| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 1 | package de.ids_mannheim.korap.web.controller; |
| 2 | |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 3 | import java.util.List; |
| 4 | |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 5 | import javax.ws.rs.Consumes; |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 6 | import javax.ws.rs.DELETE; |
| 7 | import javax.ws.rs.FormParam; |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 8 | import javax.ws.rs.GET; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 9 | import javax.ws.rs.POST; |
| 10 | import javax.ws.rs.Path; |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 11 | import javax.ws.rs.PathParam; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 12 | import javax.ws.rs.Produces; |
| 13 | import javax.ws.rs.core.Context; |
| 14 | import javax.ws.rs.core.MediaType; |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 15 | import javax.ws.rs.core.Response; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 16 | import javax.ws.rs.core.SecurityContext; |
| 17 | |
| 18 | import org.springframework.beans.factory.annotation.Autowired; |
| 19 | import org.springframework.stereotype.Controller; |
| 20 | |
| 21 | import com.sun.jersey.spi.container.ResourceFilters; |
| 22 | |
| margaretha | 2df0660 | 2018-11-14 19:10:30 +0100 | [diff] [blame] | 23 | import de.ids_mannheim.korap.constant.OAuth2Scope; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 24 | import de.ids_mannheim.korap.exceptions.KustvaktException; |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 25 | import de.ids_mannheim.korap.oauth2.dto.OAuth2ClientDto; |
| 26 | import de.ids_mannheim.korap.oauth2.dto.OAuth2ClientInfoDto; |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 27 | import de.ids_mannheim.korap.oauth2.dto.OAuth2UserClientDto; |
| margaretha | a452c5e | 2018-04-25 22:48:09 +0200 | [diff] [blame] | 28 | import de.ids_mannheim.korap.oauth2.service.OAuth2ClientService; |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 29 | import de.ids_mannheim.korap.oauth2.service.OAuth2ScopeService; |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 30 | import de.ids_mannheim.korap.security.context.TokenContext; |
| margaretha | f839dde | 2018-04-16 17:52:57 +0200 | [diff] [blame] | 31 | import de.ids_mannheim.korap.web.OAuth2ResponseHandler; |
| margaretha | ee0cbfe | 2018-08-28 17:47:14 +0200 | [diff] [blame] | 32 | import de.ids_mannheim.korap.web.APIVersionFilter; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 33 | import de.ids_mannheim.korap.web.filter.AuthenticationFilter; |
| 34 | import de.ids_mannheim.korap.web.filter.BlockingFilter; |
| 35 | import de.ids_mannheim.korap.web.input.OAuth2ClientJson; |
| 36 | |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 37 | /** |
| 38 | * Defines controllers for OAuth2 clients, namely applications |
| margaretha | 7f5071f | 2018-08-14 15:58:51 +0200 | [diff] [blame] | 39 | * performing actions such as searching and retrieving match |
| 40 | * information on behalf of users. |
| margaretha | a048627 | 2018-04-12 19:59:31 +0200 | [diff] [blame] | 41 | * |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 42 | * <br /><br /> |
| 43 | * According to its privileges, clients are categorized into super and |
| 44 | * normal clients. Super clients are intended only for clients that |
| 45 | * are part of KorAP. They has special privileges to use controllers |
| 46 | * that usually are not allowed for normal clients, for instance using |
| 47 | * OAuth2 password grant to obtain access tokens. |
| 48 | * |
| 49 | * <br /><br /> |
| 50 | * By default, clients are set as normal clients. Super clients has to |
| 51 | * be set manually by an admin, e.g by using |
| 52 | * {@link #updateClientPrivilege(SecurityContext, String, boolean)} |
| 53 | * controller. Only confidential clients are allowed to be super |
| 54 | * clients. |
| 55 | * |
| margaretha | a048627 | 2018-04-12 19:59:31 +0200 | [diff] [blame] | 56 | * @author margaretha |
| 57 | * |
| 58 | */ |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 59 | @Controller |
| margaretha | ee0cbfe | 2018-08-28 17:47:14 +0200 | [diff] [blame] | 60 | @Path("{version}/oauth2/client") |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 61 | @ResourceFilters({ APIVersionFilter.class, AuthenticationFilter.class, |
| 62 | BlockingFilter.class }) |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 63 | public class OAuthClientController { |
| 64 | |
| 65 | @Autowired |
| 66 | private OAuth2ClientService clientService; |
| 67 | @Autowired |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 68 | private OAuth2ScopeService scopeService; |
| 69 | @Autowired |
| margaretha | f839dde | 2018-04-16 17:52:57 +0200 | [diff] [blame] | 70 | private OAuth2ResponseHandler responseHandler; |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 71 | |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 72 | /** |
| 73 | * Registers a client application. Before starting an OAuth |
| margaretha | e4034a8 | 2018-07-02 14:46:59 +0200 | [diff] [blame] | 74 | * process, client applications have to be registered first. Only |
| 75 | * registered users are allowed to register client applications. |
