Commit 1cae44b0 authored by Alinga Yeung's avatar Alinga Yeung
Browse files

Merge branch 'ac2' of /srv/cadc/git/wopencadc into ac2

parents da98ede5 52a4b880
Loading
Loading
Loading
Loading
+2 −4
Original line number Diff line number Diff line
@@ -4,5 +4,3 @@ JAR files required for the OpenCADC cadcTomcat project
Name in build.xml          Versioned Name		    Project URL
-----------------          --------------       	-----------
catalina.jar               catalina-7.0.33.jar      http://tomcat.apache.org/
 No newline at end of file
cadcUtil.jar                                    	http://code.google.com/p/opencadc    
+2 −2
Original line number Diff line number Diff line
@@ -86,10 +86,10 @@
    <!-- developer convenience: place for extra targets and properties -->
    <import file="extras.xml" optional="true" />

    <property name="cadcUtil"           value="${lib}/cadcUtil.jar" />
    <property name="log4j"              value="${ext.lib}/log4j.jar" />
    <property name="tomcat"             value="${ext.lib}/catalina.jar" />

    <property name="jars"               value="${cadcUtil}:${tomcat}" />
    <property name="jars"               value="${log4j}:${tomcat}" />

    <target name="build" depends="compile,resources">
        <jar jarfile="${build}/lib/${project}.jar"
+222 −19
Original line number Diff line number Diff line
package ca.nrc.cadc.auth;
/*
************************************************************************
*******************  CANADIAN ASTRONOMY DATA CENTRE  *******************
**************  CENTRE CANADIEN DE DONNÉES ASTRONOMIQUES  **************
*
*  (c) 2015.                            (c) 2015.
*  Government of Canada                 Gouvernement du Canada
*  National Research Council            Conseil national de recherches
*  Ottawa, Canada, K1A 0R6              Ottawa, Canada, K1A 0R6
*  All rights reserved                  Tous droits réservés
*
*  NRC disclaims any warranties,        Le CNRC dénie toute garantie
*  expressed, implied, or               énoncée, implicite ou légale,
*  statutory, of any kind with          de quelque nature que ce
*  respect to the software,             soit, concernant le logiciel,
*  including without limitation         y compris sans restriction
*  any warranty of merchantability      toute garantie de valeur
*  or fitness for a particular          marchande ou de pertinence
*  purpose. NRC shall not be            pour un usage particulier.
*  liable in any event for any          Le CNRC ne pourra en aucun cas
*  damages, whether direct or           être tenu responsable de tout
*  indirect, special or general,        dommage, direct ou indirect,
*  consequential or incidental,         particulier ou général,
*  arising from the use of the          accessoire ou fortuit, résultant
*  software.  Neither the name          de l'utilisation du logiciel. Ni
*  of the National Research             le nom du Conseil National de
*  Council of Canada nor the            Recherches du Canada ni les noms
*  names of its contributors may        de ses  participants ne peuvent
*  be used to endorse or promote        être utilisés pour approuver ou
*  products derived from this           promouvoir les produits dérivés
*  software without specific prior      de ce logiciel sans autorisation
*  written permission.                  préalable et particulière
*                                       par écrit.
*
*  This file is part of the             Ce fichier fait partie du projet
*  OpenCADC project.                    OpenCADC.
*
*  OpenCADC is free software:           OpenCADC est un logiciel libre ;
*  you can redistribute it and/or       vous pouvez le redistribuer ou le
*  modify it under the terms of         modifier suivant les termes de
*  the GNU Affero General Public        la “GNU Affero General Public
*  License as published by the          License” telle que publiée
*  Free Software Foundation,            par la Free Software Foundation
*  either version 3 of the              : soit la version 3 de cette
*  License, or (at your option)         licence, soit (à votre gré)
*  any later version.                   toute version ultérieure.
*
*  OpenCADC is distributed in the       OpenCADC est distribué
*  hope that it will be useful,         dans l’espoir qu’il vous
*  but WITHOUT ANY WARRANTY;            sera utile, mais SANS AUCUNE
*  without even the implied             GARANTIE : sans même la garantie
*  warranty of MERCHANTABILITY          implicite de COMMERCIALISABILITÉ
*  or FITNESS FOR A PARTICULAR          ni d’ADÉQUATION À UN OBJECTIF
*  PURPOSE.  See the GNU Affero         PARTICULIER. Consultez la Licence
*  General Public License for           Générale Publique GNU Affero
*  more details.                        pour plus de détails.
*
*  You should have received             Vous devriez avoir reçu une
*  a copy of the GNU Affero             copie de la Licence Générale
*  General Public License along         Publique GNU Affero avec
*  with OpenCADC.  If not, see          OpenCADC ; si ce n’est
*  <http://www.gnu.org/licenses/>.      pas le cas, consultez :
*                                       <http://www.gnu.org/licenses/>.
*
*  $Revision: 5 $
*
************************************************************************
*/

