AbsAuthServlet.java 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249
  1. /**
  2. * Copyright (c) 2006-2019, JGraph Ltd
  3. */
  4. package com.mxgraph.online;
  5. import java.io.BufferedReader;
  6. import java.io.DataOutputStream;
  7. import java.io.IOException;
  8. import java.io.InputStreamReader;
  9. import java.io.OutputStream;
  10. import java.io.PrintWriter;
  11. import java.net.HttpURLConnection;
  12. import java.net.URL;
  13. import java.util.HashMap;
  14. import javax.servlet.ServletException;
  15. import javax.servlet.http.HttpServlet;
  16. import javax.servlet.http.HttpServletRequest;
  17. import javax.servlet.http.HttpServletResponse;
  18. @SuppressWarnings("serial")
  19. abstract public class AbsAuthServlet extends HttpServlet
  20. {
  21. private static final boolean DEBUG = false;
  22. private static final String SEPARATOR = "/:::/";
  23. static public class Config
  24. {
  25. public String DEV_CLIENT_SECRET = null, CLIENT_SECRET = null, DEV_CLIENT_ID = null, CLIENT_ID = null,
  26. DEV_REDIRECT_URI = null, REDIRECT_URI = null, AUTH_SERVICE_URL = null;
  27. }
  28. protected Config getConfig()
  29. {
  30. return null;
  31. }
  32. protected String processAuthError(String errorCode)
  33. {
  34. //Usually sending null is enough as it is used as a value for auth info
  35. //If more processing is needed, override this method
  36. return processAuthResponse("null", false);
  37. }
  38. protected String processAuthResponse(String authRes, boolean jsonResponse)
  39. {
  40. return "";
  41. }
  42. /**
  43. * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response)
  44. */
  45. protected void doGet(HttpServletRequest request,
  46. HttpServletResponse response) throws ServletException, IOException
  47. {
  48. String code = request.getParameter("code");
  49. String refreshToken = request.getParameter("refresh_token");
  50. String error = request.getParameter("error");
  51. HashMap<String, String> stateVars = new HashMap<>();
  52. try
  53. {
  54. String state = request.getParameter("state");
  55. if (state != null)
  56. {
  57. String[] parts = state.split("&");
  58. for (String part : parts)
  59. {
  60. String[] keyVal = part.split("=");
  61. stateVars.put(keyVal[0], keyVal[1]);
  62. }
  63. }
  64. int configIndex = 0;
  65. String appIndex = stateVars.get("appIndex");
  66. if (appIndex != null)
  67. {
  68. configIndex = Integer.parseInt(appIndex);
  69. }
  70. Config CONFIG = getConfig();
  71. String secret, client, redirectUri;
  72. String[] secrets, clients;
  73. if ("127.0.0.1".equals(request.getServerName()))
  74. {
  75. secrets = CONFIG.DEV_CLIENT_SECRET.split(SEPARATOR);
  76. clients = CONFIG.DEV_CLIENT_ID.split(SEPARATOR);
  77. redirectUri = CONFIG.DEV_REDIRECT_URI;
  78. }
  79. else
  80. {
  81. secrets = CONFIG.CLIENT_SECRET.split(SEPARATOR);
  82. clients = CONFIG.CLIENT_ID.split(SEPARATOR);
  83. redirectUri = CONFIG.REDIRECT_URI;
  84. }
  85. secret = secrets.length > configIndex ? secrets[configIndex] : secrets[0];
  86. client = clients.length > configIndex ? clients[configIndex] : clients[0];
  87. if (error != null)
  88. {
  89. response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
  90. OutputStream out = response.getOutputStream();
  91. PrintWriter writer = new PrintWriter(out);
  92. // Writes JavaScript code
  93. writer.println(processAuthError(error));
  94. writer.flush();
  95. writer.close();
  96. }
  97. else if (code == null && refreshToken == null)
  98. {
  99. response.setStatus(HttpServletResponse.SC_BAD_REQUEST);
  100. }
  101. else
  102. {
  103. HttpURLConnection con = null;
  104. try
  105. {
  106. String url = CONFIG.AUTH_SERVICE_URL;
  107. URL obj = new URL(url);
  108. con = (HttpURLConnection) obj.openConnection();
  109. con.setRequestMethod("POST");
  110. con.setRequestProperty("Content-Type", "application/x-www-form-urlencoded");
  111. boolean jsonResponse = false;
  112. StringBuilder urlParameters = new StringBuilder();
  113. urlParameters.append("client_id=");
  114. urlParameters.append(client);
  115. urlParameters.append("&redirect_uri=");
  116. urlParameters.append(redirectUri);
  117. urlParameters.append("&client_secret=");
  118. urlParameters.append(secret);
  119. if (code != null)
  120. {
  121. urlParameters.append("&code=");
  122. urlParameters.append(code);
  123. urlParameters.append("&grant_type=authorization_code");
  124. }
  125. else
  126. {
  127. urlParameters.append("&refresh_token=");
  128. urlParameters.append(refreshToken);
  129. urlParameters.append("&grant_type=refresh_token");
  130. jsonResponse = true;
  131. }
  132. // Send post request
  133. con.setDoOutput(true);
  134. DataOutputStream wr = new DataOutputStream(con.getOutputStream());
  135. wr.writeBytes(urlParameters.toString());
  136. wr.flush();
  137. wr.close();
  138. BufferedReader in = new BufferedReader(
  139. new InputStreamReader(con.getInputStream()));
  140. String inputLine;
  141. StringBuffer authRes = new StringBuffer();
  142. while ((inputLine = in.readLine()) != null)
  143. {
  144. authRes.append(inputLine);
  145. }
  146. in.close();
  147. response.setStatus(con.getResponseCode());
  148. OutputStream out = response.getOutputStream();
  149. PrintWriter writer = new PrintWriter(out);
  150. // Writes JavaScript code
  151. writer.println(processAuthResponse(authRes.toString(), jsonResponse));
  152. writer.flush();
  153. writer.close();
  154. }
  155. catch(IOException e)
  156. {
  157. e.printStackTrace();
  158. StringBuilder details = new StringBuilder("");
  159. if (con != null)
  160. {
  161. try
  162. {
  163. BufferedReader in = new BufferedReader(
  164. new InputStreamReader(con.getErrorStream()));
  165. String inputLine;
  166. while ((inputLine = in.readLine()) != null)
  167. {
  168. System.err.println(inputLine);
  169. details.append(inputLine);
  170. details.append("\n");
  171. }
  172. in.close();
  173. }
  174. catch (Exception e2)
  175. {
  176. // Ignore
  177. }
  178. }
  179. if (e.getMessage() != null && e.getMessage().contains("401"))
  180. {
  181. response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
  182. }
  183. else
  184. {
  185. response.setStatus(HttpServletResponse.SC_INTERNAL_SERVER_ERROR);
  186. }
  187. if (DEBUG)
  188. {
  189. OutputStream out = response.getOutputStream();
  190. PrintWriter writer = new PrintWriter(out);
  191. e.printStackTrace(writer);
  192. writer.println(details.toString());
  193. writer.flush();
  194. writer.close();
  195. }
  196. }
  197. }
  198. }
  199. catch (Exception e)
  200. {
  201. response.setStatus(HttpServletResponse.SC_INTERNAL_SERVER_ERROR);
  202. }
  203. }
  204. }