Mercurial > hg > AnnotationManagerN4J
annotate src/main/java/de/mpiwg/itgroup/annotations/restlet/AnnotatorAnnotations.java @ 16:794077e6288c
CLOSED - # 252: Tags for Annotations
https://it-dev.mpiwg-berlin.mpg.de/tracs/mpdl-project-software/ticket/252
author | casties |
---|---|
date | Tue, 04 Sep 2012 20:02:59 +0200 |
parents | 58357a4b86de |
children | 715aa11d138b |
rev | line source |
---|---|
3 | 1 /** |
2 * Implements the "annotations" uri of the Annotator API. see | |
3 * <https://github.com/okfn/annotator/wiki/Storage> | |
4 */ | |
5 package de.mpiwg.itgroup.annotations.restlet; | |
6 | |
7 import java.io.IOException; | |
8 | |
9 import org.json.JSONException; | |
10 import org.json.JSONObject; | |
11 import org.restlet.data.Status; | |
12 import org.restlet.ext.json.JsonRepresentation; | |
13 import org.restlet.representation.Representation; | |
14 import org.restlet.resource.Delete; | |
15 import org.restlet.resource.Get; | |
16 import org.restlet.resource.Post; | |
17 import org.restlet.resource.Put; | |
18 | |
4 | 19 import de.mpiwg.itgroup.annotations.Annotation; |
15 | 20 import de.mpiwg.itgroup.annotations.Person; |
4 | 21 import de.mpiwg.itgroup.annotations.neo4j.AnnotationStore; |
3 | 22 |
23 /** | |
4 | 24 * Implements the "annotations" uri of the Annotator API. see |
25 * <https://github.com/okfn/annotator/wiki/Storage> | |
3 | 26 * |
27 * @author dwinter, casties | |
28 * | |
29 */ | |
30 public class AnnotatorAnnotations extends AnnotatorResourceImpl { | |
31 | |
32 protected String getAllowedMethodsForHeader() { | |
33 return "OPTIONS,GET,POST,PUT,DELETE"; | |
34 } | |
35 | |
36 /** | |
37 * GET with JSON content-type. | |
38 * | |
39 * @param entity | |
40 * @return | |
41 */ | |
42 @Get("json") | |
43 public Representation doGetJSON(Representation entity) { | |
44 logger.debug("AnnotatorAnnotations doGetJSON!"); | |
45 setCorsHeaders(); | |
46 // id from URI /annotations/{id} | |
47 String jsonId = (String) getRequest().getAttributes().get("id"); | |
48 String id = decodeJsonId(jsonId); | |
49 logger.debug("annotation-id=" + id); | |
50 | |
51 // TODO: what to return without id - list of all annotations? | |
52 | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
53 // do authentication |
15 | 54 Person authUser = Person.createPersonWithId(this.checkAuthToken(entity)); |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
55 logger.debug("request authenticated=" + authUser); |
3 | 56 |
16 | 57 AnnotationStore store = getAnnotationStore(); |
58 Annotation annot = store.getAnnotationById(id); | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
59 if (annot != null) { |
16 | 60 if (! annot.isActionAllowed("read", authUser, store)) { |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
61 setStatus(Status.CLIENT_ERROR_FORBIDDEN, "Not Authorized!"); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
62 return null; |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
63 } |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
64 JSONObject result = createAnnotatorJson(annot, (authUser == null)); |
4 | 65 logger.debug("sending:"); |
66 logger.debug(result); | |
67 return new JsonRepresentation(result); | |
68 } else { | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
69 // not found |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
70 setStatus(Status.CLIENT_ERROR_NOT_FOUND); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
71 return null; |
3 | 72 } |
73 } | |
74 | |
75 /** | |
76 * POST with JSON content-type. | |
77 * | |
78 * @return | |
79 */ | |
80 @Post("json") | |
81 public Representation doPostJson(Representation entity) { | |
82 logger.debug("AnnotatorAnnotations doPostJSON!"); | |
83 // set headers | |
84 setCorsHeaders(); | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
85 |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
86 // do authentication TODO: who's allowed to create? |
15 | 87 Person authUser = Person.createPersonWithId(this.checkAuthToken(entity)); |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
88 logger.debug("request authenticated=" + authUser); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
89 if (authUser == null) { |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
90 setStatus(Status.CLIENT_ERROR_FORBIDDEN, "Not Authorized!"); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
91 return null; |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
92 } |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
93 |
3 | 94 Annotation annot = null; |
95 try { | |
96 JsonRepresentation jrep = new JsonRepresentation(entity); | |
97 JSONObject jo = jrep.getJsonObject(); | |
98 if (jo == null) { | |
99 setStatus(Status.SERVER_ERROR_INTERNAL); | |
100 return null; | |
101 } | |
102 // make sure id is not set for POST | |
103 jo.remove("id"); | |
104 // get Annotation object from posted JSON | |
105 annot = createAnnotation(jo, entity); | |
106 } catch (IOException e1) { | |
107 setStatus(Status.SERVER_ERROR_INTERNAL); | |
108 return null; | |
