Home » geronimo-2.2-source-release » org.apache.geronimo.security.realm.providers » [javadoc | source]

    1   /**
    2    *  Licensed to the Apache Software Foundation (ASF) under one or more
    3    *  contributor license agreements.  See the NOTICE file distributed with
    4    *  this work for additional information regarding copyright ownership.
    5    *  The ASF licenses this file to You under the Apache License, Version 2.0
    6    *  (the "License"); you may not use this file except in compliance with
    7    *  the License.  You may obtain a copy of the License at
    8    *
    9    *     http://www.apache.org/licenses/LICENSE-2.0
   10    *
   11    *  Unless required by applicable law or agreed to in writing, software
   12    *  distributed under the License is distributed on an "AS IS" BASIS,
   13    *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
   14    *  See the License for the specific language governing permissions and
   15    *  limitations under the License.
   16    */
   17   package org.apache.geronimo.security.realm.providers;
   18   
   19   import java.io.IOException;
   20   import java.util.Arrays;
   21   import java.util.Collections;
   22   import java.util.List;
   23   import java.util.Map;
   24   import java.util.Set;
   25   import javax.security.auth.DestroyFailedException;
   26   import javax.security.auth.Subject;
   27   import javax.security.auth.callback.Callback;
   28   import javax.security.auth.callback.CallbackHandler;
   29   import javax.security.auth.callback.NameCallback;
   30   import javax.security.auth.callback.PasswordCallback;
   31   import javax.security.auth.callback.UnsupportedCallbackException;
   32   import javax.security.auth.login.LoginException;
   33   import javax.security.auth.spi.LoginModule;
   34   
   35   import org.slf4j.Logger;
   36   import org.slf4j.LoggerFactory;
   37   import org.apache.geronimo.security.jaas.JaasLoginModuleUse;
   38   import org.apache.geronimo.security.jaas.NamedUsernamePasswordCredential;
   39   import org.apache.geronimo.security.jaas.WrappingLoginModule;
   40   
   41   /**
   42    * Inserts named Username/Password credential into private credentials of Subject.
   43    * <p/>
   44    * If either the username or password is not passed in the callback handler,
   45    * then the credential is not placed into the Subject.
   46    *
   47    * This login module does not check credentials so it should never be able to cause a login to succeed.
   48    * Therefore the lifecycle methods must return false to indicate success or throw a LoginException to indicate failure.
   49    *
   50    * @version $Revision: 653740 $ $Date: 2008-05-06 03:44:18 -0700 (Tue, 06 May 2008) $
   51    */
   52   public class NamedUsernamePasswordCredentialLoginModule implements LoginModule {
   53       private static final Logger log = LoggerFactory.getLogger(NamedUsernamePasswordCredentialLoginModule.class);
   54   
   55       public static final String CREDENTIAL_NAME = "Name";
   56       public static final String CREDENTIAL_NAME_LONG = NamedUsernamePasswordCredentialLoginModule.class.getName() + "." + CREDENTIAL_NAME;
   57       public final static List<String> supportedOptions = Collections.unmodifiableList(Arrays.asList(CREDENTIAL_NAME, CREDENTIAL_NAME_LONG));
   58   
   59       private String name;
   60       private Subject subject;
   61       private CallbackHandler callbackHandler;
   62       private NamedUsernamePasswordCredential nupCredential;
   63   
   64       public void initialize(Subject subject, CallbackHandler callbackHandler, Map sharedState, Map options) {
   65           this.subject = subject;
   66           this.callbackHandler = callbackHandler;
   67           for(Object option: options.keySet()) {
   68               if(!supportedOptions.contains(option) && !JaasLoginModuleUse.supportedOptions.contains(option)
   69                       && !WrappingLoginModule.supportedOptions.contains(option)) {
   70                   log.warn("Ignoring option: "+option+". Not supported.");
   71               }
   72           }
   73           name = (String) options.get(CREDENTIAL_NAME);
   74           if (name == null) {
   75               name = (String) options.get(CREDENTIAL_NAME_LONG);
   76           }
   77       }
   78   
   79       public boolean login() throws LoginException {
   80   
   81           Callback[] callbacks = new Callback[2];
   82   
   83           callbacks[0] = new NameCallback("User name");
   84           callbacks[1] = new PasswordCallback("Password", false);
   85           try {
   86               callbackHandler.handle(callbacks);
   87           } catch (IOException ioe) {
   88               throw (LoginException) new LoginException().initCause(ioe);
   89           } catch (UnsupportedCallbackException uce) {
   90               throw (LoginException) new LoginException().initCause(uce);
   91           }
   92   
   93           String username = ((NameCallback) callbacks[0]).getName();
   94           char[] password = ((PasswordCallback) callbacks[1]).getPassword();
   95   
   96           if (username == null || password == null) return false;
   97   
   98           nupCredential = new NamedUsernamePasswordCredential(username, password, name);
   99   
  100           return false;
  101       }
  102   
  103       public boolean commit() throws LoginException {
  104   
  105           if (subject.isReadOnly()) {
  106               throw new LoginException("Subject is ReadOnly");
  107           }
  108   
  109           Set pvtCreds = subject.getPrivateCredentials();
  110           if (nupCredential != null && !pvtCreds.contains(nupCredential)) {
  111               pvtCreds.add(nupCredential);
  112           }
  113   
  114           return false;
  115       }
  116   
  117       public boolean abort() throws LoginException {
  118   
  119           return logout();
  120       }
  121   
  122       public boolean logout() throws LoginException {
  123   
  124           if (nupCredential == null) return false;
  125   
  126           if(!subject.isReadOnly()) {
  127               subject.getPrivateCredentials().remove(nupCredential);
  128           }
  129           
  130           try {
  131               nupCredential.destroy();
  132           } catch (DestroyFailedException e) {
  133               // do nothing
  134           }
  135           nupCredential = null;
  136   
  137           return false;
  138       }
  139   
  140   }

Home » geronimo-2.2-source-release » org.apache.geronimo.security.realm.providers » [javadoc | source]