annotate src/main/java/de/mpiwg/itgroup/annotations/restlet/AnnotatorResourceImpl.java @ 14:629e15b345aa

permissions mostly work. need more server-side checking.
author casties
date Fri, 13 Jul 2012 20:41:02 +0200
parents 90911b2da322
children 58357a4b86de
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
1 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
2 * Base class for Annotator resource classes.
47b53ae385d1 merging old code
casties
parents:
diff changeset
3 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
4 package de.mpiwg.itgroup.annotations.restlet;
47b53ae385d1 merging old code
casties
parents:
diff changeset
5
47b53ae385d1 merging old code
casties
parents:
diff changeset
6 import java.io.UnsupportedEncodingException;
47b53ae385d1 merging old code
casties
parents:
diff changeset
7 import java.security.InvalidKeyException;
47b53ae385d1 merging old code
casties
parents:
diff changeset
8 import java.security.SignatureException;
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
9 import java.text.SimpleDateFormat;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
10 import java.util.ArrayList;
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
11 import java.util.Calendar;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
12 import java.util.List;
47b53ae385d1 merging old code
casties
parents:
diff changeset
13 import java.util.regex.Matcher;
47b53ae385d1 merging old code
casties
parents:
diff changeset
14 import java.util.regex.Pattern;
47b53ae385d1 merging old code
casties
parents:
diff changeset
15
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
16 import javax.servlet.ServletContext;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
17
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
18 import net.oauth.jsontoken.Checker;
47b53ae385d1 merging old code
casties
parents:
diff changeset
19 import net.oauth.jsontoken.JsonToken;
47b53ae385d1 merging old code
casties
parents:
diff changeset
20 import net.oauth.jsontoken.JsonTokenParser;
47b53ae385d1 merging old code
casties
parents:
diff changeset
21 import net.oauth.jsontoken.SystemClock;
47b53ae385d1 merging old code
casties
parents:
diff changeset
22 import net.oauth.jsontoken.crypto.HmacSHA256Verifier;
47b53ae385d1 merging old code
casties
parents:
diff changeset
23 import net.oauth.jsontoken.crypto.Verifier;
47b53ae385d1 merging old code
casties
parents:
diff changeset
24
47b53ae385d1 merging old code
casties
parents:
diff changeset
25 import org.apache.commons.codec.binary.Base64;
47b53ae385d1 merging old code
casties
parents:
diff changeset
26 import org.apache.log4j.Logger;
47b53ae385d1 merging old code
casties
parents:
diff changeset
27 import org.json.JSONArray;
47b53ae385d1 merging old code
casties
parents:
diff changeset
28 import org.json.JSONException;
47b53ae385d1 merging old code
casties
parents:
diff changeset
29 import org.json.JSONObject;
47b53ae385d1 merging old code
casties
parents:
diff changeset
30 import org.restlet.data.Form;
47b53ae385d1 merging old code
casties
parents:
diff changeset
31 import org.restlet.data.Status;
47b53ae385d1 merging old code
casties
parents:
diff changeset
32 import org.restlet.representation.Representation;
47b53ae385d1 merging old code
casties
parents:
diff changeset
33 import org.restlet.resource.Options;
47b53ae385d1 merging old code
casties
parents:
diff changeset
34 import org.restlet.resource.ServerResource;
47b53ae385d1 merging old code
casties
parents:
diff changeset
35
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
36 import de.mpiwg.itgroup.annotations.Actor;
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
37 import de.mpiwg.itgroup.annotations.Annotation;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
38 import de.mpiwg.itgroup.annotations.Annotation.FragmentTypes;
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
39 import de.mpiwg.itgroup.annotations.Group;
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
40 import de.mpiwg.itgroup.annotations.Person;
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
41 import de.mpiwg.itgroup.annotations.neo4j.AnnotationStore;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
42 import de.mpiwg.itgroup.annotations.old.NS;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
43
47b53ae385d1 merging old code
casties
parents:
diff changeset
44 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
45 * Base class for Annotator resource classes.