package ca.nrc.cadc.tomcat;

import java.net.HttpURLConnection;
import java.net.URI;
import java.net.URL;
import java.security.Principal;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.List;

import org.apache.catalina.realm.GenericPrincipal;
import org.apache.catalina.realm.RealmBase;
import org.apache.log4j.BasicConfigurator;
import org.apache.log4j.ConsoleAppender;
import org.apache.log4j.Level;
import org.apache.log4j.Logger;
import org.apache.log4j.PatternLayout;
import org.apache.log4j.varia.LevelRangeFilter;

/**
 * Custom class for Tomcat realm authentication.
 *
 * This class was written against the Apache Tomcat 7 (7.0.33.0) API
 *
 * Authentication checks are performed as REST calls to servers
 * implementing the cadcAccessControl-Server code.
 *
 * @author majorb
 */
public class CadcBasicAuthenticator extends RealmBase
{

    private static Logger log = Logger.getLogger(CadcBasicAuthenticator.class);
    private static final String AC_URI = "ivo://cadc.nrc.ca/canfargms";

    private static final String ISO_DATE_FORMAT = "yyyy-MM-dd HH:mm:ss.SSS";

    // SHORT_FORMAT applies to DEBUG and TRACE logging levels
    private static final String SHORT_FORMAT = "%-4r [%t] %-5p %c{1} %x - %m\n";

    // LONG_FORMAT applies to INFO, WARN, ERROR and FATAL logging levels
    private static final String LONG_FORMAT = "%d{" + ISO_DATE_FORMAT
                                              + "} [%t] %-5p %c{1} %x - %m\n";

    static
    {
        initLogging();
        Logger.getLogger("ca.nrc.cadc.tomcat").setLevel(Level.INFO);
    }

    @Override
    protected String getName()
    {
        System.out.println("getName");
        // not used
        return this.getClass().getSimpleName();
    }

    @Override
    protected String getPassword(final String username)
    {
        System.out.println("getPassword");
        // not used
        return null;
    }

    @Override
    protected Principal getPrincipal(final String username)
    {
        System.out.println("getPrincipal");
        // not used
        return null;
    }

    @Override
    public Principal authenticate(String username, String credentials)
    {
        System.out.println(String.format("username/credentials: %s/%s", username, credentials));
        System.out.println("Returning role public");
        long start = System.currentTimeMillis();
        boolean success = true;

        try
        {
            RealmRegistryClient registryClient = new RealmRegistryClient();
            URL loginURL = registryClient.getServiceURL(
                new URI(AC_URI), "http", "/login");

            String post = "userid=" + username + "&password=" + credentials;

            HttpURLConnection conn = (HttpURLConnection) loginURL.openConnection();
            conn.setRequestMethod("POST");
            conn.setDoOutput(true);

            byte[] postData = post.getBytes("UTF-8");
            conn.getOutputStream().write(postData);

            int responseCode = conn.getResponseCode();

            log.debug("Http POST to /ac/login returned " +
                    responseCode + " for user " + username);

            if (responseCode != 200)
            {
                // authentication not ok
                if (responseCode != 401)
                {
                    // not an unauthorized, so log the
                    // possible server side error
                    String errorMessage = "Error calling /ac/login, error code: " + responseCode;
                    success = false;
                    throw new IllegalStateException(errorMessage);
                }

                // authentication simply failed
                return null;
            }

            // authentication ok, add public role
            List<String> roles = Arrays.asList("public");
        return new GenericPrincipal(username, credentials, roles);
//
//        return new Principal()
//        {
//            @Override
//            public String getName()
//            {
//                return "majorb";
//            }
//        };

