1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20 package org.apache.wss4j.dom.handler;
21
22 import java.security.Provider;
23 import java.security.cert.Certificate;
24 import java.util.ArrayList;
25 import java.util.Collection;
26 import java.util.LinkedList;
27 import java.util.List;
28 import java.util.Map;
29 import java.util.regex.Pattern;
30
31 import javax.security.auth.callback.CallbackHandler;
32 import javax.xml.namespace.QName;
33
34 import org.apache.wss4j.common.ConfigurationConstants;
35 import org.apache.wss4j.common.EncryptionActionToken;
36 import org.apache.wss4j.common.SignatureActionToken;
37 import org.apache.wss4j.common.bsp.BSPEnforcer;
38 import org.apache.wss4j.common.bsp.BSPRule;
39 import org.apache.wss4j.common.cache.ReplayCache;
40 import org.apache.wss4j.common.crypto.AlgorithmSuite;
41 import org.apache.wss4j.common.crypto.Crypto;
42 import org.apache.wss4j.common.crypto.PasswordEncryptor;
43 import org.apache.wss4j.common.ext.WSSecurityException;
44 import org.apache.wss4j.dom.SOAPConstants;
45 import org.apache.wss4j.dom.WSConstants;
46 import org.apache.wss4j.dom.WSDocInfo;
47 import org.apache.wss4j.dom.engine.WSSConfig;
48 import org.apache.wss4j.dom.message.WSSecHeader;
49 import org.apache.wss4j.dom.validate.Validator;
50 import org.apache.xml.security.encryption.Serializer;
51
52
53
54
55 public class RequestData {
56
57 private Object msgContext;
58 private SOAPConstants soapConstants;
59 private String actor;
60 private String username;
61 private String pwType = WSConstants.PASSWORD_DIGEST;
62 private Crypto sigVerCrypto;
63 private Crypto decCrypto;
64 private SignatureActionToken signatureToken;
65 private EncryptionActionToken encryptionToken;
66 private WSSConfig wssConfig;
67 private List<byte[]> signatureValues = new ArrayList<>();
68 private WSSecHeader secHeader;
69 private int derivedKeyIterations = 1000;
70 private boolean useDerivedKeyForMAC = true;
71 private CallbackHandler callback;
72 private CallbackHandler attachmentCallbackHandler;
73 private boolean enableRevocation;
74 private boolean requireSignedEncryptedDataElements;
75 private ReplayCache timestampReplayCache;
76 private ReplayCache nonceReplayCache;
77 private ReplayCache samlOneTimeUseReplayCache;
78 private Collection<Pattern> subjectDNPatterns = new ArrayList<>();
79 private Collection<Pattern> issuerDNPatterns = new ArrayList<>();
80 private final List<BSPRule> ignoredBSPRules = new LinkedList<>();
81 private boolean appendSignatureAfterTimestamp;
82 private int originalSignatureActionPosition;
83 private AlgorithmSuite algorithmSuite;
84 private AlgorithmSuite samlAlgorithmSuite;
85 private boolean disableBSPEnforcement;
86 private boolean allowRSA15KeyTransportAlgorithm;
87 private int processorNestingDepth;
88 private boolean addUsernameTokenNonce;
89 private boolean addUsernameTokenCreated;
90 private Certificate[] tlsCerts;
91 private PasswordEncryptor passwordEncryptor;
92 private String derivedKeyTokenReference;
93 private boolean use200512Namespace = true;
94 private final List<String> audienceRestrictions = new ArrayList<>();
95 private boolean requireTimestampExpires;
96 private boolean storeBytesInAttachment;
97 private Serializer encryptionSerializer;
98 private WSDocInfo wsDocInfo;
99 private Provider signatureProvider;
100
101
102
103
104
105
