Added: cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationEntryPoint.java URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationEntryPoint.java?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationEntryPoint.java (added) +++ cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationEntryPoint.java Tue Mar 12 21:07:21 2013 @@ -0,0 +1,167 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.spring.web; + +import java.io.IOException; + +import javax.servlet.ServletException; +import javax.servlet.ServletRequest; +import javax.servlet.ServletResponse; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.apache.cxf.fediz.core.FederationProcessor; +import org.apache.cxf.fediz.core.FederationProcessorImpl; +import org.apache.cxf.fediz.core.config.FederationContext; +import org.apache.cxf.fediz.core.exception.ProcessingException; +import org.apache.cxf.fediz.spring.FederationConfig; + +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; + +import org.springframework.beans.BeansException; +import org.springframework.beans.factory.InitializingBean; +import org.springframework.context.ApplicationContext; +import org.springframework.context.ApplicationContextAware; +import org.springframework.security.AuthenticationException; +import org.springframework.security.ui.AuthenticationEntryPoint; +import org.springframework.util.Assert; + + +/** + * Used by the <code>ExceptionTranslationFilter</code> to commence authentication via the + * WS-Federation protocol. + * <p> + * The user's browser will be redirected to the IDP. + * + */ +public class FederationAuthenticationEntryPoint implements AuthenticationEntryPoint, + InitializingBean, ApplicationContextAware { + + private static final Logger LOG = LoggerFactory.getLogger(FederationAuthenticationEntryPoint.class); + + private ApplicationContext appContext; + private FederationConfig federationConfig; + //private String servletContext; + + public FederationConfig getFederationConfig() { + return federationConfig; + } + + public void setFederationConfig(FederationConfig federationConfig) { + this.federationConfig = federationConfig; + } + + public void afterPropertiesSet() throws Exception { + Assert.notNull(this.appContext, "ApplicationContext cannot be null."); + Assert.notNull(this.federationConfig, "FederationConfig cannot be null."); + } + + public final void commence(final HttpServletRequest servletRequest, final HttpServletResponse response, + final AuthenticationException authenticationException) throws IOException, ServletException { + + String redirectUrl = null; + FederationContext fedContext = federationConfig.getFederationContext(); + if (LOG.isDebugEnabled()) { + LOG.debug("Federation context: " + fedContext); + } + try { + FederationProcessor wfProc = new FederationProcessorImpl(); + redirectUrl = wfProc.createSignInRequest(servletRequest, fedContext); + if (redirectUrl == null) { + LOG.warn("Failed to create SignInRequest."); + response.sendError( + HttpServletResponse.SC_INTERNAL_SERVER_ERROR, "Failed to create SignInRequest."); + } + } catch (ProcessingException ex) { + System.err.println("Failed to create SignInRequest: " + ex.getMessage()); + LOG.warn("Failed to create SignInRequest: " + ex.getMessage()); + response.sendError( + HttpServletResponse.SC_INTERNAL_SERVER_ERROR, "Failed to create SignInRequest."); + } + + preCommence(servletRequest, response); + if (LOG.isInfoEnabled()) { + LOG.info("Redirecting to IDP: " + redirectUrl); + } + response.sendRedirect(redirectUrl); + } + + + /** + * Template method for you to do your own pre-processing before the redirect occurs. + * + * @param request the HttpServletRequest + * @param response the HttpServletResponse + */ + protected void preCommence(final HttpServletRequest request, final HttpServletResponse response) { + + } + + @Override + public void setApplicationContext(ApplicationContext applicationContext) throws BeansException { + this.appContext = applicationContext; + } + + @Override + public void commence(ServletRequest request, ServletResponse response, + AuthenticationException authException) throws IOException, ServletException { + + HttpServletRequest hrequest = (HttpServletRequest)request; + HttpServletResponse hresponse = (HttpServletResponse)response; + String redirectUrl = null; + FederationContext fedContext = federationConfig.getFederationContext(); + if (LOG.isDebugEnabled()) { + LOG.debug("Federation context: " + fedContext); + } + try { + FederationProcessor wfProc = new FederationProcessorImpl(); + redirectUrl = wfProc.createSignInRequest(hrequest, fedContext); + if (redirectUrl == null) { + LOG.warn("Failed to create SignInRequest."); + hresponse.sendError( + HttpServletResponse.SC_INTERNAL_SERVER_ERROR, "Failed to create SignInRequest."); + } + } catch (ProcessingException ex) { + System.err.println("Failed to create SignInRequest: " + ex.getMessage()); + LOG.warn("Failed to create SignInRequest: " + ex.getMessage()); + hresponse.sendError( + HttpServletResponse.SC_INTERNAL_SERVER_ERROR, "Failed to create SignInRequest."); + } + + preCommence(hrequest, hresponse); + if (LOG.isInfoEnabled()) { + LOG.info("Redirecting to IDP: " + redirectUrl); + } + hresponse.sendRedirect(redirectUrl); + + } + + /* + public void setServletContext(String servletContext) { + this.servletContext = servletContext; + } + + public String getServletContext() { + return servletContext; + } + */ + +}
Added: cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationFilter.java URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationFilter.java?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationFilter.java (added) +++ cxf/fediz/trunk/plugins/spring2/src/main/java/org/apache/cxf/fediz/spring/web/FederationAuthenticationFilter.java Tue Mar 12 21:07:21 2013 @@ -0,0 +1,81 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.spring.web; + +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.apache.cxf.fediz.core.FederationRequest; + +import org.springframework.security.Authentication; +import org.springframework.security.AuthenticationException; +import org.springframework.security.providers.UsernamePasswordAuthenticationToken; +import org.springframework.security.ui.AbstractProcessingFilter; +import org.springframework.security.ui.FilterChainOrder; +//import org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler; + + +public class FederationAuthenticationFilter extends AbstractProcessingFilter { + + public FederationAuthenticationFilter() { + super(); + //setAuthenticationFailureHandler(new SimpleUrlAuthenticationFailureHandler()); + } + + /** + * + */ + @Override + protected boolean requiresAuthentication(final HttpServletRequest request, final HttpServletResponse response) { + final boolean result = request.getRequestURI().contains(getFilterProcessesUrl()); + + if (logger.isDebugEnabled()) { + logger.debug("requiresAuthentication = " + result); + } + return result; + } + + @Override + public int getOrder() { + return FilterChainOrder.BASIC_PROCESSING_FILTER; + } + + @Override + public Authentication attemptAuthentication(HttpServletRequest request) throws AuthenticationException { + String wa = request.getParameter("wa"); + String wresult = request.getParameter("wresult"); + FederationRequest wfReq = new FederationRequest(); + wfReq.setWa(wa); + wfReq.setWresult(wresult); + + final UsernamePasswordAuthenticationToken authRequest = new UsernamePasswordAuthenticationToken(null, wfReq); + + authRequest.setDetails(authenticationDetailsSource.buildDetails(request)); + + return this.getAuthenticationManager().authenticate(authRequest); + } + + @Override + public String getDefaultFilterProcessesUrl() { + return "/j_spring_fediz_security_check"; + } + + +} \ No newline at end of file Added: cxf/fediz/trunk/plugins/spring2/src/main/resources/org/apache/cxf/fediz/spring/messages.properties URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/plugins/spring2/src/main/resources/org/apache/cxf/fediz/spring/messages.properties?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/plugins/spring2/src/main/resources/org/apache/cxf/fediz/spring/messages.properties (added) +++ cxf/fediz/trunk/plugins/spring2/src/main/resources/org/apache/cxf/fediz/spring/messages.properties Tue Mar 12 21:07:21 2013 @@ -0,0 +1,2 @@ +FederationAuthenticationProvider.incorrectKey=The presented FederationAuthenticationToken does not contain the expected key +FederationAuthenticationProvider.noSignInRequest=Failed to get SignIn request Modified: cxf/fediz/trunk/systests/pom.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/pom.xml?rev=1455711&r1=1455710&r2=1455711&view=diff ============================================================================== --- cxf/fediz/trunk/systests/pom.xml (original) +++ cxf/fediz/trunk/systests/pom.xml Tue Mar 12 21:07:21 2013 @@ -34,6 +34,7 @@ <module>simpleWebapp</module> <module>springPreauthWebapp</module> <module>springWebapp</module> + <module>spring2Webapp</module> <module>jetty8</module> <module>tomcat7</module> <module>spring</module> Modified: cxf/fediz/trunk/systests/spring/pom.