47b53ae385d1 merging old code
casties
parents:
diff changeset
46 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
47 * @author dwinter, casties
47b53ae385d1 merging old code
casties
parents:
diff changeset
48 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
49 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
50 public abstract class AnnotatorResourceImpl extends ServerResource {
47b53ae385d1 merging old code
casties
parents:
diff changeset
51
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
52 protected static Logger logger = Logger.getLogger(AnnotatorResourceImpl.class);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
53
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
54 private AnnotationStore store;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
55
47b53ae385d1 merging old code
casties
parents:
diff changeset
56 protected String getAllowedMethodsForHeader() {
47b53ae385d1 merging old code
casties
parents:
diff changeset
57 return "OPTIONS,GET,POST";
47b53ae385d1 merging old code
casties
parents:
diff changeset
58 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
59
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
60 protected AnnotationStore getAnnotationStore() {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
61 if (store == null) {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
62 ServletContext sc = (ServletContext) getContext().getServerDispatcher().getContext().getAttributes()
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
63 .get("org.restlet.ext.servlet.ServletContext");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
64 logger.debug("Getting AnnotationStore from Context");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
65 store = (AnnotationStore) sc.getAttribute(RestServer.ANNSTORE_KEY);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
66 }
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
67 return store;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
68 }
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
69
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
70 public String encodeJsonId(String id) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
71 try {
47b53ae385d1 merging old code
casties
parents:
diff changeset
72 return Base64.encodeBase64URLSafeString(id.getBytes("UTF-8"));
47b53ae385d1 merging old code
casties
parents:
diff changeset
73 } catch (UnsupportedEncodingException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
74 return null;
47b53ae385d1 merging old code
casties
parents:
diff changeset
75 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
76 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
77
47b53ae385d1 merging old code
casties
parents:
diff changeset
78 public String decodeJsonId(String id) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
79 try {
47b53ae385d1 merging old code
casties
parents:
diff changeset
80 return new String(Base64.decodeBase64(id), "UTF-8");
47b53ae385d1 merging old code
casties
parents:
diff changeset
81 } catch (UnsupportedEncodingException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
82 return null;
47b53ae385d1 merging old code
casties
parents:
diff changeset
83 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
84 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
85
47b53ae385d1 merging old code
casties
parents:
diff changeset
86 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
87 * Handle options request to allow CORS for AJAX.
47b53ae385d1 merging old code
casties
parents:
diff changeset
88 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
89 * @param entity
47b53ae385d1 merging old code
casties
parents:
diff changeset
90 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
91 @Options
47b53ae385d1 merging old code
casties
parents:
diff changeset
92 public void doOptions(Representation entity) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
93 logger.debug("AnnotatorResourceImpl doOptions!");
47b53ae385d1 merging old code
casties
parents:
diff changeset
94 setCorsHeaders();
47b53ae385d1 merging old code
casties
parents:
diff changeset
95 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
96
47b53ae385d1 merging old code
casties
parents:
diff changeset
97 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
98 * set headers to allow CORS for AJAX.
47b53ae385d1 merging old code
casties
parents:
diff changeset
99 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
100 protected void setCorsHeaders() {
47b53ae385d1 merging old code
casties
parents:
diff changeset
101 Form responseHeaders = (Form) getResponse().getAttributes().get("org.restlet.http.headers");
47b53ae385d1 merging old code
casties
parents:
diff changeset
102 if (responseHeaders == null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
103 responseHeaders = new Form();
47b53ae385d1 merging old code
casties
parents:
diff changeset
104 getResponse().getAttributes().put("org.restlet.http.headers", responseHeaders);
47b53ae385d1 merging old code
casties
parents:
diff changeset
105 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
106 responseHeaders.add("Access-Control-Allow-Methods", getAllowedMethodsForHeader());
47b53ae385d1 merging old code
casties
parents:
diff changeset
107 // echo back Origin and Request-Headers
47b53ae385d1 merging old code
casties
parents:
diff changeset
108 Form requestHeaders = (Form) getRequest().getAttributes().get("org.restlet.http.headers");
47b53ae385d1 merging old code
casties
parents:
diff changeset
109 String origin = requestHeaders.getFirstValue("Origin", true);
47b53ae385d1 merging old code
casties
parents:
diff changeset
110 if (origin == null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
111 responseHeaders.add("Access-Control-Allow-Origin", "*");
47b53ae385d1 merging old code
casties
parents:
diff changeset
112 } else {
47b53ae385d1 merging old code
casties
parents:
diff changeset
113 responseHeaders.add("Access-Control-Allow-Origin", origin);
47b53ae385d1 merging old code
casties
parents:
diff changeset
114 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
115 String allowHeaders = requestHeaders.getFirstValue("Access-Control-Request-Headers", true);
47b53ae385d1 merging old code
casties
parents:
diff changeset
116 if (allowHeaders != null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
117 responseHeaders.add("Access-Control-Allow-Headers", allowHeaders);
47b53ae385d1 merging old code
casties
parents:
diff changeset
118 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
119 responseHeaders.add("Access-Control-Allow-Credentials", "true");
47b53ae385d1 merging old code
casties
parents:
diff changeset
120 responseHeaders.add("Access-Control-Max-Age", "60");
47b53ae385d1 merging old code
casties
parents:
diff changeset
121 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
122
47b53ae385d1 merging old code
casties
parents:
diff changeset
123 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
124 * returns if authentication information from headers is valid.