109 } catch (JSONException e) { | |
110 setStatus(Status.CLIENT_ERROR_BAD_REQUEST); | |
111 return null; | |
112 } | |
4 | 113 if (annot == null) { |
3 | 114 setStatus(Status.CLIENT_ERROR_BAD_REQUEST); |
115 return null; | |
116 } | |
117 Annotation storedAnnot; | |
4 | 118 // store Annotation |
119 storedAnnot = getAnnotationStore().storeAnnotation(annot); | |
120 /* | |
121 * according to https://github.com/okfn/annotator/wiki/Storage we should | |
122 * return 303: see other. For now we return the annotation. | |
3 | 123 */ |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
124 JSONObject jo = createAnnotatorJson(storedAnnot, (authUser == null)); |
3 | 125 JsonRepresentation retRep = new JsonRepresentation(jo); |
126 return retRep; | |
127 } | |
128 | |
129 /** | |
130 * PUT with JSON content-type. | |
131 * | |
132 * @param entity | |
133 * @return | |
134 */ | |
135 @Put("json") | |
136 public Representation doPutJSON(Representation entity) { | |
137 logger.debug("AnnotatorAnnotations doPutJSON!"); | |
138 setCorsHeaders(); | |
139 // id from URI /annotations/{id} | |
140 String jsonId = (String) getRequest().getAttributes().get("id"); | |
141 String id = decodeJsonId(jsonId); | |
142 logger.debug("annotation-id=" + id); | |
143 | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
144 // do authentication |
15 | 145 Person authUser = Person.createPersonWithId(this.checkAuthToken(entity)); |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
146 logger.debug("request authenticated=" + authUser); |
3 | 147 |
148 Annotation annot = null; | |
4 | 149 AnnotationStore store = getAnnotationStore(); |
3 | 150 try { |
151 JsonRepresentation jrep = new JsonRepresentation(entity); | |
152 JSONObject jo = jrep.getJsonObject(); | |
153 if (jo == null) { | |
154 setStatus(Status.CLIENT_ERROR_BAD_REQUEST); | |
155 return null; | |
156 } | |
157 // get stored Annotation | |
4 | 158 Annotation storedAnnot = store.getAnnotationById(id); |
159 if (storedAnnot == null) { | |
3 | 160 setStatus(Status.CLIENT_ERROR_NOT_FOUND); |
161 return null; | |
162 } | |
16 | 163 if (! storedAnnot.isActionAllowed("update", authUser, store)) { |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
164 setStatus(Status.CLIENT_ERROR_FORBIDDEN); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
165 return null; |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
166 } |
3 | 167 // update from posted JSON |
168 annot = updateAnnotation(storedAnnot, jo, entity); | |
169 // store Annotation | |
4 | 170 storedAnnot = store.storeAnnotation(annot); |
171 /* | |
172 * according to https://github.com/okfn/annotator/wiki/Storage we | |
173 * should return 303: see other. but the client doesn't like it | |
174 * setStatus(Status.REDIRECTION_SEE_OTHER); // go to same URL as | |
175 * this one Reference thisUrl = this.getReference(); | |
176 * this.getResponse().setLocationRef(thisUrl); | |
177 */ | |
3 | 178 // return new annotation |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
179 jo = createAnnotatorJson(storedAnnot, (authUser == null)); |
3 | 180 JsonRepresentation retRep = new JsonRepresentation(jo); |
181 return retRep; | |
182 } catch (JSONException e) { | |
183 e.printStackTrace(); | |
184 setStatus(Status.CLIENT_ERROR_BAD_REQUEST); | |
185 } catch (IOException e) { | |
186 e.printStackTrace(); | |
187 setStatus(Status.SERVER_ERROR_INTERNAL, "Other Error"); | |
188 } | |
189 return null; | |
190 } | |
191 | |
192 /** | |
193 * DELETE with JSON content-type. | |
194 * | |
195 * @param entity | |
196 * @return | |
197 */ | |
198 @Delete("json") | |
199 public Representation doDeleteJSON(Representation entity) { | |
200 logger.debug("AnnotatorAnnotations doDeleteJSON!"); | |
201 setCorsHeaders(); | |
202 // id from URI /annotations/{id} | |
203 String jsonId = (String) getRequest().getAttributes().get("id"); | |
204 String id = decodeJsonId(jsonId); | |
205 logger.debug("annotation-id=" + id); | |
206 | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
207 // do authentication |
15 | 208 Person authUser = Person.createPersonWithId(this.checkAuthToken(entity)); |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
209 logger.debug("request authenticated=" + authUser); |
16 | 210 AnnotationStore store = getAnnotationStore(); |
211 Annotation annot = store.getAnnotationById(id); | |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
212 if (annot != null) { |
16 | 213 if (! annot.isActionAllowed("delete", authUser, store)) { |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
214 setStatus(Status.CLIENT_ERROR_FORBIDDEN, "Not Authorized!"); |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
215 return null; |
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
216 } |
3 | 217 } |
14
629e15b345aa
permissions mostly work. need more server-side checking.
casties
parents:
4
diff
changeset
|
218 |
4 | 219 // delete annotation |
16 | 220 store.deleteById(id); |
4 | 221 setStatus(Status.SUCCESS_NO_CONTENT); |
3 | 222 return null; |
223 } | |
224 | |
225 } |