            // Don't want to return the password here in the principal
            // in case it makes it into the servlet somehow
            return new GenericPrincipal(username, "", roles);

        }
        catch (Throwable t)
        {
            String message = "Could not do http basic authentication: " + t.getMessage();
            log.error(message, t);
            throw new IllegalStateException(message, t);
        }
        finally
        {
            long duration = System.currentTimeMillis() - start;

            StringBuilder json = new StringBuilder();
            json.append("{");
            json.append("\"method\":\"AUTH\",");
            json.append("\"user\":\"" + username + "\",");
            json.append("\"success\":" + success + ",");
            json.append("\"time\":" + duration);
            json.append("}");

            log.info(json.toString());
        }
    }

    private static void initLogging()
    {
        // Clear all existing appenders, if there's any.
        BasicConfigurator.resetConfiguration();
        Logger.getRootLogger().setLevel(Level.ERROR); // must redo after reset

        String errorLogFormat = LONG_FORMAT;
        String infoLogFormat = LONG_FORMAT;
        String debugLogFormat = SHORT_FORMAT;

        // Appender for WARN, ERROR and FATAL with LONG_FORMAT message prefix
        ConsoleAppender conAppenderHigh =
                new ConsoleAppender(new PatternLayout(errorLogFormat));
        LevelRangeFilter errorFilter = new LevelRangeFilter();
        errorFilter.setLevelMax(Level.FATAL);
        errorFilter.setLevelMin(Level.WARN);
        errorFilter.setAcceptOnMatch(true);
        conAppenderHigh.clearFilters();
        conAppenderHigh.addFilter(errorFilter);
        BasicConfigurator.configure(conAppenderHigh);

        // Appender for INFO with LONG_FORMAT message prefix
        ConsoleAppender conAppenderInfo =
                new ConsoleAppender(new PatternLayout(infoLogFormat));
        LevelRangeFilter infoFilter = new LevelRangeFilter();
        infoFilter.setLevelMax(Level.INFO);
        infoFilter.setLevelMin(Level.INFO);
        infoFilter.setAcceptOnMatch(true);
        conAppenderInfo.clearFilters();
        conAppenderInfo.addFilter(infoFilter);
        BasicConfigurator.configure(conAppenderInfo);

        // Appender for DEBUG and TRACE with LONG_FORMAT message prefix
        ConsoleAppender conAppenderDebug =
                new ConsoleAppender(new PatternLayout(debugLogFormat));
        LevelRangeFilter debugFilter = new LevelRangeFilter();
        debugFilter.setLevelMax(Level.DEBUG);
        debugFilter.setLevelMin(Level.TRACE);
        debugFilter.setAcceptOnMatch(true);
        conAppenderDebug.clearFilters();
        conAppenderDebug.addFilter(debugFilter);
        BasicConfigurator.configure(conAppenderDebug);
    }

