privatestaticfinal List<Class<? extends DigestCredentialHandlerBase>> credentialHandlerClasses = new ArrayList<>();
static { // Order is important since it determines the search order for a // matching handler if only an algorithm is specified when calling // main()
credentialHandlerClasses.add(MessageDigestCredentialHandler.class);
credentialHandlerClasses.add(SecretKeyCredentialHandler.class);
}
@Override public Principal authenticate(String username) {
if (username == null) { returnnull;
}
if (containerLog.isTraceEnabled()) {
containerLog.trace(sm.getString("realmBase.authenticateSuccess", username));
}
return getPrincipal(username);
}
@Override public Principal authenticate(String username, String credentials) { // No user or no credentials // Can't possibly authenticate, don't bother doing anything. if (username == null || credentials == null) { if (containerLog.isTraceEnabled()) {
containerLog.trace(sm.getString("realmBase.authenticateFailure", username));
} returnnull;
}
// Look up the user's credentials
String serverCredentials = getPassword(username);
if (serverCredentials == null) { // User was not found // Waste a bit of time as not to reveal that the user does not exist.
getCredentialHandler().mutate(credentials);
if (containerLog.isTraceEnabled()) {
containerLog.trace(sm.getString("realmBase.authenticateFailure", username));
} returnnull;
}
@Override public Principal authenticate(GSSName gssName, GSSCredential gssCredential) { if (gssName == null) { returnnull;
}
return getPrincipal(gssName, gssCredential);
}
/** *{@inheritDoc} *<p> *ThedefaultimplementationisNO-OP.
*/
@Override publicvoid backgroundProcess() { // NOOP in base class
}
@Override public SecurityConstraint[] findSecurityConstraints(Request request, Context context) {
ArrayList<SecurityConstraint> results = null; // Are there any defined security constraints?
SecurityConstraint constraints[] = context.findConstraints(); if (constraints == null || constraints.length == 0) { if (log.isDebugEnabled()) {
log.debug(" No applicable constraints defined");
} returnnull;
}
// Check each defined security constraint
String uri = request.getRequestPathMB().toString(); // Bug47080 - in rare cases this may be null or "" // Mapper treats as '/' do the same to prevent NPE if (uri == null || uri.length() == 0) {
uri = "/";
}
String method = request.getMethod(); int i; boolean found = false; for (i = 0; i < constraints.length; i++) {
SecurityCollection[] collections = constraints[i].findCollections();
// If collection is null, continue to avoid an NPE // See Bugzilla 30624 if (collections == null) { continue;
}
if (log.isDebugEnabled()) {
log.debug(" Checking constraint '" + constraints[i] + "' against " + method + " " + uri + " --> " +
constraints[i].included(uri, method));
}
for (SecurityCollection securityCollection : collections) {
String[] patterns = securityCollection.findPatterns();
// If patterns is null, continue to avoid an NPE // See Bugzilla 30624 if (patterns == null) { continue;
}
for (String pattern : patterns) { // Exact match including special case for the context root. if (uri.equals(pattern) || pattern.length() == 0 && uri.equals("/")) {
found = true; if (securityCollection.findMethod(method)) { if (results == null) {
results = new ArrayList<>();
}
results.add(constraints[i]);
}
}
}
}
}
if (found) { return resultsToArray(results);
}
int longest = -1;
for (i = 0; i < constraints.length; i++) {
SecurityCollection[] collection = constraints[i].findCollections();
// If collection is null, continue to avoid an NPE // See Bugzilla 30624 if (collection == null) { continue;
}
if (log.isDebugEnabled()) {
log.debug(" Checking constraint '" + constraints[i] + "' against " + method + " " + uri + " --> " +
constraints[i].included(uri, method));
}
for (SecurityCollection securityCollection : collection) {
String[] patterns = securityCollection.findPatterns();
