aboutsummaryrefslogtreecommitdiffstats
path: root/cadi/core/src/main/java/org/onap/ccsdk/apps/cadi/wsse/WSSEParser.java
blob: 4f85fa5fbe597d240f9dbf21fda3c664731ad9af (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
/**
 * ============LICENSE_START====================================================
 * org.onap.ccsdk
 * ===========================================================================
 * Copyright (c) 2023 AT&T Intellectual Property. All rights reserved.
 * ===========================================================================
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 * ============LICENSE_END====================================================
 *
 */

package org.onap.ccsdk.apps.cadi.wsse;

import java.io.InputStream;

import javax.xml.stream.XMLStreamException;

import org.onap.ccsdk.apps.cadi.BasicCred;


/**
 * WSSE Parser
 *
 * Read the User and Password from WSSE Formatted SOAP Messages
 *
 * This class uses StAX so that processing is stopped as soon as the Security User/Password are read into BasicCred, or the Header Ends
 *
 * This class is intended to be created once (or very few times) and reused as much as possible.
 *
 * It is as thread safe as StAX parsing is.
 *
 * @author Jonathan
 */
public class WSSEParser {
    private static final String SOAP_NS = "http://schemas.xmlsoap.org/soap/envelope/";
    private static final String WSSE_NS = "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd";
    private Match<BasicCred> parseTree;

    public WSSEParser() {
        // soap:Envelope/soap:Header/wsse:Security/wsse:UsernameToken/[wsse:Password&wsse:Username]
        parseTree = new Match<BasicCred>(SOAP_NS,"root", // need a root level to start from... Doesn't matter what the tag is
            new Match<BasicCred>(SOAP_NS,"Envelope",
                new Match<BasicCred>(SOAP_NS,"Header",
                    new Match<BasicCred>(WSSE_NS,"Security",
                        new Match<BasicCred>(WSSE_NS,"UsernameToken",
                            new Match<BasicCred>(WSSE_NS,"Password").set(new Action<BasicCred>() {
                                public boolean content(BasicCred bc,String text) {
                                    bc.setCred(text.getBytes());
                                    return true;
                                }
                            }),
                            new Match<BasicCred>(WSSE_NS,"Username").set(new Action<BasicCred>() {
                                public boolean content(BasicCred bc,String text) {
                                    bc.setUser(text);
                                    return true;
                                }
                            })
                        ).stopAfter() // if found, end when UsernameToken ends (no further processing needed)
                    )
                ).stopAfter() // Stop Processing when Header Ends
            ).exclusive()// Envelope must match Header, and no other.  FYI, Body comes after Header short circuits (see above), so it's ok
        ).exclusive(); // root must be Envelope
    }

    public XMLStreamException parse(BasicCred bc, InputStream is) {
        try {
            parseTree.onMatch(bc, new XReader(is));
            return null;
        } catch (XMLStreamException e) {
            return e;
        }
    }
}