}
 No newline at end of file
+153 −0
Original line number Diff line number Diff line
/*
************************************************************************
*******************  CANADIAN ASTRONOMY DATA CENTRE  *******************
**************  CENTRE CANADIEN DE DONNÉES ASTRONOMIQUES  **************
*
*  (c) 2010.                            (c) 2010.
*  Government of Canada                 Gouvernement du Canada
*  National Research Council            Conseil national de recherches
*  Ottawa, Canada, K1A 0R6              Ottawa, Canada, K1A 0R6
*  All rights reserved                  Tous droits réservés
*
*  NRC disclaims any warranties,        Le CNRC dénie toute garantie
*  expressed, implied, or               énoncée, implicite ou légale,
*  statutory, of any kind with          de quelque nature que ce
*  respect to the software,             soit, concernant le logiciel,
*  including without limitation         y compris sans restriction
*  any warranty of merchantability      toute garantie de valeur
*  or fitness for a particular          marchande ou de pertinence
*  purpose. NRC shall not be            pour un usage particulier.
*  liable in any event for any          Le CNRC ne pourra en aucun cas
*  damages, whether direct or           être tenu responsable de tout
*  indirect, special or general,        dommage, direct ou indirect,
*  consequential or incidental,         particulier ou général,
*  arising from the use of the          accessoire ou fortuit, résultant
*  software.  Neither the name          de l'utilisation du logiciel. Ni
*  of the National Research             le nom du Conseil National de
*  Council of Canada nor the            Recherches du Canada ni les noms
*  names of its contributors may        de ses  participants ne peuvent
*  be used to endorse or promote        être utilisés pour approuver ou
*  products derived from this           promouvoir les produits dérivés
*  software without specific prior      de ce logiciel sans autorisation
*  written permission.                  préalable et particulière
*                                       par écrit.
*
*  This file is part of the             Ce fichier fait partie du projet
*  OpenCADC project.                    OpenCADC.
*
*  OpenCADC is free software:           OpenCADC est un logiciel libre ;
*  you can redistribute it and/or       vous pouvez le redistribuer ou le
*  modify it under the terms of         modifier suivant les termes de
*  the GNU Affero General Public        la “GNU Affero General Public
*  License as published by the          License” telle que publiée
*  Free Software Foundation,            par la Free Software Foundation
*  either version 3 of the              : soit la version 3 de cette
*  License, or (at your option)         licence, soit (à votre gré)
*  any later version.                   toute version ultérieure.
*
*  OpenCADC is distributed in the       OpenCADC est distribué
*  hope that it will be useful,         dans l’espoir qu’il vous
*  but WITHOUT ANY WARRANTY;            sera utile, mais SANS AUCUNE
*  without even the implied             GARANTIE : sans même la garantie
*  warranty of MERCHANTABILITY          implicite de COMMERCIALISABILITÉ
*  or FITNESS FOR A PARTICULAR          ni d’ADÉQUATION À UN OBJECTIF
*  PURPOSE.  See the GNU Affero         PARTICULIER. Consultez la Licence
*  General Public License for           Générale Publique GNU Affero
*  more details.                        pour plus de détails.
*
*  You should have received             Vous devriez avoir reçu une
*  a copy of the GNU Affero             copie de la Licence Générale
*  General Public License along         Publique GNU Affero avec
*  with OpenCADC.  If not, see          OpenCADC ; si ce n’est
*  <http://www.gnu.org/licenses/>.      pas le cas, consultez :
*                                       <http://www.gnu.org/licenses/>.
*
*  $Revision: 5 $
*
************************************************************************
*/

package ca.nrc.cadc.tomcat;

import java.io.BufferedReader;
import java.io.IOException;
import java.io.InputStream;
import java.io.InputStreamReader;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import java.util.Set;

/**
 * A properties file reader that allows a property to have multiple values.
 * The <code>java.util.Properties</code> class is a HashTable so only permits one
 * value.
 *
 * This class is a fork of ca.nrc.cadc.util.MultiValuedProperties.  It was forked
 * to allow the realm implementation to be deployed without library dependencies.
 *
 * @author pdowler
 */
public class RealmMultiValuedProperties
{
    private Map<String, List<String>> props;

    public RealmMultiValuedProperties() { }

    public List<String> getProperty(String name)
    {
        if (props == null)
            return null;
        return props.get(name);
    }

    public Set<String> keySet()
    {
        if (props == null)
            return null;
        return props.keySet();
    }

    public void load(InputStream istream)
        throws IOException
    {
        this.props = new HashMap<String, List<String>>();

        String strLine, key, value;
        char firstChar;
        List<String> valueList;
        int idxColon, lineLength;

        BufferedReader br = new BufferedReader(new InputStreamReader(istream));
        //Read File Line By Line
        while ((strLine = br.readLine()) != null)
        {
            strLine = strLine.trim();
            lineLength = strLine.length();
            if (lineLength == 0)
                continue;

            firstChar = strLine.charAt(0);
            if (firstChar == '#' || firstChar == '!') //comment line
                continue;

            idxColon = strLine.indexOf('=');
            if (idxColon == 0) // "=foo"
                continue;

            key = strLine.substring(0, idxColon).trim();
            value = strLine.substring(idxColon + 1).trim();

            valueList = props.get(key);
            if (valueList == null) // the key is not in parameters yet
            {
                valueList = new ArrayList<String>();
                props.put(key, valueList);
            }
            valueList.add(value);
        }
        //Close the buffered reader
        br.close();
    }
}
+325 −0

File added.

Preview size limit exceeded, changes collapsed.