47b53ae385d1 merging old code
casties
parents:
diff changeset
125 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
126 * @param entity
47b53ae385d1 merging old code
casties
parents:
diff changeset
127 * @return
47b53ae385d1 merging old code
casties
parents:
diff changeset
128 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
129 public boolean isAuthenticated(Representation entity) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
130 return (checkAuthToken(entity) != null);
47b53ae385d1 merging old code
casties
parents:
diff changeset
131 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
132
47b53ae385d1 merging old code
casties
parents:
diff changeset
133 /**
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
134 * checks Annotator Auth plugin authentication information from headers.
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
135 * returns userId if successful.
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
136 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
137 * @param entity
47b53ae385d1 merging old code
casties
parents:
diff changeset
138 * @return
47b53ae385d1 merging old code
casties
parents:
diff changeset
139 */
47b53ae385d1 merging old code
casties
parents:
diff changeset
140 public String checkAuthToken(Representation entity) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
141 Form requestHeaders = (Form) getRequest().getAttributes().get("org.restlet.http.headers");
47b53ae385d1 merging old code
casties
parents:
diff changeset
142 String authToken = requestHeaders.getFirstValue("x-annotator-auth-token", true);
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
143 if (authToken == null) return null;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
144 // decode token first to get consumer key
47b53ae385d1 merging old code
casties
parents:
diff changeset
145 JsonToken token = new JsonTokenParser(null, null).deserialize(authToken);
47b53ae385d1 merging old code
casties
parents:
diff changeset
146 String userId = token.getParamAsPrimitive("userId").getAsString();
47b53ae385d1 merging old code
casties
parents:
diff changeset
147 String consumerKey = token.getParamAsPrimitive("consumerKey").getAsString();
47b53ae385d1 merging old code
casties
parents:
diff changeset
148 // get stored consumer secret for key
47b53ae385d1 merging old code
casties
parents:
diff changeset
149 RestServer restServer = (RestServer) getApplication();
47b53ae385d1 merging old code
casties
parents:
diff changeset
150 String consumerSecret = restServer.getConsumerSecret(consumerKey);
47b53ae385d1 merging old code
casties
parents:
diff changeset
151 logger.debug("requested consumer key=" + consumerKey + " secret=" + consumerSecret);
47b53ae385d1 merging old code
casties
parents:
diff changeset
152 if (consumerSecret == null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
153 return null;
47b53ae385d1 merging old code
casties
parents:
diff changeset
154 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
155 // logger.debug(String.format("token=%s tokenString=%s signatureAlgorithm=%s",token,token.getTokenString(),token.getSignatureAlgorithm()));
47b53ae385d1 merging old code
casties
parents:
diff changeset
156 try {
47b53ae385d1 merging old code
casties
parents:
diff changeset
157 List<Verifier> verifiers = new ArrayList<Verifier>();
47b53ae385d1 merging old code
casties
parents:
diff changeset
158 // we only do HS256 yet
47b53ae385d1 merging old code
casties
parents:
diff changeset
159 verifiers.add(new HmacSHA256Verifier(consumerSecret.getBytes("UTF-8")));
47b53ae385d1 merging old code
casties
parents:
diff changeset
160 // verify token signature(should really be static...)