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring/pom.xml?rev=1455711&r1=1455710&r2=1455711&view=diff ============================================================================== --- cxf/fediz/trunk/systests/spring/pom.xml (original) +++ cxf/fediz/trunk/systests/spring/pom.xml Tue Mar 12 21:07:21 2013 @@ -151,7 +151,14 @@ <version>${project.version}</version> <type>war</type> <overWrite>true</overWrite> - </artifactItem> + </artifactItem> + <artifactItem> + <groupId>org.apache.cxf.fediz.systests</groupId> + <artifactId>systests-spring2Webapp</artifactId> + <version>${project.version}</version> + <type>war</type> + <overWrite>true</overWrite> + </artifactItem> </artifactItems> <outputAbsoluteArtifactFilename>true</outputAbsoluteArtifactFilename> <outputDirectory>target</outputDirectory> Added: cxf/fediz/trunk/systests/spring/src/test/java/org/apache/cxf/fediz/integrationtests/Spring2Test.java URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring/src/test/java/org/apache/cxf/fediz/integrationtests/Spring2Test.java?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring/src/test/java/org/apache/cxf/fediz/integrationtests/Spring2Test.java (added) +++ cxf/fediz/trunk/systests/spring/src/test/java/org/apache/cxf/fediz/integrationtests/Spring2Test.java Tue Mar 12 21:07:21 2013 @@ -0,0 +1,76 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.integrationtests; + + +import org.junit.AfterClass; +import org.junit.Assert; +import org.junit.BeforeClass; + + +public class Spring2Test extends AbstractTests { + + static String idpHttpsPort; + static String rpHttpsPort; + + @BeforeClass + public static void init() { + System.setProperty("org.apache.commons.logging.Log", "org.apache.commons.logging.impl.SimpleLog"); + + System.setProperty("org.apache.commons.logging.simplelog.showdatetime", "true"); + + System.setProperty("org.apache.commons.logging.simplelog.log.httpclient.wire", "debug"); + + System.setProperty("org.apache.commons.logging.simplelog.log.org.apache.commons.httpclient", "debug"); + + idpHttpsPort = System.getProperty("idp.https.port"); + Assert.assertNotNull("Property 'idp.https.port' null", idpHttpsPort); + rpHttpsPort = System.getProperty("rp.https.port"); + Assert.assertNotNull("Property 'rp.https.port' null", rpHttpsPort); + + JettyUtils.initIdpServer(); + JettyUtils.startIdpServer(); + JettyUtils.initRpServer(); + JettyUtils.startRpServer(); + } + + @AfterClass + public static void cleanup() { + JettyUtils.stopIdpServer(); + JettyUtils.stopRpServer(); + } + + @Override + public String getIdpHttpsPort() { + return idpHttpsPort; + } + + @Override + public String getRpHttpsPort() { + return rpHttpsPort; + } + + @Override + public String getServletContextName() { + return "fedizhelloworld_spring2"; + } + + +} Modified: cxf/fediz/trunk/systests/spring/src/test/resources/fediz_config.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring/src/test/resources/fediz_config.xml?rev=1455711&r1=1455710&r2=1455711&view=diff ============================================================================== --- cxf/fediz/trunk/systests/spring/src/test/resources/fediz_config.xml (original) +++ cxf/fediz/trunk/systests/spring/src/test/resources/fediz_config.xml Tue Mar 12 21:07:21 2013 @@ -35,5 +35,36 @@ </claimTypesRequested> </protocol> </contextConfig> + <contextConfig name="/fedizhelloworld_spring2"> + <audienceUris> + <audienceItem>urn:org:apache:cxf:fediz:fedizhelloworld</audienceItem> + </audienceUris> + <certificateStores> + <trustManager> + <keyStore file="stsstore.jks" password="stsspass" type="JKS" /> + </trustManager> + </certificateStores> + <trustedIssuers> + <issuer subject=".*CN=www.sts.com.*" certificateValidation="ChainTrust" + name="DoubleItSTSIssuer" /> + </trustedIssuers> + <maximumClockSkew>1000</maximumClockSkew> + <protocol xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:type="federationProtocolType" version="1.0.0"> + <realm>urn:org:apache:cxf:fediz:fedizhelloworld</realm> + <issuer>https://localhost:${idp.https.port}/fediz-idp/</issuer> + <roleDelimiter>,</roleDelimiter> + <roleURI>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/role</roleURI> + <reply>/j_spring_fediz_security_check</reply> + <!--<authenticationType type="String">some auth type</authenticationType>--> + <!