
org.kawanfw.sql.servlet.MetadataQueryActionManager Maven / Gradle / Ivy
/*
* Copyright (c)2022 KawanSoft S.A.S. All rights reserved.
*
* Use of this software is governed by the Business Source License included
* in the LICENSE.TXT file in the project's root directory.
*
* Change Date: 2026-11-01
*
* On the date above, in accordance with the Business Source License, use
* of this software will be governed by version 2.0 of the Apache License.
*/
package org.kawanfw.sql.servlet;
import java.io.FileNotFoundException;
import java.io.IOException;
import java.io.OutputStream;
import java.sql.Connection;
import java.sql.SQLException;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.HashSet;
import java.util.LinkedHashSet;
import java.util.List;
import java.util.Map;
import java.util.Set;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import org.apache.commons.lang3.exception.ExceptionUtils;
import org.kawanfw.sql.api.server.SqlEvent;
import org.kawanfw.sql.api.server.SqlEventWrapper;
import org.kawanfw.sql.api.server.firewall.SqlFirewallManager;
import org.kawanfw.sql.api.util.firewall.SqlFirewallTriggerWrapper;
import org.kawanfw.sql.metadata.AceQLMetaData;
import org.kawanfw.sql.metadata.JdbcDatabaseMetaData;
import org.kawanfw.sql.metadata.Table;
import org.kawanfw.sql.metadata.dto.JdbcDatabaseMetaDataDto;
import org.kawanfw.sql.metadata.dto.TableDto;
import org.kawanfw.sql.metadata.dto.TableNamesDto;
import org.kawanfw.sql.metadata.util.GsonWsUtil;
import org.kawanfw.sql.servlet.connection.RollbackUtil;
import org.kawanfw.sql.servlet.sql.ServerStatementUtil;
import org.kawanfw.sql.servlet.sql.json_return.JsonErrorReturn;
import org.kawanfw.sql.servlet.sql.json_return.JsonSecurityMessage;
import org.kawanfw.sql.servlet.util.healthcheck.HealthCheckInfoDto;
import org.kawanfw.sql.util.IpUtil;
/**
* Execute the metadata query asked by user.
*
* @author Nicolas de Pomereu
*/
public class MetadataQueryActionManager {
private HttpServletRequest request = null;
private HttpServletResponse response = null;
private Connection connection = null;
Set sqlFirewallManagers = new LinkedHashSet<>();
private OutputStream out = null;
public MetadataQueryActionManager(HttpServletRequest request, HttpServletResponse response, OutputStream out,
Set sqlFirewallManagers, Connection connection) {
super();
this.request = request;
this.response = response;
this.out = out;
this.sqlFirewallManagers = sqlFirewallManagers;
this.connection = connection;
}
public void execute() throws SQLException, IOException {
try {
executeInTryCatch(out);
} catch (SecurityException e) {
RollbackUtil.rollback(connection);
JsonErrorReturn errorReturn = new JsonErrorReturn(response, HttpServletResponse.SC_FORBIDDEN,
JsonErrorReturn.ERROR_ACEQL_UNAUTHORIZED, e.getMessage());
ServerSqlManager.writeLine(out, errorReturn.build());
} catch (SQLException e) {
RollbackUtil.rollback(connection);
JsonErrorReturn errorReturn = new JsonErrorReturn(response, HttpServletResponse.SC_BAD_REQUEST,
JsonErrorReturn.ERROR_JDBC_ERROR, e.getMessage());
ServerSqlManager.writeLine(out, errorReturn.build());
} catch (Exception e) {
RollbackUtil.rollback(connection);
JsonErrorReturn errorReturn = new JsonErrorReturn(response, HttpServletResponse.SC_INTERNAL_SERVER_ERROR,
JsonErrorReturn.ERROR_ACEQL_FAILURE, e.getMessage(), ExceptionUtils.getStackTrace(e));
ServerSqlManager.writeLine(out, errorReturn.build());
}
}
/**
* @param out
* @throws SQLException
* @throws IOException
* @throws SecurityException
* @throws FileNotFoundException
* @throws IllegalArgumentException
*/
private void executeInTryCatch(OutputStream out)
throws SQLException, IOException, SecurityException, FileNotFoundException, IllegalArgumentException {
AceQLMetaData aceQLMetaData = new AceQLMetaData(connection);
String action = request.getParameter(HttpParameter.ACTION);
String username = request.getParameter(HttpParameter.USERNAME);
String database = request.getParameter(HttpParameter.DATABASE);
boolean allow = true;
String sql = "";
for (SqlFirewallManager sqlFirewallManager : sqlFirewallManagers) {
allow = sqlFirewallManager.allowMetadataQuery(username, database, connection);
if (!allow) {
String ipAddress = IpUtil.getRemoteAddr(request);
List
© 2015 - 2025 Weber Informatics LLC | Privacy Policy