47b53ae385d1 merging old code
casties
parents:
diff changeset
161 new JsonTokenParser(new SystemClock(), null, (Checker[]) null).verify(token, verifiers);
47b53ae385d1 merging old code
casties
parents:
diff changeset
162 } catch (SignatureException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
163 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
164 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
165 } catch (InvalidKeyException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
166 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
167 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
168 } catch (UnsupportedEncodingException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
169 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
170 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
171 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
172 // must be ok then
47b53ae385d1 merging old code
casties
parents:
diff changeset
173 logger.debug("auth OK! user=" + userId);
47b53ae385d1 merging old code
casties
parents:
diff changeset
174 return userId;
47b53ae385d1 merging old code
casties
parents:
diff changeset
175 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
176
47b53ae385d1 merging old code
casties
parents:
diff changeset
177 /**
47b53ae385d1 merging old code
casties
parents:
diff changeset
178 * creates Annotator-JSON from an Annotation object.
47b53ae385d1 merging old code
casties
parents:
diff changeset
179 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
180 * @param annot
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
181 * @param forAnonymous TODO
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
182 * @return
47b53ae385d1 merging old code
casties
parents:
diff changeset
183 */
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
184 public JSONObject createAnnotatorJson(Annotation annot, boolean forAnonymous) {
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
185 // return user as a JSON object (otherwise just as string)
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
186 boolean makeUserObject = true;
47b53ae385d1 merging old code
casties
parents:
diff changeset
187 JSONObject jo = new JSONObject();
47b53ae385d1 merging old code
casties
parents:
diff changeset
188 try {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
189 jo.put("text", annot.getBodyText());
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
190 jo.put("uri", annot.getTargetBaseUri());
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
191
47b53ae385d1 merging old code
casties
parents:
diff changeset
192 if (makeUserObject) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
193 // create user object
47b53ae385d1 merging old code
casties
parents:
diff changeset
194 JSONObject userObject = new JSONObject();
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
195 Actor creator = annot.getCreator();
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
196 // save creator as uri
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
197 userObject.put("uri", creator.getUri());
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
198 // make short user id
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
199 String userId = creator.getIdString();
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
200 // set as id
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
201 userObject.put("id", userId);
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
202 // get full name
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
203 String userName = creator.getName();
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
204 if (userName == null) {
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
205 RestServer restServer = (RestServer) getApplication();
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
206 userName = restServer.getFullNameFromLdap(userId);
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
207 }
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
208 userObject.put("name", userName);
47b53ae385d1 merging old code
casties
parents:
diff changeset
209 // save user object
47b53ae385d1 merging old code
casties
parents:
diff changeset
210 jo.put("user", userObject);
47b53ae385d1 merging old code
casties
parents:
diff changeset
211 } else {
47b53ae385d1 merging old code
casties
parents:
diff changeset
212 // save user as string
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
213 jo.put("user", annot.getCreatorUri());
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
214 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
215
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
216 if (annot.getTargetFragment() != null) {
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
217 // we only look at the first xpointer
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
218 List<String> fragments = new ArrayList<String>();
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
219 fragments.add(annot.getTargetFragment());
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
220 FragmentTypes xt = annot.getFragmentType();
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
221 if (xt == FragmentTypes.XPOINTER) {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
222 jo.put("ranges", transformToRanges(fragments));
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
223 } else if (xt == FragmentTypes.AREA) {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
224 jo.put("areas", transformToAreas(fragments));
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
225 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
226 }
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
227
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
228 // permissions
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
229 JSONObject perms = new JSONObject();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
230 jo.put("permissions", perms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
231 // admin
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
232 JSONArray adminPerms = new JSONArray();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
233 perms.put("admin", adminPerms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
234 Actor adminPerm = annot.getAdminPermission();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
235 if (adminPerm != null) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
236 adminPerms.put(adminPerm.getIdString());
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
237 } else if (forAnonymous) {
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
238 // set something because its not allowed for anonymous
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
239 adminPerms.put("not-you");
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
240 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
241 // delete
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
242 JSONArray deletePerms = new JSONArray();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
243 perms.put("delete", deletePerms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
244 Actor deletePerm = annot.getDeletePermission();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
245 if (deletePerm != null) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
246 deletePerms.put(deletePerm.getIdString());
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
247 } else if (forAnonymous) {
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
248 // set something because its not allowed for anonymous
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
249 deletePerms.put("not-you");
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
250 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
251 // update
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
252 JSONArray updatePerms = new JSONArray();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
253 perms.put("update", updatePerms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
254 Actor updatePerm = annot.getUpdatePermission();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
255 if (updatePerm != null) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
256 updatePerms.put(updatePerm.getIdString());
14
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
257 } else if (forAnonymous) {
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
258 // set something because its not allowed for anonymous
629e15b345aa permissions mostly work. need more server-side checking.