// If patterns is null, continue to avoid an NPE // See Bugzilla 30624 if (patterns == null) { continue;
}
boolean matched = false; int length = -1; for (String pattern : patterns) { if (pattern.startsWith("/") && pattern.endsWith("/*") && pattern.length() >= longest) {
if (pattern.length() == 2) {
matched = true;
length = pattern.length();
} elseif (pattern.regionMatches(0, uri, 0, pattern.length() - 1) ||
(pattern.length() - 2 == uri.length() &&
pattern.regionMatches(0, uri, 0, pattern.length() - 2))) {
matched = true;
length = pattern.length();
}
}
} if (matched) { if (length > longest) {
found = false; if (results != null) {
results.clear();
}
longest = length;
} if (securityCollection.findMethod(method)) {
found = true; if (results == null) {
results = new ArrayList<>();
}
results.add(constraints[i]);
}
}
}
}
if (found) { return resultsToArray(results);
}
for (i = 0; i < constraints.length; i++) {
SecurityCollection[] collection = constraints[i].findCollections();
// If collection is null, continue to avoid an NPE // See Bugzilla 30624 if (collection == null) { continue;
}
if (log.isDebugEnabled()) {
log.debug(" Checking constraint '" + constraints[i] + "' against " + method + " " + uri + " --> " +
constraints[i].included(uri, method));
}
// If patterns is null, continue to avoid an NPE // See Bugzilla 30624 if (patterns == null) { continue;
}
for (int k = 0; k < patterns.length && !matched; k++) {
String pattern = patterns[k]; if (pattern.startsWith("*.")) { int slash = uri.lastIndexOf('/'); int dot = uri.lastIndexOf('.'); if (slash >= 0 && dot > slash && dot != uri.length() - 1 &&
uri.length() - dot == pattern.length() - 1) { if (pattern.regionMatches(1, uri, dot, uri.length() - dot)) {
matched = true;
pos = j;
}
}
}
}
} if (matched) {
found = true; if (collection[pos].findMethod(method)) { if (results == null) {
results = new ArrayList<>();
}
results.add(constraints[i]);
}
}
}
if (found) { return resultsToArray(results);
}
for (i = 0; i < constraints.length; i++) {
SecurityCollection[] collection = constraints[i].findCollections();
// If collection is null, continue to avoid an NPE // See Bugzilla 30624 if (collection == null) { continue;
}
if (log.isDebugEnabled()) {
log.debug(" Checking constraint '" + constraints[i] + "' against " + method + " " + uri + " --> " +
constraints[i].included(uri, method));
}
for (SecurityCollection securityCollection : collection) {
String[] patterns = securityCollection.findPatterns();
// If patterns is null, continue to avoid an NPE // See Bugzilla 30624 if (patterns == null) { continue;
}
boolean matched = false; for (String pattern : patterns) { if (pattern.equals("/")) {
matched = true; break;
}
} if (matched) { if (results == null) {
results = new ArrayList<>();
}
results.add(constraints[i]);
}
}
}
if (results == null) { // No applicable security constraint was found if (log.isDebugEnabled()) {
log.debug(" No applicable constraint located");
}
} return resultsToArray(results);
}
// Which user principal have we already authenticated?
Principal principal = request.getPrincipal(); boolean status = false; boolean denyfromall = false; for (SecurityConstraint constraint : constraints) {
String roles[]; if (constraint.getAllRoles()) { // * means all roles defined in web.xml
roles = request.getContext().findSecurityRoles();
} else {
roles = constraint.findAuthRoles();
}
if (roles == null) {
roles = new String[0];
}
if (log.isDebugEnabled()) {
log.debug(" Checking roles " + principal);
}
if (constraint.getAuthenticatedUsers() && principal != null) { if (log.isDebugEnabled()) {
log.debug("Passing all authenticated users");
}
status = true;
} elseif (roles.length == 0 && !constraint.getAllRoles() && !constraint.getAuthenticatedUsers()) { if (constraint.getAuthConstraint()) { if (log.isDebugEnabled()) {
log.debug("No roles");
}
status = false; // No listed roles means no access at all