| 76 | * |
| 77 | * After registration, the client receives a client_id and a |
| 78 | * client_secret, if the client is confidential (capable of |
| 79 | * storing the client_secret), that are needed in the |
| 80 | * authorization process. |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 81 | * |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 82 | * From RFC 6749: |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 83 | * The authorization server SHOULD document the size of any |
| margaretha | e4034a8 | 2018-07-02 14:46:59 +0200 | [diff] [blame] | 84 | * identifier it issues. |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 85 | * |
| 86 | * @param context |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 87 | * @param clientJson |
| 88 | * a JSON object describing the client |
| 89 | * @return client_id and client_secret if the client type is |
| 90 | * confidential |
| margaretha | a048627 | 2018-04-12 19:59:31 +0200 | [diff] [blame] | 91 | * |
| 92 | * @see OAuth2ClientJson |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 93 | */ |
| 94 | @POST |
| 95 | @Path("register") |
| 96 | @Consumes(MediaType.APPLICATION_JSON) |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 97 | @Produces(MediaType.APPLICATION_JSON + ";charset=utf-8") |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 98 | public OAuth2ClientDto registerClient ( |
| 99 | @Context SecurityContext securityContext, |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 100 | OAuth2ClientJson clientJson) { |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 101 | TokenContext context = |
| 102 | (TokenContext) securityContext.getUserPrincipal(); |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 103 | try { |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 104 | scopeService.verifyScope(context, OAuth2Scope.REGISTER_CLIENT); |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 105 | return clientService.registerClient(clientJson, |
| 106 | context.getUsername()); |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 107 | } |
| 108 | catch (KustvaktException e) { |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 109 | throw responseHandler.throwit(e); |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 110 | } |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 111 | } |
| 112 | |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 113 | /** |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 114 | * Deregisters a client requires client owner authentication. For |
| 115 | * confidential clients, client authentication is also required. |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 116 | * |
| 117 | * |
| 118 | * @param securityContext |
| margaretha | ec247dd | 2018-06-12 21:55:46 +0200 | [diff] [blame] | 119 | * @param clientId |
| 120 | * the client id |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 121 | * @param clientSecret |
| 122 | * the client secret |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 123 | * @return HTTP Response OK if successful. |
| 124 | */ |
| 125 | @DELETE |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 126 | @Path("deregister/{client_id}") |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 127 | @Consumes(MediaType.APPLICATION_FORM_URLENCODED) |
| margaretha | fb1e099 | 2018-04-10 14:58:28 +0200 | [diff] [blame] | 128 | public Response deregisterPublicClient ( |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 129 | @Context SecurityContext securityContext, |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 130 | @PathParam("client_id") String clientId, |
| 131 | @FormParam("client_secret") String clientSecret) { |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 132 | TokenContext context = |
| 133 | (TokenContext) securityContext.getUserPrincipal(); |
| 134 | try { |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 135 | scopeService.verifyScope(context, OAuth2Scope.DEREGISTER_CLIENT); |
| margaretha | 80ea0dd | 2018-07-03 14:22:59 +0200 | [diff] [blame] | 136 | clientService.deregisterClient(clientId, clientSecret, |
| margaretha | 8d804f6 | 2018-04-10 12:39:56 +0200 | [diff] [blame] | 137 | context.getUsername()); |
| 138 | return Response.ok().build(); |
| 139 | } |
| 140 | catch (KustvaktException e) { |
| 141 | throw responseHandler.throwit(e); |
| 142 | } |
| 143 | } |
| margaretha | 7f5071f | 2018-08-14 15:58:51 +0200 | [diff] [blame] | 144 | |
| 145 | /** |
| 146 | * Resets client secret of the given client. This controller |
| 147 | * requires client owner and client authentication. Only |
| 148 | * confidential clients are issued client secrets. |
| 149 | * |
| 150 | * @param securityContext |
| 151 | * @param clientId |
| 152 | * @param clientSecret |
| 153 | * @return a new client secret |
| 154 | */ |
| 155 | @POST |
| 156 | @Path("reset") |
| 157 | @Consumes(MediaType.APPLICATION_FORM_URLENCODED) |
| 158 | @Produces(MediaType.APPLICATION_JSON + ";charset=utf-8") |
| margaretha | 7f5071f | 2018-08-14 15:58:51 +0200 | [diff] [blame] | 159 | public OAuth2ClientDto resetClientSecret ( |
| 160 | @Context SecurityContext securityContext, |
| 161 | @FormParam("client_id") String clientId, |