casties
parents: 10
diff changeset
259 updatePerms.put("not-you");
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
260 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
261 // read
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
262 JSONArray readPerms = new JSONArray();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
263 perms.put("read", readPerms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
264 Actor readPerm = annot.getReadPermission();
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
265 if (readPerm != null) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
266 readPerms.put(readPerm.getIdString());
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
267 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
268
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
269 // encode Annotation URL (=id) in base64
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
270 String annotUrl = annot.getUri();
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
271 String annotId = encodeJsonId(annotUrl);
47b53ae385d1 merging old code
casties
parents:
diff changeset
272 jo.put("id", annotId);
47b53ae385d1 merging old code
casties
parents:
diff changeset
273 return jo;
47b53ae385d1 merging old code
casties
parents:
diff changeset
274 } catch (JSONException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
275 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
276 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
277 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
278 return null;
47b53ae385d1 merging old code
casties
parents:
diff changeset
279 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
280
47b53ae385d1 merging old code
casties
parents:
diff changeset
281 private JSONArray transformToRanges(List<String> xpointers) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
282
47b53ae385d1 merging old code
casties
parents:
diff changeset
283 JSONArray ja = new JSONArray();
47b53ae385d1 merging old code
casties
parents:
diff changeset
284
47b53ae385d1 merging old code
casties
parents:
diff changeset
285 Pattern rg = Pattern
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
286 .compile("xpointer\\(start-point\\(string-range\\(\"([^\"]*)\",([^,]*),1\\)\\)/range-to\\(end-point\\(string-range\\(\"([^\"]*)\",([^,]*),1\\)\\)\\)\\)");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
287 Pattern rg1 = Pattern.compile("xpointer\\(start-point\\(string-range\\(\"([^\"]*)\",([^,]*),1\\)\\)\\)");
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
288
47b53ae385d1 merging old code
casties
parents:
diff changeset
289 try {
47b53ae385d1 merging old code
casties
parents:
diff changeset
290 for (String xpointer : xpointers) {
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
291 // String decoded = URLDecoder.decode(xpointer, "utf-8");
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
292 String decoded = xpointer;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
293 Matcher m = rg.matcher(decoded);
47b53ae385d1 merging old code
casties
parents:
diff changeset
294
47b53ae385d1 merging old code
casties
parents:
diff changeset
295 if (m.find()) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
296 {
47b53ae385d1 merging old code
casties
parents:
diff changeset
297 JSONObject jo = new JSONObject();
47b53ae385d1 merging old code
casties
parents:
diff changeset
298 jo.put("start", m.group(1));
47b53ae385d1 merging old code
casties
parents:
diff changeset
299 jo.put("startOffset", m.group(2));
47b53ae385d1 merging old code
casties
parents:
diff changeset
300 jo.put("end", m.group(3));
47b53ae385d1 merging old code
casties
parents:
diff changeset
301 jo.put("endOffset", m.group(4));
47b53ae385d1 merging old code
casties
parents:
diff changeset
302 ja.put(jo);
47b53ae385d1 merging old code
casties
parents:
diff changeset
303 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
304 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
305 m = rg1.matcher(xpointer);
47b53ae385d1 merging old code
casties
parents:
diff changeset
306 if (m.find()) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
307 JSONObject jo = new JSONObject();
47b53ae385d1 merging old code
casties
parents:
diff changeset
308 jo.put("start", m.group(1));
47b53ae385d1 merging old code
casties
parents:
diff changeset
309 jo.put("startOffset", m.group(2));
47b53ae385d1 merging old code
casties
parents:
diff changeset
310
47b53ae385d1 merging old code
casties
parents:
diff changeset
311 ja.put(jo);
47b53ae385d1 merging old code
casties
parents:
diff changeset
312 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
313 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
314 } catch (JSONException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
315 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
316 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
317 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
318 return ja;
47b53ae385d1 merging old code
casties
parents:
diff changeset
319 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