--<homeRealm type="Class">org.apache.fediz.realm.MyHomeRealm</homeRealm>--> + <!--<freshness>0</freshness>--> + <!--<reply>reply value</reply>--> + <!--<request>REQUEST</request>--> + <claimTypesRequested> + <claimType type="a particular claim type" optional="true" /> + </claimTypesRequested> + </protocol> + </contextConfig> </FedizConfig> Modified: cxf/fediz/trunk/systests/spring/src/test/resources/rp-server.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring/src/test/resources/rp-server.xml?rev=1455711&r1=1455710&r2=1455711&view=diff ============================================================================== --- cxf/fediz/trunk/systests/spring/src/test/resources/rp-server.xml (original) +++ cxf/fediz/trunk/systests/spring/src/test/resources/rp-server.xml Tue Mar 12 21:07:21 2013 @@ -35,7 +35,14 @@ <Set name="war">./target/systests-springWebapp.war</Set> <Set name="throwUnavailableOnStartupException">true</Set> </New> - </Item> + </Item> + <Item> + <New class="org.eclipse.jetty.webapp.WebAppContext"> + <Set name="contextPath">/fedizhelloworld_spring2</Set> + <Set name="war">./target/systests-spring2Webapp.war</Set> + <Set name="throwUnavailableOnStartupException">true</Set> + </New> + </Item> </Array> </Set> </New> Added: cxf/fediz/trunk/systests/spring2Webapp/pom.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/pom.xml?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/pom.xml (added) +++ cxf/fediz/trunk/systests/spring2Webapp/pom.xml Tue Mar 12 21:07:21 2013 @@ -0,0 +1,109 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!-- + Licensed to the Apache Software Foundation (ASF) under one + or more contributor license agreements. See the NOTICE file + distributed with this work for additional information + regarding copyright ownership. The ASF licenses this file + to you under the Apache License, Version 2.0 (the + "License"); you may not use this file except in compliance + with the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, + software distributed under the License is distributed on an + "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + KIND, either express or implied. See the License for the + specific language governing permissions and limitations + under the License. +--> +<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"> + + <modelVersion>4.0.0</modelVersion> + <parent> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>systests</artifactId> + <version>1.1.0-SNAPSHOT</version> + <relativePath>../pom.xml</relativePath> + </parent> + + <groupId>org.apache.cxf.fediz.systests</groupId> + <artifactId>systests-spring2Webapp</artifactId> + <name>Apache Fediz Systests Spring2 Webapp</name> + <packaging>war</packaging> + + <properties> + <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> + <spring.version>2.0.8</spring.version> + </properties> + + <dependencies> + <dependency> + <groupId>javax.servlet</groupId> + <artifactId>servlet-api</artifactId> + <version>${servlet.version}</version> + <scope>provided</scope> + </dependency> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-cxf</artifactId> + <version>${project.version}</version> + </dependency> + <dependency> + <groupId>org.slf4j</groupId> + <artifactId>slf4j-log4j12</artifactId> + <version>${slf4j.version}</version> + </dependency> + <dependency> + <groupId>org.apache.cxf.fediz</groupId> + <artifactId>fediz-spring2</artifactId> + <version>${project.version}</version> + </dependency> + <dependency> + <groupId>org.apache.commons</groupId> + <artifactId>commons-lang3</artifactId> + <version>${commons.lang.version}</version> + </dependency> + <dependency> + <groupId>log4j</groupId> + <artifactId>log4j</artifactId> + <version>${log4j.version}</version> + <exclusions> + <exclusion> + <groupId>javax.mail</groupId> + <artifactId>mail</artifactId> + </exclusion> + <exclusion> + <groupId>javax.jms</groupId> + <artifactId>jms</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jdmk</groupId> + <artifactId>jmxtools</artifactId> + </exclusion> + <exclusion> + <groupId>com.sun.jmx</groupId> + <artifactId>jmxri</artifactId> + </exclusion> + </exclusions> + </dependency> + </dependencies> + + <build> + <plugins> + <plugin><!--for mvn tomcat:deploy/:undeploy/:redeploy --> + <groupId>org.codehaus.mojo</groupId> + <artifactId>tomcat-maven-plugin</artifactId> + <version>1.1</version> + <configuration> + <server>myTomcat</server> + <url>http://localhost:8080/manager/text</url> + <path>/${project.build.finalName}</path> + </configuration> + </plugin> + </plugins> + <!