| 162 | @FormParam("client_secret") String clientSecret) { |
| 163 | TokenContext context = |
| 164 | (TokenContext) securityContext.getUserPrincipal(); |
| 165 | try { |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 166 | scopeService.verifyScope(context, OAuth2Scope.RESET_CLIENT_SECRET); |
| margaretha | 7f5071f | 2018-08-14 15:58:51 +0200 | [diff] [blame] | 167 | return clientService.resetSecret(clientId, clientSecret, |
| 168 | context.getUsername()); |
| 169 | } |
| 170 | catch (KustvaktException e) { |
| 171 | throw responseHandler.throwit(e); |
| 172 | } |
| 173 | } |
| 174 | |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 175 | /** |
| 176 | * Facilitates editing client privileges for admin purposes, e.g. |
| margaretha | bdddbaf | 2018-08-15 19:08:33 +0200 | [diff] [blame] | 177 | * setting a specific client to be a super client. |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 178 | * Only confidential clients are allowed to be super clients. |
| 179 | * |
| margaretha | f008512 | 2018-08-16 16:19:53 +0200 | [diff] [blame] | 180 | * When upgrading clients to super clients, existing access tokens |
| 181 | * and authorization codes retain their scopes. |
| 182 | * |
| 183 | * When degrading super clients, all existing tokens and |
| 184 | * authorization codes are invalidated. |
| 185 | * |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 186 | * @param securityContext |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 187 | * @param clientId |
| 188 | * OAuth2 client id |
| margaretha | f008512 | 2018-08-16 16:19:53 +0200 | [diff] [blame] | 189 | * @param super |
| 190 | * true indicating super client, false otherwise |
| 191 | * @return Response status OK, if successful |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 192 | */ |
| 193 | @POST |
| 194 | @Path("privilege") |
| 195 | @Consumes(MediaType.APPLICATION_FORM_URLENCODED) |
| 196 | public Response updateClientPrivilege ( |
| 197 | @Context SecurityContext securityContext, |
| 198 | @FormParam("client_id") String clientId, |
| 199 | @FormParam("super") String isSuper) { |
| 200 | TokenContext context = |
| 201 | (TokenContext) securityContext.getUserPrincipal(); |
| 202 | try { |
| 203 | scopeService.verifyScope(context, OAuth2Scope.ADMIN); |
| 204 | clientService.updatePrivilege(context.getUsername(), clientId, |
| margaretha | f008512 | 2018-08-16 16:19:53 +0200 | [diff] [blame] | 205 | Boolean.valueOf(isSuper)); |
| margaretha | 835178d | 2018-08-15 19:04:03 +0200 | [diff] [blame] | 206 | return Response.ok().build(); |
| 207 | } |
| 208 | catch (KustvaktException e) { |
| 209 | throw responseHandler.throwit(e); |
| 210 | } |
| 211 | } |
| 212 | |
| 213 | @GET |
| 214 | @Path("info/{client_id}") |
| 215 | @Produces(MediaType.APPLICATION_JSON + ";charset=utf-8") |
| 216 | public OAuth2ClientInfoDto retrieveClientInfo ( |
| 217 | @Context SecurityContext securityContext, |
| 218 | @PathParam("client_id") String clientId) { |
| 219 | TokenContext context = |
| 220 | (TokenContext) securityContext.getUserPrincipal(); |
| 221 | try { |
| 222 | scopeService.verifyScope(context, OAuth2Scope.CLIENT_INFO); |
| 223 | return clientService.retrieveClientInfo(context.getUsername(), |
| 224 | clientId); |
| 225 | } |
| 226 | catch (KustvaktException e) { |
| 227 | throw responseHandler.throwit(e); |
| 228 | } |
| 229 | } |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 230 | |
| 231 | /** |
| margaretha | 5a2c34e | 2018-11-29 19:35:13 +0100 | [diff] [blame^] | 232 | * Lists user clients having active refresh tokens (not revoked, |
| 233 | * not expired), except super clients. |
| 234 | * |
| 235 | * This service is not part of the OAuth2 specification. It is |
| 236 | * intended to facilitate users revoking any suspicious and |
| 237 | * misused access or refresh tokens. |
| margaretha | 230effb | 2018-11-29 17:28:18 +0100 | [diff] [blame] | 238 | * |
| 239 | * Only super clients are allowed to use this service. It requires |
| 240 | * user and client authentications. |
| 241 | * |
| 242 | * @param context |
| 243 | * @return a list of clients having refresh tokens of the |
| 244 | * given user |
| 245 | */ |
| 246 | @POST |
| 247 | @Path("list") |
| 248 | @ResourceFilters({ AuthenticationFilter.class, BlockingFilter.class }) |
| 249 | @Consumes(MediaType.APPLICATION_FORM_URLENCODED) |
| 250 | @Produces(MediaType.APPLICATION_JSON + ";charset=utf-8") |
| 251 | public List<OAuth2UserClientDto> listUserApp ( |
| 252 | @Context SecurityContext context, |
| 253 | @FormParam("client_id") String clientId, |
| 254 | @FormParam("client_secret") String clientSecret) { |
| 255 | |
| 256 | TokenContext tokenContext = (TokenContext) context.getUserPrincipal(); |
| 257 | String username = tokenContext.getUsername(); |
| 258 | |
| 259 | try { |
| 260 | scopeService.verifyScope(tokenContext, |
| 261 | OAuth2Scope.LIST_USER_CLIENT); |
| 262 | |
| 263 | return clientService.listUserClients(username, clientId, |
| 264 | clientSecret); |
| 265 | } |
| 266 | catch (KustvaktException e) { |
| 267 | throw responseHandler.throwit(e); |
| 268 | } |
| 269 | } |
| 270 | |
| margaretha | 31a9f52 | 2018-04-03 20:40:45 +0200 | [diff] [blame] | 271 | } |