320
47b53ae385d1 merging old code
casties
parents:
diff changeset
321 private JSONArray transformToAreas(List<String> xpointers) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
322
47b53ae385d1 merging old code
casties
parents:
diff changeset
323 JSONArray ja = new JSONArray();
47b53ae385d1 merging old code
casties
parents:
diff changeset
324
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
325 Pattern rg = Pattern.compile("xywh=(\\w*:)([\\d\\.]+),([\\d\\.]+),([\\d\\.]+),([\\d\\.]+)");
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
326
47b53ae385d1 merging old code
casties
parents:
diff changeset
327 try {
47b53ae385d1 merging old code
casties
parents:
diff changeset
328 for (String xpointer : xpointers) {
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
329 // String decoded = URLDecoder.decode(xpointer, "utf-8");
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
330 String decoded = xpointer;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
331 Matcher m = rg.matcher(decoded);
47b53ae385d1 merging old code
casties
parents:
diff changeset
332
47b53ae385d1 merging old code
casties
parents:
diff changeset
333 if (m.find()) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
334 {
47b53ae385d1 merging old code
casties
parents:
diff changeset
335 JSONObject jo = new JSONObject();
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
336 @SuppressWarnings("unused")
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
337 String unit = m.group(1);
47b53ae385d1 merging old code
casties
parents:
diff changeset
338 jo.put("x", m.group(2));
47b53ae385d1 merging old code
casties
parents:
diff changeset
339 jo.put("y", m.group(3));
47b53ae385d1 merging old code
casties
parents:
diff changeset
340 jo.put("width", m.group(4));
47b53ae385d1 merging old code
casties
parents:
diff changeset
341 jo.put("height", m.group(5));
47b53ae385d1 merging old code
casties
parents:
diff changeset
342 ja.put(jo);
47b53ae385d1 merging old code
casties
parents:
diff changeset
343 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
344 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
345 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
346 } catch (JSONException e) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
347 // TODO Auto-generated catch block
47b53ae385d1 merging old code
casties
parents:
diff changeset
348 e.printStackTrace();
47b53ae385d1 merging old code
casties
parents:
diff changeset
349 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
350 return ja;
47b53ae385d1 merging old code
casties
parents:
diff changeset
351 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
352
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
353 protected String parseArea(JSONObject area) throws JSONException {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
354 String x = area.getString("x");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
355 String y = area.getString("y");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
356 String width = "0";
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
357 String height = "0";
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
358 if (area.has("width")) {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
359 width = area.getString("width");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
360 height = area.getString("height");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
361 }
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
362 String fragment = String.format("xywh=fraction:%s,%s,%s,%s", x, y, width, height);
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
363 return fragment;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
364 }
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
365
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
366 protected String parseRange(JSONObject range) throws JSONException {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
367 String start = range.getString("start");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
368 String end = range.getString("end");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
369 String startOffset = range.getString("startOffset");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
370 String endOffset = range.getString("endOffset");
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
371
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
372 String fragment = String.format(
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
373 "xpointer(start-point(string-range(\"%s\",%s,1))/range-to(end-point(string-range(\"%s\",%s,1))))", start,
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
374 startOffset, end, endOffset);
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
375 return fragment;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
376 }
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
377
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
378 /**
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
379 * Creates an Annotation object with data from JSON.
