org.restheart.security.handlers.AuthenticationConstraintHandler Maven / Gradle / Ivy
Go to download
Show more of this group Show more artifacts with this name
Show all versions of restheart Show documentation
Show all versions of restheart Show documentation
RESTHeart Core - Core services for RESTHeart
/*-
* ========================LICENSE_START=================================
* restheart-core
* %%
* Copyright (C) 2014 - 2024 SoftInstigate
* %%
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see .
* =========================LICENSE_END==================================
*/
package org.restheart.security.handlers;
import java.util.Set;
import java.util.stream.Collectors;
import org.restheart.exchange.Request;
import org.restheart.handlers.PipelinedHandler;
import org.restheart.plugins.PluginRecord;
import org.restheart.plugins.security.Authorizer;
import org.restheart.plugins.security.Authorizer.TYPE;
import org.restheart.utils.PluginUtils;
import com.google.common.collect.Sets;
import io.undertow.server.HttpServerExchange;
/**
*
* @author Andrea Di Cesare {@literal }
*/
public class AuthenticationConstraintHandler extends PipelinedHandler {
private final Set allowers;
/**
*
* @param next
* @param authorizers
*/
public AuthenticationConstraintHandler(PipelinedHandler next, Set> authorizers) {
super(next);
this.allowers = authorizers == null
? Sets.newHashSet()
: authorizers.stream()
.filter(a -> a.isEnabled())
.filter(a -> a.getInstance() != null)
.map(a -> a.getInstance())
.filter(a -> PluginUtils.authorizerType(a) == TYPE.ALLOWER)
.collect(Collectors.toSet());
}
/**
*
* @param exchange
* @return true if all enabled authorizers of type ALLOWER require authentication
*/
protected boolean isAuthenticationRequired(final HttpServerExchange exchange) {
return this.allowers.isEmpty()
? false
: allowers.stream().allMatch(a -> a.isAuthenticationRequired(Request.of(exchange)));
}
@Override
public void handleRequest(HttpServerExchange exchange) throws Exception {
if (isAuthenticationRequired(exchange)) {
exchange.getSecurityContext().setAuthenticationRequired();
}
next(exchange);
}
}