106 private boolean addInclusivePrefixes = true;
107
108
109
110
111
112
113 private boolean precisionInMilliSeconds = true;
114
115 private boolean enableSignatureConfirmation;
116
117
118
119
120
121
122
123
124 private boolean timeStampStrict = true;
125
126
127
128
129
130 private String requiredPasswordType;
131
132
133
134
135
136
137 private boolean allowUsernameTokenNoPassword;
138
139
140
141
142
143 private int timeStampTTL = 300;
144
145
146
147
148
149 private int timeStampFutureTTL = 60;
150
151
152
153
154
155 private int utTTL = 300;
156
157
158
159
160
161 private int utFutureTTL = 60;
162
163
164
165
166
167
168
169
170 private boolean handleCustomPasswordTypes;
171
172
173
174
175
176
177
178 private boolean allowNamespaceQualifiedPasswordTypes;
179
180
181
182
183
184
185
186
187
188
189
190
191 private boolean encodePasswords;
192
193
194
195
196
197 private boolean validateSamlSubjectConfirmation = true;
198
199 private boolean expandXopInclude;
200
201 public Object getMsgContext() {
202 return msgContext;
203 }
204
205 public void setMsgContext(Object msgContext) {
206 this.msgContext = msgContext;
207 }
208
209 public SOAPConstants getSoapConstants() {
210 return soapConstants;
211 }
212
213 public void setSoapConstants(SOAPConstants soapConstants) {
214 this.soapConstants = soapConstants;
215 }
216
217 public String getActor() {
218 return actor;
219 }
220
221 public void setActor(String actor) {
222 this.actor = actor;
223 }
224
225 public String getUsername() {
226 return username;
227 }
228
229 public void setUsername(String username) {
230 this.username = username;
231 }
232
233 public String getPwType() {
234 return pwType;
235 }
236
237 public void setPwType(String pwType) {
238 this.pwType = pwType;
239 }
240
241 public Crypto getSigVerCrypto() {
242 return sigVerCrypto;
243 }
244
245 public void setSigVerCrypto(Crypto sigVerCrypto) {
246 this.sigVerCrypto = sigVerCrypto;
247 }
248
249 public Crypto getDecCrypto() {
250 return decCrypto;
251 }
252
253 public void setDecCrypto(Crypto decCrypto) {
254 this.decCrypto = decCrypto;
255 }
256
257
258
259
260 public WSSConfig getWssConfig() {
261 return wssConfig;
262 }
263
264
265
266
267 public void setWssConfig(WSSConfig wssConfig) {
268 this.wssConfig = wssConfig;
269 }
270
271
272
273
274 public List<byte[]> getSignatureValues() {
275 return signatureValues;
276 }
277
278
279
280
281 public WSSecHeader getSecHeader() {
282 return secHeader;
283 }
284
285
286
287
288 public void setSecHeader(WSSecHeader secHeader) {
289 this.secHeader = secHeader;
290 }
291
292
293
294
295
296 public void setDerivedKeyIterations(int iterations) {
297 derivedKeyIterations = iterations;
298 }
299
300
301
302
303
304 public int getDerivedKeyIterations() {
305 return derivedKeyIterations;
306 }
307
308
309
310
311
312 public void setUseDerivedKeyForMAC(boolean useMac) {
313 useDerivedKeyForMAC = useMac;
314 }
315
316
317
318
319
320 public boolean isUseDerivedKeyForMAC() {
321 return useDerivedKeyForMAC;
322 }
323
324
325
326
327
328 public void setEnableRevocation(boolean enableRevocation) {
329 this.enableRevocation = enableRevocation;
330 }
331
332
333
334
335
336 public boolean isRevocationEnabled() {
337 return enableRevocation;
338 }
339
340
341
342
343 public boolean isRequireSignedEncryptedDataElements() {
344 return requireSignedEncryptedDataElements;
345 }