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
380 *
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
381 * uses the specification from the annotator project: {@link https
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
382 * ://github.com/okfn/annotator/wiki/Annotation-format}
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
383 *
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
384 * The username will be transformed to an URI if not given already as URI,
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
385 * if not it will set to the MPIWG namespace defined in
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
386 * de.mpiwg.itgroup.annotationManager.Constants.NS
47b53ae385d1 merging old code
casties
parents:
diff changeset
387 *
47b53ae385d1 merging old code
casties
parents:
diff changeset
388 * @param jo
47b53ae385d1 merging old code
casties
parents:
diff changeset
389 * @return
47b53ae385d1 merging old code
casties
parents:
diff changeset
390 * @throws JSONException
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
391 * @throws UnsupportedEncodingException
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
392 */
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
393 public Annotation createAnnotation(JSONObject jo, Representation entity) throws JSONException, UnsupportedEncodingException {
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
394 return updateAnnotation(new Annotation(), jo, entity);
47b53ae385d1 merging old code
casties
parents:
diff changeset
395 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
396
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
397 /**
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
398 * Updates an Annotation object with data from JSON.
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
399 *
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
400 * uses the specification from the annotator project: {@link https
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
401 * ://github.com/okfn/annotator/wiki/Annotation-format}
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
402 *
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
403 * The username will be transformed to an URI if not given already as URI,
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
404 * if not it will set to the MPIWG namespace defined in
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
405 * de.mpiwg.itgroup.annotationManager.Constants.NS
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
406 *
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
407 * @param annot
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
408 * @param jo
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
409 * @return
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
410 * @throws JSONException
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
411 * @throws UnsupportedEncodingException
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
412 */
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
413 public Annotation updateAnnotation(Annotation annot, JSONObject jo, Representation entity) throws JSONException,
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
414 UnsupportedEncodingException {
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
415 // target uri
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
416 if (jo.has("uri")) {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
417 annot.setTargetBaseUri(jo.getString("uri"));
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
418 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
419 // annotation text
47b53ae385d1 merging old code
casties
parents:
diff changeset
420 if (jo.has("text")) {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
421 annot.setBodyText(jo.getString("text"));
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
422 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
423 // check authentication
47b53ae385d1 merging old code
casties
parents:
diff changeset
424 String authUser = checkAuthToken(entity);
47b53ae385d1 merging old code
casties
parents:
diff changeset
425 if (authUser == null) {
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
426 /*
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
427 * // try http auth User httpUser = getHttpAuthUser(entity); if
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
428 * (httpUser == null) {
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
429 */
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
430 setStatus(Status.CLIENT_ERROR_FORBIDDEN);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
431 return null;
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
432 /*
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
433 * } authUser = httpUser.getIdentifier();
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
434 */
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
435 }
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
436 // get or create creator object
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
437 Actor creator = annot.getCreator();
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
438 if (creator == null) {
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
439 creator = new Person();
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
440 annot.setCreator(creator);
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
441 }
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
442 // username not required, if no username given authuser will be used
47b53ae385d1 merging old code
casties
parents:
diff changeset
443 String username = null;
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
444 String userUri = creator.getUri();
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
445 if (jo.has("user")) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
446 if (jo.get("user") instanceof String) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
447 // user is just a String
47b53ae385d1 merging old code
casties
parents:
diff changeset
448 username = jo.getString("user");
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
449 creator.setId(username);
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
450 // TODO: what if username and authUser are different?
47b53ae385d1 merging old code
casties
parents:
diff changeset
451 } else {
47b53ae385d1 merging old code
casties
parents:
diff changeset
452 // user is an object
47b53ae385d1 merging old code
casties
parents:
diff changeset
453 JSONObject user = jo.getJSONObject("user");
47b53ae385d1 merging old code
casties
parents:
diff changeset
454 if (user.has("id")) {
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
455 String id = user.getString("id");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
456 creator.setId(id);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
457 username = id;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
458 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
459 if (user.has("uri")) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
460 userUri = user.getString("uri");
47b53ae385d1 merging old code
casties
parents:
diff changeset
461 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
462 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
463 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
464 if (username == null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
465 username = authUser;
47b53ae385d1 merging old code
casties
parents:
diff changeset
466 }
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
467 // try to get full name
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
468 if (creator.getName() == null && username != null) {
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
469 RestServer restServer = (RestServer) getApplication();
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
470 String fullName = restServer.getFullNameFromLdap(username);
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
471 creator.setName(fullName);
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
472 }
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
473 // userUri should be a URI, if not it will set to the MPIWG namespace
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
474 if (userUri == null) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
475 if (username.startsWith("http")) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
476 userUri = username;
47b53ae385d1 merging old code
casties
parents:
diff changeset
477 } else {
47b53ae385d1 merging old code
casties
parents:
diff changeset
478 userUri = NS.MPIWG_PERSONS_URL + username;
47b53ae385d1 merging old code
casties
parents:
diff changeset
479 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
480 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
481 // TODO: should we overwrite the creator?
