1 /*
2 * Copyright (c) 2002-2021, City of Paris
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 *
9 * 1. Redistributions of source code must retain the above copyright notice
10 * and the following disclaimer.
11 *
12 * 2. Redistributions in binary form must reproduce the above copyright notice
13 * and the following disclaimer in the documentation and/or other materials
14 * provided with the distribution.
15 *
16 * 3. Neither the name of 'Mairie de Paris' nor 'Lutece' nor the names of its
17 * contributors may be used to endorse or promote products derived from
18 * this software without specific prior written permission.
19 *
20 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
21 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE
24 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30 * POSSIBILITY OF SUCH DAMAGE.
31 *
32 * License 1.0
33 */
34 package fr.paris.lutece.util.signrequest;
35
36 import java.util.ArrayList;
37 import java.util.Date;
38 import java.util.List;
39
40 import javax.servlet.http.HttpServletRequest;
41
42 /**
43 * HeaderHashAuthenticator
44 */
45 public class HeaderHashAuthenticator extends AbstractPrivateKeyAuthenticator implements RequestAuthenticator
46 {
47 private static final String HEADER_SIGNATURE = "Lutece-Request-Signature";
48 private static final String HEADER_TIMESTAMP = "Lutece-Request-Timestamp";
49
50 /**
51 * {@inheritDoc }
52 */
53 @Override
54 public boolean isRequestAuthenticated( HttpServletRequest request )
55 {
56 String strHash1 = request.getHeader( HEADER_SIGNATURE );
57 String strTimestamp = request.getHeader( HEADER_TIMESTAMP );
58
59 // no signature or timestamp
60 if ( ( strHash1 == null ) || ( strTimestamp == null ) )
61 {
62 LOGGER.info( "SignRequest - Invalid signature" );
63
64 return false;
65 }
66
67 if ( !isValidTimestamp( strTimestamp ) )
68 {
69 LOGGER.info( "SignRequest - Invalid timestamp : " + strTimestamp );
70
71 return false;
72 }
73
74 List<String> listElements = new ArrayList<String>( );
75
76 for ( String strParameter : getSignatureElements( ) )
77 {
78 String strValue = request.getParameter( strParameter );
79
80 if ( strValue != null )
81 {
82 listElements.add( strValue );
83 }
84 }
85
86 String strHash2 = buildSignature( listElements, strTimestamp, getPrivateKey( ) );
87
88 return strHash1.equals( strHash2 );
89 }
90
91 /**
92 * {@inheritDoc }
93 */
94 @Override
95 public AuthenticateRequestInformations getSecurityInformations( List<String> elements )
96 {
97 String strTimestamp = String.valueOf( new Date( ).getTime( ) );
98 String strSignature = buildSignature( elements, strTimestamp, getPrivateKey( ) );
99
100 return new AuthenticateRequestInformations().addSecurityHeader(HEADER_TIMESTAMP,strTimestamp).addSecurityHeader(HEADER_SIGNATURE, strSignature);
101
102 }
103 }