| margaretha | 139d0f7 | 2017-11-14 18:56:22 +0100 | [diff] [blame] | 1 | package de.ids_mannheim.korap.authentication; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 2 | |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 3 | import java.text.ParseException; |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 4 | import java.time.ZoneId; |
| 5 | import java.time.ZonedDateTime; |
| 6 | import java.util.Date; |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 7 | import java.util.Map; |
| 8 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 9 | import org.apache.logging.log4j.LogManager; |
| 10 | import org.apache.logging.log4j.Logger; |
| 11 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 12 | import com.nimbusds.jose.JOSEException; |
| 13 | import com.nimbusds.jwt.SignedJWT; |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 14 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 15 | import de.ids_mannheim.korap.config.Attributes; |
| margaretha | 5225ed0 | 2018-06-25 18:38:40 +0200 | [diff] [blame] | 16 | import de.ids_mannheim.korap.config.FullConfiguration; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 17 | import de.ids_mannheim.korap.config.JWTSigner; |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 18 | import de.ids_mannheim.korap.constant.TokenType; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 19 | import de.ids_mannheim.korap.exceptions.KustvaktException; |
| 20 | import de.ids_mannheim.korap.exceptions.StatusCodes; |
| margaretha | 0e8f4e7 | 2018-04-05 14:11:52 +0200 | [diff] [blame] | 21 | import de.ids_mannheim.korap.security.context.TokenContext; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 22 | import de.ids_mannheim.korap.user.User; |
| Michael Hanl | f1e85e7 | 2016-01-21 16:55:45 +0100 | [diff] [blame] | 23 | import net.sf.ehcache.Cache; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 24 | import net.sf.ehcache.CacheManager; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 25 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 26 | /** |
| margaretha | 398f472 | 2019-01-09 19:07:20 +0100 | [diff] [blame] | 27 | * Authentication provider using JWT tokens |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 28 | * |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 29 | * Created by hanl on 5/23/14. |
| 30 | */ |
| margaretha | bc3d3f7 | 2023-02-15 15:34:12 +0100 | [diff] [blame] | 31 | @Deprecated |
| margaretha | dfecb4b | 2017-12-12 19:32:30 +0100 | [diff] [blame] | 32 | public class APIAuthentication implements AuthenticationIface { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 33 | |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 34 | private static Logger jlog = LogManager.getLogger(APIAuthentication.class); |
| margaretha | dda4ef7 | 2018-12-06 14:20:51 +0100 | [diff] [blame] | 35 | public static boolean DEBUG = false; |
| 36 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 37 | private JWTSigner signedToken; |
| 38 | |
| margaretha | 5225ed0 | 2018-06-25 18:38:40 +0200 | [diff] [blame] | 39 | public APIAuthentication (FullConfiguration config) throws JOSEException { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 40 | this.signedToken = new JWTSigner(config.getSharedSecret(), |
| 41 | config.getIssuer(), config.getTokenTTL()); |
| 42 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 43 | |
| 44 | /** |
| 45 | * EM: for testing |
| 46 | * |
| margaretha | dfecb4b | 2017-12-12 19:32:30 +0100 | [diff] [blame] | 47 | * @param signedToken |
| 48 | */ |
| 49 | public APIAuthentication (JWTSigner signedToken) { |
| 50 | this.signedToken = signedToken; |
| 51 | } |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 52 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 53 | @Override |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 54 | public TokenContext getTokenContext (String authToken) |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 55 | throws KustvaktException { |
| Michael Hanl | f1e85e7 | 2016-01-21 16:55:45 +0100 | [diff] [blame] | 56 | TokenContext context; |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 57 | // Element ein = invalided.get(authToken); |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 58 | try { |
| 59 | context = signedToken.getTokenContext(authToken); |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 60 | context.setTokenType(getTokenType()); |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 61 | } |
| 62 | catch (JOSEException | ParseException ex) { |
| 63 | throw new KustvaktException(StatusCodes.ILLEGAL_ARGUMENT); |
| 64 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 65 | // context = (TokenContext) e.getObjectValue(); |
| 66 | // throw new KustvaktException(StatusCodes.EXPIRED); |
| Michael Hanl | f1e85e7 | 2016-01-21 16:55:45 +0100 | [diff] [blame] | 67 | return context; |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 68 | } |
| 69 | |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 70 | |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 71 | @Override |
| margaretha | 4de4119 | 2017-11-15 11:47:11 +0100 | [diff] [blame] | 72 | public TokenContext createTokenContext (User user, Map<String, Object> attr) |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 73 | throws KustvaktException { |
| Michael Hanl | e25dea2 | 2015-09-24 19:37:56 +0200 | [diff] [blame] | 74 | TokenContext c = new TokenContext(); |
| 75 | c.setUsername(user.getUsername()); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 76 | SignedJWT jwt = signedToken.createJWT(user, attr); |
| 77 | try { |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 78 | c.setExpirationTime( |
| 79 | jwt.getJWTClaimsSet().getExpirationTime().getTime()); |
| margaretha | dda4ef7 | 2018-12-06 14:20:51 +0100 | [diff] [blame] | 80 | if (DEBUG ) { |
| 81 | jlog.debug(jwt.getJWTClaimsSet() |
| 82 | .getClaim(Attributes.AUTHENTICATION_TIME)); |
| 83 | } |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 84 | Date authTime = jwt.getJWTClaimsSet() |
| 85 | .getDateClaim(Attributes.AUTHENTICATION_TIME); |
| 86 | ZonedDateTime time = ZonedDateTime.ofInstant(authTime.toInstant(), |
| 87 | ZoneId.of(Attributes.DEFAULT_TIME_ZONE)); |
| 88 | c.setAuthenticationTime(time); |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 89 | } |
| 90 | catch (ParseException e) { |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 91 | throw new KustvaktException(StatusCodes.ILLEGAL_ARGUMENT); |
| 92 | } |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 93 | c.setTokenType(getTokenType()); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 94 | c.setToken(jwt.serialize()); |
| margaretha | 07a356a | 2018-07-11 19:12:21 +0200 | [diff] [blame] | 95 | // id_tokens.put(new Element(c.getToken(), c)); |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 96 | return c; |
| 97 | } |
| 98 | |
| Michael Hanl | 8abaf9e | 2016-05-23 16:46:35 +0200 | [diff] [blame] | 99 | |
| margaretha | 2afb97d | 2017-12-07 19:18:44 +0100 | [diff] [blame] | 100 | @Override |
| 101 | public TokenType getTokenType () { |
| 102 | return TokenType.API; |
| 103 | } |
| Michael Hanl | 87106d1 | 2015-09-14 18:13:51 +0200 | [diff] [blame] | 104 | } |