346
347
348
349
350
351
352
353
354
355 public void setRequireSignedEncryptedDataElements(boolean requireSignedEncryptedDataElements) {
356 this.requireSignedEncryptedDataElements = requireSignedEncryptedDataElements;
357 }
358
359
360
361
362
363 public void setCallbackHandler(CallbackHandler cb) {
364 callback = cb;
365 }
366
367
368
369
370
371 public CallbackHandler getCallbackHandler() {
372 return callback;
373 }
374
375 public CallbackHandler getAttachmentCallbackHandler() {
376 return attachmentCallbackHandler;
377 }
378
379 public void setAttachmentCallbackHandler(CallbackHandler attachmentCallbackHandler) {
380 this.attachmentCallbackHandler = attachmentCallbackHandler;
381 }
382
383
384
385
386
387
388
389 public Validator getValidator(QName qName) throws WSSecurityException {
390
391 if (getMsgContext() instanceof Map<?,?>) {
392 @SuppressWarnings("unchecked")
393 Map<QName, Validator> validatorMap =
394 (Map<QName, Validator>)((Map<?,?>)getMsgContext()).get(ConfigurationConstants.VALIDATOR_MAP);
395 if (validatorMap != null && validatorMap.containsKey(qName)) {
396 return validatorMap.get(qName);
397 }
398 }
399 if (wssConfig != null) {
400 return wssConfig.getValidator(qName);
401 }
402 return null;
403 }
404
405
406
407
408 public void setTimestampReplayCache(ReplayCache newCache) {
409 timestampReplayCache = newCache;
410 }
411
412
413
414
415
416 public ReplayCache getTimestampReplayCache() throws WSSecurityException {
417 return timestampReplayCache;
418 }
419
420
421
422
423 public void setNonceReplayCache(ReplayCache newCache) {
424 nonceReplayCache = newCache;
425 }
426
427
428
429
430
431 public ReplayCache getNonceReplayCache() throws WSSecurityException {
432 return nonceReplayCache;
433 }
434
435
436
437
438 public void setSamlOneTimeUseReplayCache(ReplayCache newCache) {
439 samlOneTimeUseReplayCache = newCache;
440 }
441
442
443
444
445
446 public ReplayCache getSamlOneTimeUseReplayCache() throws WSSecurityException {
447 return samlOneTimeUseReplayCache;
448 }
449
450
451
452
453 public void setSubjectCertConstraints(Collection<Pattern> subjectCertConstraints) {
454 if (subjectCertConstraints != null) {
455 subjectDNPatterns.addAll(subjectCertConstraints);
456 }
457 }
458
459
460
461
462 public Collection<Pattern> getSubjectCertConstraints() {
463 return subjectDNPatterns;
464 }
465
466
467
468
469
470 public Collection<Pattern> getIssuerDNPatterns() {
471 return issuerDNPatterns;
472 }
473
474
475
476
477 public void setIssuerDNPatterns(Collection<Pattern> issuerDNPatterns) {
478 this.issuerDNPatterns = issuerDNPatterns;
479 }
480
481
482
483
484 public void setAudienceRestrictions(List<String> audienceRestrictions) {
485 if (audienceRestrictions != null) {
486 this.audienceRestrictions.addAll(audienceRestrictions);
487 }
488 }
489
490
491
492
493 public List<String> getAudienceRestrictions() {
494 return audienceRestrictions;
495 }
496
497 public void setIgnoredBSPRules(List<BSPRule> bspRules) {
498 ignoredBSPRules.clear();
499 ignoredBSPRules.addAll(bspRules);
500 }
501
502 public BSPEnforcer getBSPEnforcer() {
503 if (disableBSPEnforcement) {
504 return new BSPEnforcer(true);
505 }
506 return new BSPEnforcer(ignoredBSPRules);
507 }
508
509 public boolean isAppendSignatureAfterTimestamp() {
510 return appendSignatureAfterTimestamp;
511 }
512
