransaction, getTransactionByGrantID, getTransactionStore, isEmpty, loadProperties2, newTransaction, postprocess, preprocess, realStoreUpdates, say, shutdownCleanup, storeUpdates
-
Methods inherited from class org.oa4mp.server.api.storage.servlet.EnvServlet
addNotificationListener, checkCancel, checkCancel, isCancelled, loadEnvironment, processStoreCheck, removeNotificationListener
-
Methods inherited from class edu.uiuc.ncsa.security.servlet.AbstractServlet
checkContentType, CONST, debug, doGet, doPing, doPost, error, error, getConfigurationLoader, getEnvironment, getExceptionHandler, getInitialization, getMyLogger, getRequestIPAddress, handleException, info, init, isDebugOn, logOK, logOK, printAllParameters, printAllParameters, resetState, setConfigurationLoader, setDebugOn, setEnvironment, setExceptionHandler, setInitialization, warn
-
Methods inherited from class javax.servlet.http.HttpServlet
doDelete, doHead, doOptions, doPut, doTrace, getLastModified, service, service
-
-
-
-
Field Detail
-
AUTHORIZATION_ACTION_KEY
public static final String AUTHORIZATION_ACTION_KEY
- See Also:
- Constant Field Values
-
AUTHORIZATION_USER_NAME_KEY
public static final String AUTHORIZATION_USER_NAME_KEY
- See Also:
- Constant Field Values
-
AUTHORIZATION_USER_NAME_VALUE
public static final String AUTHORIZATION_USER_NAME_VALUE
- See Also:
- Constant Field Values
-
AUTHORIZATION_PASSWORD_KEY
public static final String AUTHORIZATION_PASSWORD_KEY
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_OK_VALUE
public static final String AUTHORIZATION_ACTION_OK_VALUE
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_DONE_VALUE
public static final String AUTHORIZATION_ACTION_DONE_VALUE
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_DF_CONSENT_VALUE
public static final String AUTHORIZATION_ACTION_DF_CONSENT_VALUE
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_DONE
public static final int AUTHORIZATION_ACTION_DONE
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_PROXY_DF_CONSENT
public static final int AUTHORIZATION_ACTION_PROXY_DF_CONSENT
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_OK
public static final int AUTHORIZATION_ACTION_OK
- See Also:
- Constant Field Values
-
AUTHORIZATION_ACTION_START
public static final int AUTHORIZATION_ACTION_START
- See Also:
- Constant Field Values
-
RETRY_MESSAGE
public static final String RETRY_MESSAGE
- See Also:
- Constant Field Values
-
AUTHORIZATION_GRANT_KEY
public static final String AUTHORIZATION_GRANT_KEY
- See Also:
- Constant Field Values
-
AUTHORIZATION_STATE_KEY
public static final String AUTHORIZATION_STATE_KEY
- See Also:
- Constant Field Values
-
PROXY_KEY
public static final String PROXY_KEY
- See Also:
- Constant Field Values
-
RESPONSE_TYPE_KEY
public static final String RESPONSE_TYPE_KEY
- See Also:
- Constant Field Values
-
RESPONSE_TYPE_TOKEN_VALUE
public static final String RESPONSE_TYPE_TOKEN_VALUE
- See Also:
- Constant Field Values
-
RESPONSE_TYPE_DF_VALUE
public static final String RESPONSE_TYPE_DF_VALUE
- See Also:
- Constant Field Values
-
TOKEN_KEY_KEY
public static final String TOKEN_KEY_KEY
- See Also:
- Constant Field Values
-
DF_USER_CODE_KEY
public static final String DF_USER_CODE_KEY
- See Also:
- Constant Field Values
-
INITIAL_PAGE
public static String INITIAL_PAGE
-
REMOTE_USER_INITIAL_PAGE
public static String REMOTE_USER_INITIAL_PAGE
-
OK_PAGE
public static String OK_PAGE
-
ERROR_PAGE
public static String ERROR_PAGE
-
-
Method Detail
-
verifyAndGet
public ServiceTransaction verifyAndGet(IssuerResponse iResponse) throws IOException
Description copied from class:OA4MPServletThis is called after the response is received so that the system can get the approproate transaction. Checks for the validity of the transaction should be done here too.- Specified by:
verifyAndGetin classOA4MPServlet- Returns:
- Throws:
IOException
-
createCallback
public abstract String createCallback(ServiceTransaction transaction, Map<String,String> params)
This will take whatever the passed in callback from the client is and append any parameters needed. Generally these parameters are protocol specific.- Parameters:
transaction-- Returns:
-
prepare
public void prepare(edu.uiuc.ncsa.security.servlet.PresentableState state) throws Throwable- Specified by:
preparein interfaceedu.uiuc.ncsa.security.servlet.Presentable- Throws:
Throwable
-
setClientRequestAttributes
protected void setClientRequestAttributes(AbstractAuthenticationServlet.AuthorizedState aState)
-
getInitialPage
protected String getInitialPage()
-
getRemoteUserInitialPage
protected String getRemoteUserInitialPage()
-
getOkPage
protected String getOkPage()
-
doProxy
protected void doProxy(AbstractAuthenticationServlet.AuthorizedState state) throws Throwable
- Throws:
Throwable
-
present
public void present(edu.uiuc.ncsa.security.servlet.PresentableState state) throws Throwable- Specified by:
presentin interfaceedu.uiuc.ncsa.security.servlet.Presentable- Throws:
Throwable
-
handleError
public void handleError(edu.uiuc.ncsa.security.servlet.PresentableState state, Throwable t) throws IOException, javax.servlet.ServletException- Specified by:
handleErrorin interfaceedu.uiuc.ncsa.security.servlet.Presentable- Throws:
IOExceptionjavax.servlet.ServletException
-
doIt
protected void doIt(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response) throws Throwable- Specified by:
doItin classedu.uiuc.ncsa.security.servlet.AbstractServlet- Throws:
Throwable
-
getState
public static int getState(javax.servlet.http.HttpServletRequest request)
Basically a switch statement for the auth actions, but with the special case that no action meansAUTHORIZATION_ACTION_START, since that is an initial request with no state.- Parameters:
request-- Returns:
-
getAndCheckTransaction
protected ServiceTransaction getAndCheckTransaction(String token) throws IOException
- Throws:
IOException
-
createRedirect
protected void createRedirect(javax.servlet.http.HttpServletRequest request, javax.servlet.http.HttpServletResponse response, ServiceTransaction trans) throws Throwable- Throws:
Throwable
-
createRedirectInit
protected abstract void createRedirectInit(ServiceTransaction trans, String userName, String password)
Additional setup for the callback. This is aimed at MyProxy aware services.- Parameters:
trans-userName-password-
-
checkUser
public void checkUser(String username, String password) throws GeneralSecurityException
If OA4MP has been extended to have a native concept of a user, this is the method that is used to verify them. Normally this is only called if explicitly set and no other authorization method (such as a proxy) is configured. Therefore, the default behavior is to throw an exception, but this is where the logic has to be. To add a user, extend OA2AuthorizationServer, override this method to talk to whatever manages your users and set your servlet as the authorization endpoint.- Parameters:
username-password-- Throws:
GeneralSecurityException
-
-