annotate servlet/src/digilib/auth/XMLAuthOps.java @ 139:11cfe4c89fdc

Servlet version 1.11b1 with improved original-size. - fixed lots of bugs in metadata handling.
author robcast
date Thu, 31 Jul 2003 20:56:51 +0200
parents 398d39ee1014
children afe7ff98bb71
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
1 /* XMLAuthOps -- Authentication class implementation using XML files
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
2
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
3 Digital Image Library servlet components
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
4
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
5 Copyright (C) 2001, 2002 Robert Casties (robcast@mail.berlios.de)
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
6
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
7 This program is free software; you can redistribute it and/or modify it
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
8 under the terms of the GNU General Public License as published by the
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
9 Free Software Foundation; either version 2 of the License, or (at your
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
10 option) any later version.
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
11
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
12 Please read license.txt for the full details. A copy of the GPL
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
13 may be found at http://www.gnu.org/copyleft/lgpl.html
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
14
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
15 You should have received a copy of the GNU General Public License
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
16 along with this program; if not, write to the Free Software
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
17 Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
18
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
19 */
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
20
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
21 package digilib.auth;
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
22
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
23 import javax.servlet.http.HttpServletRequest;
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
24 import java.util.*;
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
25 import java.io.*;
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
26
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
27 import digilib.*;
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
28 import digilib.io.*;
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
29 import digilib.servlet.DigilibRequest;
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
30
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
31 /** Implementation of AuthOps using XML files.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
32 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
33 * The configuration file is read by an XMLListLoader into HashTree objects for
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
34 * authentication paths and IP numbers.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
35 */
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
36 public class XMLAuthOps extends AuthOpsImpl {
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
37
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
38 private String configFile =
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
39 "/docuserver/www/digitallibrary/WEB-INF/digilib-auth.xml";
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
40 private HashTree authPaths;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
41 private HashTree authIPs;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
42
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
43 /** Constructor taking an XML config file name and utils object.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
44 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
45 * @param u utils object
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
46 * @param confFile Configuration file name.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
47 * @throws AuthOpException Exception thrown on error.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
48 */
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
49 public XMLAuthOps(Utils u, String confFile) throws AuthOpException {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
50 util = u;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
51 configFile = confFile;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
52 init();
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
53 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
54
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
55 /** Set configuration file and utils object.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
56 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
57 * @param confFile XML config file name.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
58 * @throws AuthOpException Exception thrown on error.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
59 */
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
60 public void setConfig(String confFile) throws AuthOpException {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
61 configFile = confFile;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
62 init();
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
63 }
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
64
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
65 /** Initialize.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
66 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
67 * Read configuration files and setup authentication arrays.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
68 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
69 * @throws AuthOpException Exception thrown on error.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
70 */
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
71 public void init() throws AuthOpException {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
72 util.dprintln(10, "xmlauthops.init (" + configFile + ")");
88
398d39ee1014 New version 1.8b4.
robcast
parents: 73
diff changeset
73 HashMap pathList = null;
398d39ee1014 New version 1.8b4.
robcast
parents: 73
diff changeset
74 HashMap ipList = null;
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
75 try {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
76 // create data loader for auth-path file
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
77 File confFile = new File(configFile);
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
78 // load authPaths
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
79 XMLListLoader pathLoader =
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
80 new XMLListLoader("digilib-paths", "path", "name", "role");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
81 pathList = pathLoader.loadURL(confFile.toURL().toString());
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
82 // load authIPs
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
83 XMLListLoader ipLoader =
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
84 new XMLListLoader("digilib-addresses", "address", "ip", "role");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
85 ipList = ipLoader.loadURL(confFile.toURL().toString());
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
86 } catch (Exception e) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
87 throw new AuthOpException(
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
88 "ERROR loading authorization config file: " + e);
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
89 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
90 if ((pathList == null) || (ipList == null)) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
91 throw new AuthOpException("ERROR unable to load authorization config file!");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
92 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
93 // setup path tree
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
94 authPaths = new HashTree(pathList, "/", ",");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
95 // setup ip tree
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
96 authIPs = new HashTree(ipList, ".", ",");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
97 }
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
98
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
99 /** Return authorization roles needed for request.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
100 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
101 * Returns the list of authorization roles that are needed to access the
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
102 * specified path. No list means the path is free.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
103 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
104 * The location information of the request is also considered.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
105 *
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
106 * @param filepath filepath to be accessed.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
107 * @param request ServletRequest with address information.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
108 * @throws AuthOpException Exception thrown on error.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
109 * @return List of Strings with role names.
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
110 */
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
111 public List rolesForPath(String filepath, HttpServletRequest request)
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
112 throws digilib.auth.AuthOpException {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
113 util.dprintln(
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
114 4,
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
115 "rolesForPath ("
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
116 + filepath
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
117 + ") by ["
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
118 + request.getRemoteAddr()
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
119 + "]");
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
120
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
121 // check if the requests address provides a role
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
122 List provided = authIPs.match(request.getRemoteAddr());
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
123 if ((provided != null) && (provided.contains("ALL"))) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
124 // ALL switches off checking;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
125 return null;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
126 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
127 // which roles are required?
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
128 List required = authPaths.match(filepath);
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
129 // do any provided roles match?
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
130 if ((provided != null) && (required != null)) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
131 for (int i = 0; i < provided.size(); i++) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
132 if (required.contains(provided.get(i))) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
133 // satisfied
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
134 return null;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
135 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
136 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
137 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
138 return required;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
139 }
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
140
73
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
141 /**
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
142 * @see digilib.auth.AuthOps#rolesForPath(digilib.servlet.DigilibRequest)
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
143 */
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
144 public List rolesForPath(DigilibRequest request) throws AuthOpException {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
145 util.dprintln(
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
146 4,
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
147 "rolesForPath ("
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
148 + request.getFilePath()
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
149 + ") by ["
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
150 + request.getServletRequest().getRemoteAddr()
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
151 + "]");
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
152
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
153 // check if the requests address provides a role
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
154 List provided =
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
155 authIPs.match(request.getServletRequest().getRemoteAddr());
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
156 if ((provided != null) && (provided.contains("ALL"))) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
157 // ALL switches off checking;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
158 return null;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
159 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
160 // which roles are required?
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
161 List required = authPaths.match(request.getFilePath());
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
162 // do any provided roles match?
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
163 if ((provided != null) && (required != null)) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
164 for (int i = 0; i < provided.size(); i++) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
165 if (required.contains(provided.get(i))) {
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
166 // satisfied
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
167 return null;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
168 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
169 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
170 }
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
171 return required;
3b8797fc3e90 New servlet version 1.5b.
robcast
parents: 1
diff changeset
172 }
1
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
173
0ff3ede32060 Initial revision
robcast
parents:
diff changeset
174 }