513 public void setAppendSignatureAfterTimestamp(boolean appendSignatureAfterTimestamp) {
514 this.appendSignatureAfterTimestamp = appendSignatureAfterTimestamp;
515 }
516
517 public AlgorithmSuite getAlgorithmSuite() {
518 return algorithmSuite;
519 }
520
521 public void setAlgorithmSuite(AlgorithmSuite algorithmSuite) {
522 this.algorithmSuite = algorithmSuite;
523 }
524
525 public AlgorithmSuite getSamlAlgorithmSuite() {
526 return samlAlgorithmSuite;
527 }
528
529 public void setSamlAlgorithmSuite(AlgorithmSuite samlAlgorithmSuite) {
530 this.samlAlgorithmSuite = samlAlgorithmSuite;
531 }
532
533 public int getOriginalSignatureActionPosition() {
534 return originalSignatureActionPosition;
535 }
536
537 public void setOriginalSignatureActionPosition(int originalSignatureActionPosition) {
538 this.originalSignatureActionPosition = originalSignatureActionPosition;
539 }
540
541 public boolean isDisableBSPEnforcement() {
542 return disableBSPEnforcement;
543 }
544
545 public void setDisableBSPEnforcement(boolean disableBSPEnforcement) {
546 this.disableBSPEnforcement = disableBSPEnforcement;
547 }
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563 public static final int MAXIMUM_PROCESSOR_NESTING_DEPTH = 5;
564
565
566
567
568
569
570
571
572 public void enterNestedToken() throws WSSecurityException {
573 if (processorNestingDepth >= MAXIMUM_PROCESSOR_NESTING_DEPTH) {
574 throw new WSSecurityException(
575 WSSecurityException.ErrorCode.INVALID_SECURITY, "empty",
576 new Object[] {"Tokens are nested more than "
577 + MAXIMUM_PROCESSOR_NESTING_DEPTH + " deep"});
578 }
579 processorNestingDepth++;
580 }
581
582
583
584
585 public void exitNestedToken() {
586 processorNestingDepth--;
587 }
588
589 public boolean isAllowRSA15KeyTransportAlgorithm() {
590 return allowRSA15KeyTransportAlgorithm;
591 }
592
593 public void setAllowRSA15KeyTransportAlgorithm(boolean allowRSA15KeyTransportAlgorithm) {
594 this.allowRSA15KeyTransportAlgorithm = allowRSA15KeyTransportAlgorithm;
595 }
596
597 public Certificate[] getTlsCerts() {
598 return tlsCerts;
599 }
600
601 public void setTlsCerts(Certificate[] tlsCerts) {
602 this.tlsCerts = tlsCerts;
603 }
604
605 public PasswordEncryptor getPasswordEncryptor() {
606 return passwordEncryptor;
607 }
608
609 public void setPasswordEncryptor(PasswordEncryptor passwordEncryptor) {
610 this.passwordEncryptor = passwordEncryptor;
611 }
612
613 public SignatureActionToken getSignatureToken() {
614 return signatureToken;
615 }
616
617 public void setSignatureToken(SignatureActionToken signatureToken) {
618 this.signatureToken = signatureToken;
619 }
620
621 public EncryptionActionToken getEncryptionToken() {
622 return encryptionToken;
623 }
624
625 public void setEncryptionToken(EncryptionActionToken encryptionToken) {
626 this.encryptionToken = encryptionToken;
627 }
628
629 public String getDerivedKeyTokenReference() {
630 return derivedKeyTokenReference;
631 }
632
633 public void setDerivedKeyTokenReference(String derivedKeyTokenReference) {
634 this.derivedKeyTokenReference = derivedKeyTokenReference;
635 }
636
637 public boolean isUse200512Namespace() {
638 return use200512Namespace;
639 }
640
641 public void setUse200512Namespace(boolean use200512Namespace) {
642 this.use200512Namespace = use200512Namespace;
643 }
644
645 public boolean isRequireTimestampExpires() {
646 return requireTimestampExpires;