denyfromall = true; break;
}
if (log.isDebugEnabled()) {
log.debug("Passing all access");
}
status = true;
} elseif (principal == null) { if (log.isDebugEnabled()) {
log.debug(" No user authenticated, cannot grant access");
}
} else { for (String role : roles) { if (hasRole(request.getWrapper(), principal, role)) {
status = true; if (log.isDebugEnabled()) {
log.debug("Role found: " + role);
}
} elseif (log.isDebugEnabled()) {
log.debug("No role found: " + role);
}
}
}
}
if (!denyfromall && allRolesMode != AllRolesMode.STRICT_MODE && !status && principal != null) { if (log.isDebugEnabled()) {
log.debug("Checking for all roles mode: " + allRolesMode);
} // Check for an all roles(role-name="*") for (SecurityConstraint constraint : constraints) {
String roles[]; // If the all roles mode exists, sets if (constraint.getAllRoles()) { if (allRolesMode == AllRolesMode.AUTH_ONLY_MODE) { if (log.isDebugEnabled()) {
log.debug("Granting access for role-name=*, auth-only");
}
status = true; break;
}
// For AllRolesMode.STRICT_AUTH_ONLY_MODE there must be zero roles
roles = request.getContext().findSecurityRoles(); if (roles == null) {
roles = new String[0];
} if (roles.length == 0 && allRolesMode == AllRolesMode.STRICT_AUTH_ONLY_MODE) { if (log.isDebugEnabled()) {
log.debug("Granting access for role-name=*, strict auth-only");
}
status = true; break;
}
}
}
}
// Return a "Forbidden" message denying access to this resource if (!status) {
response.sendError(HttpServletResponse.SC_FORBIDDEN, sm.getString("realmBase.forbidden"));
} return status;
}
/** *{@inheritDoc} *<p> *Thismethodor{@link#hasRoleInternal(Principal,String)}canbeoverriddenbyRealmimplementations,butthe *defaultisadequatewhenaninstanceof<code>GenericPrincipal</code>isusedtorepresentauthenticated *PrincipalsfromthisRealm.
*/
@Override publicboolean hasRole(Wrapper wrapper, Principal principal, String role) { // Check for a role alias if (wrapper != null) {
String realRole = wrapper.findSecurityReference(role); if (realRole != null) {
role = realRole;
}
}
// Should be overridden in JAASRealm - to avoid pretty inefficient conversions if (principal == null || role == null) { returnfalse;
}
boolean result = hasRoleInternal(principal, role);
if (log.isDebugEnabled()) {
String name = principal.getName(); if (result) {
log.debug(sm.getString("realmBase.hasRoleSuccess", name, role));
} else {
log.debug(sm.getString("realmBase.hasRoleFailure", name, role));
}
}
return result;
}
/** *Parsethespecifieddelimiterseparatedattributenamesandreturnalistofthatnamesor<code>null</code>,if *noattributeshavebeenspecified. *<p> *Ifawildcardcharacterisfound,returnalistconsistingofasinglewildcardcharacteronly. * *@paramuserAttributescommaseparatednamesofattributestoparse * *@returnalistcontainingtheparsedattributenamesor<code>null</code>,ifnoattributeshavebeenspecified
*/ protected List<String> parseUserAttributes(String userAttributes) { if (userAttributes == null) { returnnull;
}
List<String> attrs = new ArrayList<>(); for (String name : userAttributes.split(USER_ATTRIBUTES_DELIMITER)) {
name = name.trim(); if (name.length() == 0) { continue;
} if (name.equals(USER_ATTRIBUTES_WILDCARD)) { return Collections.singletonList(USER_ATTRIBUTES_WILDCARD);
} if (attrs.contains(name)) { // skip duplicates continue;
}
attrs.add(name);
} return attrs.size() > 0 ? attrs : null;
}
/** *CheckifthespecifiedPrincipalhasthespecifiedsecurityrole,withinthecontextofthisRealm.Thismethod *or{@link#hasRoleInternal(Principal,String)}canbeoverriddenbyRealmimplementations,butthedefaultis *adequatewhenaninstanceof<code>GenericPrincipal</code>isusedtorepresentauthenticatedPrincipalsfrom *thisRealm. * *@paramprincipalPrincipalforwhomtheroleistobechecked *@paramroleSecurityroletobechecked * *@return<code>true</code>ifthespecifiedPrincipalhasthespecifiedsecurityrole,withinthecontextofthis *Realm;otherwisereturn<code>false</code>.
