| margaretha | 139d0f7 | 2017-11-14 18:56:22 +0100 | [diff] [blame] | 1 | package de.ids_mannheim.korap.authentication; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 2 | |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 3 | import java.text.ParseException; |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 4 | import java.time.ZoneId; |
| 5 | import java.time.ZonedDateTime; |
| 6 | import java.util.Date; |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 7 | import java.util.Map; |
| 8 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 9 | import org.apache.logging.log4j.LogManager; |
| 10 | import org.apache.logging.log4j.Logger; |
| 11 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 12 | import com.nimbusds.jose.JOSEException; |
| 13 | import com.nimbusds.jwt.SignedJWT; |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 14 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 15 | import de.ids_mannheim.korap.config.Attributes; |
| margaretha | 5225ed0 | 2018-06-25 18:38:40 +0200 | [diff] [blame] | 16 | import de.ids_mannheim.korap.config.FullConfiguration; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 17 | import de.ids_mannheim.korap.config.JWTSigner; |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 18 | import de.ids_mannheim.korap.constant.TokenType; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 19 | import de.ids_mannheim.korap.exceptions.KustvaktException; |
| 20 | import de.ids_mannheim.korap.exceptions.StatusCodes; |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 21 | import de.ids_mannheim.korap.security.context.TokenContext; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 22 | import de.ids_mannheim.korap.user.User; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 23 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 24 | /** |
| margaretha | 398f472 | 2019-01-09 19:07:20 +0100 | [diff] [blame] | 25 | * Authentication provider using JWT tokens |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 26 | * |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 27 | * Created by hanl on 5/23/14. |
| 28 | */ |
| margaretha | bc3d3f7 | 2023-02-15 15:34:12 +0100 | [diff] [blame] | 29 | @Deprecated |
| margaretha | dfecb4b | 2017-12-12 19:32:30 +0100 | [diff] [blame] | 30 | public class APIAuthentication implements AuthenticationIface { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 31 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 32 | private static Logger jlog = LogManager.getLogger(APIAuthentication.class); |
| margaretha | dda4ef7 | 2018-12-06 14:20:51 +0100 | [diff] [blame] | 33 | public static boolean DEBUG = false; |
| 34 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 35 | private JWTSigner signedToken; |
| 36 | |
| margaretha | 5225ed0 | 2018-06-25 18:38:40 +0200 | [diff] [blame] | 37 | public APIAuthentication (FullConfiguration config) throws JOSEException { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 38 | this.signedToken = new JWTSigner(config.getSharedSecret(), |
| 39 | config.getIssuer(), config.getTokenTTL()); |
| 40 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 41 | |
| 42 | /** |
| 43 | * EM: for testing |
| 44 | * |
| margaretha | dfecb4b | 2017-12-12 19:32:30 +0100 | [diff] [blame] | 45 | * @param signedToken |
| 46 | */ |
| 47 | public APIAuthentication (JWTSigner signedToken) { |
| 48 | this.signedToken = signedToken; |
| 49 | } |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 50 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 51 | @Override |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 52 | public TokenContext getTokenContext (String authToken) |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 53 | throws KustvaktException { |
| Michael Hanl | f1e85e7 | 2016-01-21 16:55:45 +0100 | [diff] [blame] | 54 | TokenContext context; |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 55 | // Element ein = invalided.get(authToken); |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 56 | try { |
| 57 | context = signedToken.getTokenContext(authToken); |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 58 | context.setTokenType(getTokenType()); |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 59 | } |
| 60 | catch (JOSEException | ParseException ex) { |
| 61 | throw new KustvaktException(StatusCodes.ILLEGAL_ARGUMENT); |
| 62 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 63 | // context = (TokenContext) e.getObjectValue(); |
| 64 | // throw new KustvaktException(StatusCodes.EXPIRED); |
| Michael Hanl | f1e85e7 | 2016-01-21 16:55:45 +0100 | [diff] [blame] | 65 | return context; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 66 | } |
| 67 | |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 68 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 69 | @Override |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 70 | public TokenContext createTokenContext (User user, Map<String, Object> attr) |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 71 | throws KustvaktException { |
| Michael Hanl | e25dea2 | 2015-09-24 19:37:56 +0200 | [diff] [blame] | 72 | TokenContext c = new TokenContext(); |
| 73 | c.setUsername(user.getUsername()); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 74 | SignedJWT jwt = signedToken.createJWT(user, attr); |
| 75 | try { |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 76 | c.setExpirationTime( |
| 77 | jwt.getJWTClaimsSet().getExpirationTime().getTime()); |
| margaretha | dda4ef7 | 2018-12-06 14:20:51 +0100 | [diff] [blame] | 78 | if (DEBUG ) { |
| 79 | jlog.debug(jwt.getJWTClaimsSet() |
| 80 | .getClaim(Attributes.AUTHENTICATION_TIME)); |
| 81 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 82 | Date authTime = jwt.getJWTClaimsSet() |
| 83 | .getDateClaim(Attributes.AUTHENTICATION_TIME); |
| 84 | ZonedDateTime time = ZonedDateTime.ofInstant(authTime.toInstant(), |
| 85 | ZoneId.of(Attributes.DEFAULT_TIME_ZONE)); |
| 86 | c.setAuthenticationTime(time); |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 87 | } |
| 88 | catch (ParseException e) { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 89 | throw new KustvaktException(StatusCodes.ILLEGAL_ARGUMENT); |
| 90 | } |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 91 | c.setTokenType(getTokenType()); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 92 | c.setToken(jwt.serialize()); |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 93 | // id_tokens.put(new Element(c.getToken(), c)); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 94 | return c; |
| 95 | } |
| 96 | |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 97 | |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 98 | @Override |
| 99 | public TokenType getTokenType () { |
| 100 | return TokenType.API; |
| 101 | } |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 102 | } |