-- Name of the generated WAR file --> + <finalName>fedizhelloworld</finalName> + </build> + +</project> Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/java/org/apache/cxf/fediz/example/FederationServlet.java Tue Mar 12 21:07:21 2013 @@ -0,0 +1,108 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.fediz.example; + +import java.io.IOException; +import java.io.PrintWriter; +import java.security.Principal; +import java.util.Arrays; +import java.util.List; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +import org.w3c.dom.Element; + +import org.apache.cxf.fediz.core.Claim; +import org.apache.cxf.fediz.core.ClaimCollection; +import org.apache.cxf.fediz.cxf.web.SecurityTokenThreadLocal; +import org.apache.cxf.fediz.spring.authentication.FederationAuthenticationToken; + +import org.springframework.security.Authentication; +import org.springframework.security.GrantedAuthority; +import org.springframework.security.context.SecurityContextHolder; + +public class FederationServlet extends HttpServlet { + + /** + * + */ + private static final long serialVersionUID = -9019993850246851112L; + + public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, + IOException { + + response.setContentType("text/html"); + PrintWriter out = response.getWriter(); + + out.println("<html>"); + out.println("<head><title>WS Federation Systests Spring Examples</title></head>"); + out.println("<body>"); + out.println("<p>Request url: " + request.getRequestURL().toString() + "</p>"); + + out.print("<p>userPrincipal="); + Principal p = request.getUserPrincipal(); + if (p != null) { + out.print(p.getName()); + } + out.println("</p>"); + + // Access Spring security context + Authentication auth = SecurityContextHolder.getContext().getAuthentication(); + + if (auth instanceof FederationAuthenticationToken) { + FederationAuthenticationToken fedToken = (FederationAuthenticationToken)auth; + List<String> roleListToCheck = Arrays.asList("Admin", "Manager", "User", "Authenticated"); + + for (String item : roleListToCheck) { + boolean found = false; + for (GrantedAuthority ga : fedToken.getAuthorities()) { + if (ga.getAuthority().toLowerCase().indexOf(item.toLowerCase()) > -1) { + found = true; + break; + } + } + out.println("<p>role:" + item + "=" + (found ? "true" : "false") + "</p>"); + } + + ClaimCollection claims = fedToken.getClaims(); + for (Claim c : claims) { + out.println("<p>" + c.getClaimType().toString() + "=" + c.getValue() + "</p>"); + } + + Element el = fedToken.getLoginToken(); + if (el != null) { + out.println("loginToken=FOUND{FederationPrincipal}<p>"); + } + + el = SecurityTokenThreadLocal.getToken(); + if (el != null) { + out.println("loginToken=FOUND{SecurityTokenThreadLocal}<p>"); + } + + } + + out.println("</body>"); + + } + +} Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/log4j.properties URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/log4j.properties?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/log4j.properties (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/log4j.properties Tue Mar 12 21:07:21 2013 @@ -0,0 +1,16 @@ +# Set root category priority to INFO and its only appender to CONSOLE. +log4j.rootLogger=INFO, CONSOLE +log4j.logger.org.springframework=INFO, CONSOLE +log4j.additivity.org.springframework=false +log4j.logger.org.springframework.security=DEBUG, CONSOLE +log4j.additivity.org.springframework.security=false +log4j.logger.org.apache.cxf.fediz=DEBUG, CONSOLE +log4j.additivity.org.apache.cxf.fediz=false + +# CONSOLE is set to be a ConsoleAppender using a PatternLayout. +log4j.appender.CONSOLE=org.apache.log4j.ConsoleAppender +log4j.appender.CONSOLE.Threshold=DEBUG +log4j.appender.CONSOLE.layout=org.apache.log4j.PatternLayout +log4j.appender.CONSOLE.layout.ConversionPattern=%d [%t] %-5p %c %x - %m%n + + Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/logging.properties URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/logging.properties?