*/ protectedboolean hasRoleInternal(Principal principal, String role) { // Should be overridden in JAASRealm - to avoid pretty inefficient conversions if (!(principal instanceof GenericPrincipal)) { returnfalse;
}
GenericPrincipal gp = (GenericPrincipal) principal; return gp.hasRole(role);
}
// Is there a relevant user data constraint? if (constraints == null || constraints.length == 0) { if (log.isDebugEnabled()) {
log.debug(" No applicable security constraint defined");
} returntrue;
} for (SecurityConstraint constraint : constraints) {
String userConstraint = constraint.getUserConstraint(); if (userConstraint == null) { if (log.isDebugEnabled()) {
log.debug(" No applicable user data constraint defined");
} returntrue;
} if (userConstraint.equals(TransportGuarantee.NONE.name())) { if (log.isDebugEnabled()) {
log.debug(" User data constraint has no restrictions");
} returntrue;
}
} // Validate the request against the user data constraint if (request.getRequest().isSecure()) { if (log.isDebugEnabled()) {
log.debug(" User data constraint already satisfied");
} returntrue;
} // Initialize variables we need to determine the appropriate action int redirectPort = request.getConnector().getRedirectPortWithOffset();
// Is redirecting disabled? if (redirectPort <= 0) { if (log.isDebugEnabled()) {
log.debug(" SSL redirect is disabled");
}
response.sendError(HttpServletResponse.SC_FORBIDDEN, request.getRequestURI()); returnfalse;
}
// Redirect to the corresponding SSL port
StringBuilder file = new StringBuilder();
String protocol = "https";
String host = request.getServerName(); // Protocol
file.append(protocol).append("://").append(host); // Host with port if (redirectPort != 443) {
file.append(':').append(redirectPort);
} // URI
file.append(request.getRequestURI());
String requestedSessionId = request.getRequestedSessionId(); if ((requestedSessionId != null) && request.isRequestedSessionIdFromURL()) {
file.append(';');
file.append(SessionConfig.getSessionUriParamName(request.getContext()));
file.append('=');
file.append(requestedSessionId);
}
String queryString = request.getQueryString(); if (queryString != null) {
file.append('?');
file.append(queryString);
} if (log.isDebugEnabled()) {
log.debug(" Redirecting to " + file.toString());
}
response.sendRedirect(file.toString(), transportGuaranteeRedirectStatus); returnfalse;
/** *Gettheprincipalassociatedwiththespecified{@linkGSSName}. * *@paramgssNameTheGSSname *@paramgssCredentialtheGSScredentialoftheprincipal * *@returntheprincipalassociatedwiththegivenusername.
*/ protected Principal getPrincipal(GSSName gssName, GSSCredential gssCredential) {
String name = gssName.toString();
if (isStripRealmForGss()) { int i = name.indexOf('@'); if (i > 0) { // Zero so we don't leave a zero length name
name = name.substring(0, i);
}
}
Principal p = getPrincipal(name);
if (p instanceof GenericPrincipal) {
((GenericPrincipal) p).setGssCredential(gssCredential);
}
return p;
}
/** *ReturntheServerobjectthatistheultimateparentforthecontainerwithwhichthisRealmisassociated.If *theservercannotbefound(egbecausethecontainerhierarchyisnotcomplete),<code>null</code>isreturned. * *@returntheServerassociatedwiththerealm
*/ protected Server getServer() {
Container c = container; if (c instanceof Context) {
c = c.getParent();
} if (c instanceof Host) {
c = c.getParent();
} if (c instanceof Engine) {
Service s = ((Engine) c).getService(); if (s != null) { return s.getServer();
}
} returnnull;
}
// Use negative values since null is not an option to indicate 'not set' int saltLength = -1; int iterations = -1; int keyLength = -1; // Default
String encoding = Charset.defaultCharset().name(); // Default values for these depend on whether either of them are set on // the command line
String algorithm = null;
String handlerClassName = null;
// Determine defaults for -a and -h. The rules are more complex to // express than the implementation: // - if neither -a nor -h is set, use SHA-512 and // MessageDigestCredentialHandler // - if only -a is set the built-in handlers will be searched in order // (MessageDigestCredentialHandler, SecretKeyCredentialHandler) and // the first handler that supports the algorithm will be used // - if only -h is set no default will be used for -a. The handler may // or may nor support -a and may or may not supply a sensible default if (algorithm == null && handlerClassName == null) {
algorithm = "SHA-512";
}
¤ Diese beiden folgenden Angebotsgruppen bietet das Unternehmen0.43Angebot
(Wie Sie bei der Firma Beratungs- und Dienstleistungen beauftragen können 2026-10-01)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.