@Nonnull @Override public CanonicalHttpRequest getCanonicalHttpRequest() { return new CanonicalHttpServletRequest(request); } }
public CanonicalHttpUriRequest(final String method, final String path, final String contextPath, final Map<String, String[]> parameterMap) { this.method = checkMethod(method); String contextPathToRemove = null == contextPath || "/".equals(contextPath) ? "" : contextPath; this.relativePath = StringUtils.defaultIfBlank(StringUtils.removeEnd(StringUtils.removeStart(path, contextPathToRemove), "/"), "/"); this.parameterMap = parameterMap; }
private static StringBuilder appendTo(StringBuilder appendable, Iterable<?> parts, CharSequence separator) { Iterator<?> iterator = parts.iterator(); if (iterator.hasNext()) { appendable.append(toString(iterator.next())); while (iterator.hasNext()) { appendable.append(separator); appendable.append(toString(iterator.next())); } } return appendable; }
public static String generateJwtSignature(HttpMethod httpMethod, URI uri, String addonKey, String secret, String contextPath, String subject) throws UnsupportedEncodingException, NoSuchAlgorithmException { JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); JwtWriter jwtWriter = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, secret); // Parse param values and build a map final List<NameValuePair> rawParams = URLEncodedUtils.parse(uri, "UTF-8"); final ImmutableMultimap.Builder<String, String> builder = ImmutableMultimap.builder(); for (NameValuePair rawParam : rawParams) { builder.put(rawParam.getName(), rawParam.getValue()); } final ImmutableMap.Builder<String, String[]> paramsMap = ImmutableMap.builder(); for (Map.Entry<String, Collection<String>> stringCollectionEntry : builder.build().asMap().entrySet()) { final Collection<String> collection = stringCollectionEntry.getValue(); paramsMap.put(stringCollectionEntry.getKey(), collection.toArray(new String[collection.size()])); } final JwtJsonBuilder jsonBuilder = new JsonSmartJwtJsonBuilder() .issuer(addonKey) .queryHash(HttpRequestCanonicalizer.computeCanonicalRequestHash(new CanonicalHttpUriRequest(httpMethod.name(), uri.getPath(), URI.create(contextPath).getPath(), paramsMap.build()))); if (null != subject) { jsonBuilder.subject(subject); } return jwtWriter.jsonToJwt(jsonBuilder.build()); } }
public static String toVerboseString(CanonicalHttpRequest request) { return new ToStringBuilder(request, ToStringStyle.SHORT_PREFIX_STYLE) .append("method", request.getMethod()) .append("relativePath", request.getRelativePath()) .append("parameterMap", mapToString(request.getParameterMap())) .toString(); }
private static String mapToString(Map<String, String[]> parameterMap) { StringBuilder sb = new StringBuilder() .append('['); for (Map.Entry<String, String[]> entry : parameterMap.entrySet()) { sb.append(entry.getKey()).append(" -> "); String[] value = entry.getValue(); if (value != null) { sb.append("("); appendTo(sb, Arrays.asList(value), ","); sb.append(")"); } sb.append(','); // I know being lazy } return sb.append(']') .toString(); }
private Jwt verifyJwt(String jwtString, REQ request) throws JwtParseException, JwtVerificationException, JwtIssuerLacksSharedSecretException, JwtUnknownIssuerException, IOException, NoSuchAlgorithmException { CanonicalHttpRequest canonicalHttpRequest = jwtExtractor.getCanonicalHttpRequest(request); log.debug("Canonical request is: {}", CanonicalRequestUtil.toVerboseString(canonicalHttpRequest)); return verifyJwt(jwtString, JwtClaimVerifiersBuilder.build(canonicalHttpRequest)); }
public static String generateJwtSignature(HttpMethod httpMethod, URI uri, String addonKey, String secret, String contextPath, String subject) throws UnsupportedEncodingException, NoSuchAlgorithmException { JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); JwtWriter jwtWriter = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, secret); // Parse param values and build a map final List<NameValuePair> rawParams = URLEncodedUtils.parse(uri, "UTF-8"); final ImmutableMultimap.Builder<String, String> builder = ImmutableMultimap.builder(); for (NameValuePair rawParam : rawParams) { builder.put(rawParam.getName(), rawParam.getValue()); } final ImmutableMap.Builder<String, String[]> paramsMap = ImmutableMap.builder(); for (Map.Entry<String, Collection<String>> stringCollectionEntry : builder.build().asMap().entrySet()) { final Collection<String> collection = stringCollectionEntry.getValue(); paramsMap.put(stringCollectionEntry.getKey(), collection.toArray(new String[collection.size()])); } final JwtJsonBuilder jsonBuilder = new JsonSmartJwtJsonBuilder() .issuer(addonKey) .queryHash(HttpRequestCanonicalizer.computeCanonicalRequestHash(new CanonicalHttpUriRequest(httpMethod.name(), uri.getPath(), URI.create(contextPath).getPath(), paramsMap.build()))); if (null != subject) { jsonBuilder.subject(subject); } return jwtWriter.jsonToJwt(jsonBuilder.build()); } }
