Many resources are needed to download a project. Please understand that we have to compensate our server costs. Thank you in advance. Project price only 1 $
You can buy this project and download/modify it how often you want.
/*
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
*
* Copyright (c) 1997-2013 Oracle and/or its affiliates. All rights reserved.
*
* The contents of this file are subject to the terms of either the GNU
* General Public License Version 2 only ("GPL") or the Common Development
* and Distribution License("CDDL") (collectively, the "License"). You
* may not use this file except in compliance with the License. You can
* obtain a copy of the License at
* https://glassfish.dev.java.net/public/CDDL+GPL_1_1.html
* or packager/legal/LICENSE.txt. See the License for the specific
* language governing permissions and limitations under the License.
*
* When distributing the software, include this License Header Notice in each
* file and include the License file at packager/legal/LICENSE.txt.
*
* GPL Classpath Exception:
* Oracle designates this particular file as subject to the "Classpath"
* exception as provided by Oracle in the GPL Version 2 section of the License
* file that accompanied this code.
*
* Modifications:
* If applicable, add the following below the License Header, with the fields
* enclosed by brackets [] replaced by your own identifying information:
* "Portions Copyright [year] [name of copyright owner]"
*
* Contributor(s):
* If you wish your version of this file to be governed by only the CDDL or
* only the GPL Version 2, indicate your decision by adding "[Contributor]
* elects to include this software in this distribution under the [CDDL or GPL
* Version 2] license." If you don't indicate a single choice of license, a
* recipient has the option to distribute your version of this file under
* either the CDDL, the GPL Version 2 or to extend the choice of license to
* its licensees as provided above. However, if you add GPL Version 2 code
* and therefore, elected the GPL Version 2 license, then the option applies
* only if the new code is made subject to such option by the copyright
* holder.
*/
// Portions Copyright [2018-2021] [Payara Foundation and/or its affiliates]
package com.sun.enterprise.security;
import static com.sun.enterprise.security.SecurityLoggerInfo.defaultSecurityContextError;
import static com.sun.enterprise.security.SecurityLoggerInfo.defaultUserLoginError;
import static com.sun.enterprise.security.SecurityLoggerInfo.nullSubjectWarning;
import static com.sun.enterprise.security.SecurityLoggerInfo.securityContextNotChangedError;
import static com.sun.enterprise.security.SecurityLoggerInfo.securityContextPermissionError;
import static com.sun.enterprise.security.SecurityLoggerInfo.securityContextUnexpectedError;
import static com.sun.enterprise.security.common.AppservAccessController.doPrivileged;
import static com.sun.enterprise.security.common.AppservAccessController.privileged;
import static java.util.logging.Level.SEVERE;
import java.security.AccessController;
import java.security.Principal;
import java.security.PrivilegedAction;
import java.security.PrivilegedExceptionAction;
import java.util.Iterator;
import java.util.Set;
import java.util.logging.Logger;
import javax.security.auth.AuthPermission;
import javax.security.auth.Subject;
import org.glassfish.api.admin.ServerEnvironment;
import org.glassfish.hk2.api.PerLookup;
import org.glassfish.internal.api.Globals;
import org.glassfish.security.common.PrincipalImpl;
import org.jvnet.hk2.annotations.Service;
import com.sun.enterprise.config.serverbeans.SecurityService;
import com.sun.enterprise.security.auth.login.DistinguishedPrincipalCredential;
import com.sun.enterprise.security.common.AbstractSecurityContext;
import com.sun.enterprise.security.common.AppservAccessController;
import com.sun.enterprise.security.integration.AppServSecurityContext;
/**
* This class that extends AbstractSecurityContext that gets stored in Thread Local Storage. If the current thread
* creates child threads, the SecurityContext stored in the current thread is automatically propagated to the child
* threads.
*
* This class is used on the server side to represent the security context.
*
* @see java.lang.ThreadLocal
* @see java.lang.InheritableThreadLocal
*
* @author Harish Prabandham
* @author Harpreet Singh
*/
@Service
@PerLookup
public class SecurityContext extends AbstractSecurityContext {
private static final long serialVersionUID = -1061816185561416857L;
private static final Logger LOGGER = SecurityLoggerInfo.getLogger();
private static InheritableThreadLocal currentSecurityContext = new InheritableThreadLocal<>();
private static SecurityContext defaultSecurityContext = generateDefaultSecurityContext();
private static AuthPermission doAsPrivilegedPerm = new AuthPermission("doAsPrivileged");
// Did the client log in as or did the server generate the context
private boolean serverGeneratedCredentials;
// ### Static public methods
/**
* Initialize the SecurityContext and handle the unauthenticated principal case
*/
public static SecurityContext init() {
SecurityContext securityContext = currentSecurityContext.get();
if (securityContext == null) { // there is no current security context...
securityContext = defaultSecurityContext;
}
return securityContext;
}
public static SecurityContext getDefaultSecurityContext() {
// Unauthenticated Security Context.
return defaultSecurityContext;
}
public static Subject getDefaultSubject() {
// Subject of unauthenticated Security Context.
return defaultSecurityContext.subject;
}
// Get caller principal of unauthenticated Security Context
public static Principal getDefaultCallerPrincipal() {
synchronized (SecurityContext.class) {
if (defaultSecurityContext.callerPrincipal == null) {
String guestUser = null;
try {
guestUser = (String) doPrivileged(new PrivilegedExceptionAction