/* * Copyright (C) 2008-2020, Juick * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU Affero General Public License as * published by the Free Software Foundation, either version 3 of the * License, or (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU Affero General Public License for more details. * * You should have received a copy of the GNU Affero General Public License * along with this program. If not, see . */ package com.juick.service.security; import com.juick.model.User; import com.juick.service.UserService; import com.juick.service.security.entities.JuickUser; import jakarta.servlet.FilterChain; import jakarta.servlet.ServletException; import jakarta.servlet.http.Cookie; import jakarta.servlet.http.HttpServletRequest; import jakarta.servlet.http.HttpServletResponse; import org.apache.commons.lang3.StringUtils; import org.springframework.http.HttpHeaders; import org.springframework.lang.NonNull; import org.springframework.lang.Nullable; import org.springframework.security.authentication.RememberMeAuthenticationToken; import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; import org.springframework.security.core.Authentication; import org.springframework.security.core.context.SecurityContextHolder; import org.springframework.security.web.authentication.RememberMeServices; import org.springframework.security.web.authentication.rememberme.AbstractRememberMeServices; import org.springframework.util.Assert; import org.springframework.web.util.WebUtils; import java.io.IOException; /** * Created by aalexeev on 4/5/17. */ public class HashParamAuthenticationFilter extends BaseAuthenticationFilter { public static final String PARAM_NAME = "hash"; private final UserService userService; private final RememberMeServices rememberMeServices; public HashParamAuthenticationFilter( @NonNull final UserService userService, @Nullable final RememberMeServices rememberMeServices) { Assert.notNull(userService, "userService should not be null"); this.userService = userService; this.rememberMeServices = rememberMeServices; } @Override protected void doFilterInternal( HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException { String hash = getHashFromRequest(request); if (hash != null && authenticationIsRequired()) { User user = userService.getUserByHash(hash); if (!user.isAnonymous()) { User userWithPassword = userService.getUserByName(user.getName()); userWithPassword.setAuthHash(userService.getHashByUID(userWithPassword.getUid())); if (rememberMeServices != null) { // web login should create cookie var authentication = new RememberMeAuthenticationToken( ((AbstractRememberMeServices) rememberMeServices).getKey(), new JuickUser(userWithPassword), JuickUser.USER_AUTHORITY); SecurityContextHolder.getContext().setAuthentication(authentication); rememberMeServices.loginSuccess(request, response, authentication); } else { Authentication authentication = new UsernamePasswordAuthenticationToken( new JuickUser(userWithPassword), userWithPassword.getCredentials(), JuickUser.USER_AUTHORITY); SecurityContextHolder.getContext().setAuthentication(authentication); } } } filterChain.doFilter(request, response); } private String hashFromAuthorizationHeader(HttpServletRequest request) { String authorizationHeader = request.getHeader(HttpHeaders.AUTHORIZATION); if (StringUtils.isNotEmpty(authorizationHeader)) { String[] parts = authorizationHeader.split(" "); if ((parts.length == 2) && parts[0].equals("Juick")) { return parts[1]; } } return StringUtils.EMPTY; } private String getHashFromRequest(HttpServletRequest request) { String paramHash = request.getParameter(PARAM_NAME); Cookie cookieHash = WebUtils.getCookie(request, PARAM_NAME); String headerHash = hashFromAuthorizationHeader(request); if (StringUtils.isNotEmpty(headerHash)) { return headerHash; } if (paramHash == null && cookieHash != null) { return cookieHash.getValue(); } return paramHash; } }