public String encodeJwt(HttpMethod httpMethod, URI targetPath, URI addonBaseUrl, Map<String, String[]> params, String issuerId, String secret, Optional<UserProfile> user) { checkArgument(null != httpMethod, "HttpMethod argument cannot be null"); checkArgument(null != targetPath, "URI argument cannot be null"); checkArgument(null != addonBaseUrl, "base URI argument cannot be null"); checkArgument(null != secret, "secret argument cannot be null"); final long currentTime = TimeUtil.currentTimeSeconds(); JwtJsonBuilder jsonBuilder = jwtBuilderFactory.jsonBuilder() .issuedAt(currentTime) .expirationTime(currentTime + JWT_EXPIRY_WINDOW_SECONDS) .issuer(issuerId); Map<String, String[]> completeParams = params; try { if (!StringUtils.isEmpty(targetPath.getQuery())) { completeParams = new HashMap<>(params); completeParams.putAll(constructParameterMap(targetPath)); } CanonicalHttpUriRequest request = new CanonicalHttpUriRequest(httpMethod.toString(), extractRelativePath(targetPath, addonBaseUrl), "", completeParams); log.debug("Canonical request is: " + HttpRequestCanonicalizer.canonicalize(request)); JwtClaimsBuilder.appendHttpRequestClaims(jsonBuilder, request); } catch (UnsupportedEncodingException | NoSuchAlgorithmException e) { throw new RuntimeException(e); } JwtUserContextBuilder.addUserContextObject(jsonBuilder, user); return jwtService.issueJwt(jsonBuilder.build(), secret); }
public String encodeJwt(HttpMethod httpMethod, URI targetPath, URI addonBaseUrl, Map<String, String[]> params, String issuerId, String secret, Optional<UserProfile> user) { checkArgument(null != httpMethod, "HttpMethod argument cannot be null"); checkArgument(null != targetPath, "URI argument cannot be null"); checkArgument(null != addonBaseUrl, "base URI argument cannot be null"); checkArgument(null != secret, "secret argument cannot be null"); final long currentTime = TimeUtil.currentTimeSeconds(); JwtJsonBuilder jsonBuilder = jwtBuilderFactory.jsonBuilder() .issuedAt(currentTime) .expirationTime(currentTime + JWT_EXPIRY_WINDOW_SECONDS) .issuer(issuerId); Map<String, String[]> completeParams = params; try { if (!StringUtils.isEmpty(targetPath.getQuery())) { completeParams = new HashMap<>(params); completeParams.putAll(constructParameterMap(targetPath)); } CanonicalHttpUriRequest request = new CanonicalHttpUriRequest(httpMethod.toString(), extractRelativePath(targetPath, addonBaseUrl), "", completeParams); log.debug("Canonical request is: " + HttpRequestCanonicalizer.canonicalize(request)); JwtClaimsBuilder.appendHttpRequestClaims(jsonBuilder, request); } catch (UnsupportedEncodingException | NoSuchAlgorithmException e) { throw new RuntimeException(e); } JwtUserContextBuilder.addUserContextObject(jsonBuilder, user); return jwtService.issueJwt(jsonBuilder.build(), secret); }
@Nonnull public static String generateJwtToken(TenantContext tenantContext, HttpMethod httpMethod, final URL url) throws UnsupportedEncodingException { final long issuedAt = System.currentTimeMillis() / 1000L; final long expiresAt = issuedAt + 180L; JwtJsonBuilder jwtBuilder = new JsonSmartJwtJsonBuilder() .issuedAt(issuedAt) .expirationTime(expiresAt) .issuer(tenantContext.getKey()); CanonicalHttpUriRequest canonical = new CanonicalHttpUriRequest(httpMethod.toString(), URLUtil.buildPath(url), "/", //Apparently no context is required so skip it. URLUtil.buildQueryValueMap(url)); try { JwtClaimsBuilder.appendHttpRequestClaims(jwtBuilder, canonical); } catch (UnsupportedEncodingException | NoSuchAlgorithmException e) { log.error("Failed to append HTTP request claims", e); } JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); String jwtbuilt = jwtBuilder.build(); String jwtToken = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, tenantContext.getSharedSecret()).jsonToJwt(jwtbuilt); return jwtToken; } }