9
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
482 if (creator.getUri() == null) {
b2bfc3bc9ba8 new internal actor class for creator.
casties
parents: 5
diff changeset
483 creator.setUri(userUri);
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
484 }
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
485
5
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
486 if (annot.getCreated() == null) {
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
487 // set creation date
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
488 SimpleDateFormat format = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ss'Z'");
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
489 String ct = format.format(Calendar.getInstance().getTime());
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
490 annot.setCreated(ct);
bbf0cc5bee29 version 0.2 really works now
casties
parents: 4
diff changeset
491 }
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
492
47b53ae385d1 merging old code
casties
parents:
diff changeset
493 // create xpointer from the first range/area
47b53ae385d1 merging old code
casties
parents:
diff changeset
494 if (jo.has("ranges")) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
495 JSONObject ranges = jo.getJSONArray("ranges").getJSONObject(0);
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
496 annot.setFragmentType(FragmentTypes.XPOINTER);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
497 String fragment = parseRange(ranges);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
498 annot.setTargetFragment(fragment);
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
499 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
500 if (jo.has("areas")) {
47b53ae385d1 merging old code
casties
parents:
diff changeset
501 JSONObject area = jo.getJSONArray("areas").getJSONObject(0);
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
502 annot.setFragmentType(FragmentTypes.AREA);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
503 String fragment = parseArea(area);
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
504 annot.setTargetFragment(fragment);
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
505 }
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
506
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
507 // permissions
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
508 if (jo.has("permissions")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
509 JSONObject permissions = jo.getJSONObject("permissions");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
510 if (permissions.has("admin")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
511 JSONArray perms = permissions.getJSONArray("admin");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
512 Actor actor = getActorFromPermissions(perms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
513 annot.setAdminPermission(actor);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
514 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
515 if (permissions.has("delete")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
516 JSONArray perms = permissions.getJSONArray("delete");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
517 Actor actor = getActorFromPermissions(perms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
518 annot.setDeletePermission(actor);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
519 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
520 if (permissions.has("update")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
521 JSONArray perms = permissions.getJSONArray("update");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
522 Actor actor = getActorFromPermissions(perms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
523 annot.setUpdatePermission(actor);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
524 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
525 if (permissions.has("read")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
526 JSONArray perms = permissions.getJSONArray("read");
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
527 Actor actor = getActorFromPermissions(perms);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
528 annot.setReadPermission(actor);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
529 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
530 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
531
4
3599b29c393f store seems to work now :-)
casties
parents: 3
diff changeset
532 return annot;
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
533 }
47b53ae385d1 merging old code
casties
parents:
diff changeset
534
10
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
535 @SuppressWarnings("unused")
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
536 protected Actor getActorFromPermissions(JSONArray perms) throws JSONException {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
537 Actor actor = null;
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
538 for (int i = 0; i < perms.length(); ++i) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
539 String perm = perms.getString(i);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
540 if (perm.toLowerCase().startsWith("group:")) {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
541 String groupId = perm.substring(6);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
542 actor = new Group(groupId);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
543 } else {
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
544 actor = new Person(perm);
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
545 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
546 // we just take the first one
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
547 break;
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
548 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
549 return actor;
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
550 }
90911b2da322 more work on permissions...
casties
parents: 9
diff changeset
551
3
47b53ae385d1 merging old code
casties
parents:
diff changeset
552 }