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/logging.properties (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/logging.properties Tue Mar 12 21:07:21 2013 @@ -0,0 +1,53 @@ +############################################################ +# Default Logging Configuration File +# +# You can use a different file by specifying a filename +# with the java.util.logging.config.file system property. +# For example java -Djava.util.logging.config.file=myfile +############################################################ + +############################################################ +# Global properties +############################################################ + +# "handlers" specifies a comma separated list of log Handler +# classes. These handlers will be installed during VM startup. +# Note that these classes must be on the system classpath. +# By default we only configure a ConsoleHandler, which will only +# show messages at the WARNING and above levels. +handlers= java.util.logging.ConsoleHandler +#handlers= java.util.logging.FileHandler, java.util.logging.ConsoleHandler + +# Default global logging level. +# This specifies which kinds of events are logged across +# all loggers. For any given facility this global level +# can be overridden by a facility specific level +# Note that the ConsoleHandler also has a separate level +# setting to limit messages printed to the console. +.level= FINEST + +############################################################ +# Handler specific properties. +# Describes specific configuration info for Handlers. +############################################################ + +# default file output is in user's home directory. +java.util.logging.FileHandler.pattern = %h/java%u.log +java.util.logging.FileHandler.limit = 50000 +java.util.logging.FileHandler.count = 1 +java.util.logging.FileHandler.formatter = java.util.logging.XMLFormatter + +# Limit the message that are printed on the console to WARNING and above. +java.util.logging.ConsoleHandler.level = FINEST +java.util.logging.ConsoleHandler.formatter = java.util.logging.SimpleFormatter + + +############################################################ +# Facility specific properties. +# Provides extra control for each logger. +############################################################ + +# For example, set the com.xyz.foo logger to only log SEVERE +# messages: +#com.xyz.foo.level = SEVERE +#org.apache.cxf.fediz.level = FINEST Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/stsstore.jks URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/stsstore.jks?rev=1455711&view=auto ============================================================================== Files cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/stsstore.jks (added) and cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/stsstore.jks Tue Mar 12 21:07:21 2013 differ Propchange: cxf/fediz/trunk/systests/spring2Webapp/src/main/resources/stsstore.jks ------------------------------------------------------------------------------ svn:executable = * Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/applicationContext-security.xml Tue Mar 12 21:07:21 2013 @@ -0,0 +1,70 @@ +<?xml version="1.0" encoding="UTF-8"?> + +<beans xmlns="http://www.springframework.org/schema/beans" + xmlns:sec="http://www.springframework.org/schema/security" + xmlns:p="http://www.springframework.org/schema/p" + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security-2.0.xsd +http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.0.xsd"> + + + <sec:http entry-point-ref="federationEntryPoint"> +<!-- + <sec:intercept-url pattern="/" access="permitAll"/> + <sec:intercept-url pattern="/fediz" access="permitAll"/> + <sec:intercept-url pattern="/index.html" access="permitAll"/> + <sec:intercept-url pattern="/secure/fedservlet" access="isAuthenticated()"/> +--> + <sec:intercept-url pattern="/secure/fedservlet" access="IS_AUTHENTICATED_FULLY"/> + <sec:intercept-url pattern="/secure/manager/**" access="ROLE_MANAGER"/> + <sec:intercept-url pattern="/secure/admin/**" access="ROLE_ADMIN"/> + <sec:intercept-url pattern="/secure/user/**" access="ROLE_USER,ROLE_ADMIN,ROLE_MANAGER"/> + <!--<sec:custom-filter ref="federationFilter" after="BASIC_AUTH_FILTER" />--> + <!--<sec:session-management session-authentication-strategy-ref="sas"/>--> + </sec:http> + + + <sec:authentication-manager alias="authManager"/> + + <bean id="fedizConfig" class="org.apache.cxf.fediz.spring.FederationConfigImpl" init-method="init" + p:configFile="file:./target/test-classes/fediz_config.xml" p:contextName="/fedizhelloworld_spring2" /> + + <bean id="federationEntryPoint" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationEntryPoint" + p:federationConfig-ref="fedizConfig" /> + +<!-- Works without org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy as well --> +<!-- + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager" p:sessionAuthenticationStrategy-ref="sas"> + + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + </bean> + --> + + <bean id="federationFilter" + class="org.apache.cxf.fediz.spring.web.FederationAuthenticationFilter" + p:authenticationManager-ref="authManager" p:defaultTargetUrl="/whatever"> + <sec:custom-filter after="BASIC_PROCESSING_FILTER"/> + <!-- + <property name="authenticationFailureHandler"> + <bean class="org.springframework.security.web.authentication.SimpleUrlAuthenticationFailureHandler" /> + </property> + --> + </bean> + + <bean id="federationAuthProvider" class="org.apache.cxf.fediz.spring.authentication.FederationAuthenticationProvider" + p:federationConfig-ref="fedizConfig"> + <sec:custom-authentication-provider /> + <property name="authenticationUserDetailsService"> + <bean class="org.apache.cxf.fediz.spring.authentication.GrantedAuthoritiesUserDetailsFederationService"/> + </property> + </bean> +<!-- + <bean id="sas" class="org.springframework.security.web.authentication.session.SessionFixationProtectionStrategy" /> +--> +</beans> + Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/web.xml URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/web.xml?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/web.xml (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/WEB-INF/web.xml Tue Mar 12 21:07:21 2013 @@ -0,0 +1,76 @@ +<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://java.sun.com/xml/ns/javaee + http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd" + version="3.0" metadata-complete="true"> + + <description>WS Federation Spring Example</description> + <display-name>WS Federation Spring Example</display-name> + + <filter> + <filter-name>springSecurityFilterChain</filter-name> + <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> + </filter> + + <!-- Optional: Cache the security token in Thread Local Storage --> + <filter> + <filter-name>FederationFilter</filter-name> + <filter-class>org.apache.cxf.fediz.cxf.web.FederationFilter</filter-class> + </filter> + + <filter-mapping> + <filter-name>springSecurityFilterChain</filter-name> + <url-pattern>/*</url-pattern> + </filter-mapping> + + <filter-mapping> + <filter-name>FederationFilter</filter-name> + <url-pattern>/secure/*</url-pattern> + </filter-mapping> + + + <!-- + - Location of the XML file that defines the root application context + - Applied by ContextLoaderListener. + --> + <context-param> + <param-name>contextConfigLocation</param-name> + <param-value> + /WEB-INF/applicationContext-security.xml + </param-value> + </context-param> + + <!-- + - Loads the root application context of this web app at startup. + - The application context is then available via + - WebApplicationContextUtils.getWebApplicationContext(servletContext). + --> + <listener> + <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class> + </listener> + + <servlet> + <servlet-name>FederationServlet</servlet-name> + <servlet-class>org.apache.cxf.fediz.example.FederationServlet</servlet-class> + </servlet> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/admin/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/user/fedservlet</url-pattern> + </servlet-mapping> + + <servlet-mapping> + <servlet-name>FederationServlet</servlet-name> + <url-pattern>/secure/manager/fedservlet</url-pattern> + </servlet-mapping> + +</web-app> Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/index.html URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/index.html?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/index.html (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/index.html Tue Mar 12 21:07:21 2013 @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Hello World</H3> +<P></P> +</BODY></HTML> Added: cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/secure/test.html URL: http://svn.apache.org/viewvc/cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/secure/test.html?rev=1455711&view=auto ============================================================================== --- cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/secure/test.html (added) +++ cxf/fediz/trunk/systests/spring2Webapp/src/main/webapp/secure/test.html Tue Mar 12 21:07:21 2013 @@ -0,0 +1,25 @@ +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> +<HTML><HEAD><TITLE>WS Federation Tomcat Examples</TITLE> +<META http-equiv=Content-Type content="text/html"> +</HEAD> +<BODY> +<P> +<H3>Secure Test</H3> +<P></P> +</BODY></HTML>