647 }
648
649 public void setRequireTimestampExpires(boolean requireTimestampExpires) {
650 this.requireTimestampExpires = requireTimestampExpires;
651 }
652
653 public boolean isValidateSamlSubjectConfirmation() {
654 return validateSamlSubjectConfirmation;
655 }
656
657 public void setValidateSamlSubjectConfirmation(boolean validateSamlSubjectConfirmation) {
658 this.validateSamlSubjectConfirmation = validateSamlSubjectConfirmation;
659 }
660
661 public boolean isAllowNamespaceQualifiedPasswordTypes() {
662 return allowNamespaceQualifiedPasswordTypes;
663 }
664
665 public void setAllowNamespaceQualifiedPasswordTypes(boolean allowNamespaceQualifiedPasswordTypes) {
666 this.allowNamespaceQualifiedPasswordTypes = allowNamespaceQualifiedPasswordTypes;
667 }
668
669 public int getUtFutureTTL() {
670 return utFutureTTL;
671 }
672
673 public void setUtFutureTTL(int utFutureTTL) {
674 this.utFutureTTL = utFutureTTL;
675 }
676
677 public boolean isHandleCustomPasswordTypes() {
678 return handleCustomPasswordTypes;
679 }
680
681 public void setHandleCustomPasswordTypes(boolean handleCustomPasswordTypes) {
682 this.handleCustomPasswordTypes = handleCustomPasswordTypes;
683 }
684
685 public int getUtTTL() {
686 return utTTL;
687 }
688
689 public void setUtTTL(int utTTL) {
690 this.utTTL = utTTL;
691 }
692
693 public int getTimeStampTTL() {
694 return timeStampTTL;
695 }
696
697 public void setTimeStampTTL(int timeStampTTL) {
698 this.timeStampTTL = timeStampTTL;
699 }
700
701 public int getTimeStampFutureTTL() {
702 return timeStampFutureTTL;
703 }
704
705 public void setTimeStampFutureTTL(int timeStampFutureTTL) {
706 this.timeStampFutureTTL = timeStampFutureTTL;
707 }
708
709 public boolean isAllowUsernameTokenNoPassword() {
710 return allowUsernameTokenNoPassword;
711 }
712
713 public void setAllowUsernameTokenNoPassword(boolean allowUsernameTokenNoPassword) {
714 this.allowUsernameTokenNoPassword = allowUsernameTokenNoPassword;
715 }
716
717 public boolean isTimeStampStrict() {
718 return timeStampStrict;
719 }
720
721 public void setTimeStampStrict(boolean timeStampStrict) {
722 this.timeStampStrict = timeStampStrict;
723 }
724
725 public boolean isAddInclusivePrefixes() {
726 return addInclusivePrefixes;
727 }
728
729 public void setAddInclusivePrefixes(boolean addInclusivePrefixes) {
730 this.addInclusivePrefixes = addInclusivePrefixes;
731 }
732
733 public boolean isPrecisionInMilliSeconds() {
734 return precisionInMilliSeconds;
735 }
736
737 public void setPrecisionInMilliSeconds(boolean precisionInMilliSeconds) {
738 this.precisionInMilliSeconds = precisionInMilliSeconds;
739 }
740
741 public boolean isEnableSignatureConfirmation() {
742 return enableSignatureConfirmation;
743 }
744
745 public void setEnableSignatureConfirmation(boolean enableSignatureConfirmation) {
746 this.enableSignatureConfirmation = enableSignatureConfirmation;
747 }
748
749 public String getRequiredPasswordType() {
750 return requiredPasswordType;
751 }
752
753 public void setRequiredPasswordType(String requiredPasswordType) {
754 this.requiredPasswordType = requiredPasswordType;
755 }
756
757 public boolean isEncodePasswords() {
758 return encodePasswords;
759 }
760
761 public void setEncodePasswords(boolean encodePasswords) {
762 this.encodePasswords = encodePasswords;
763 }
764
765 public boolean isStoreBytesInAttachment() {
766 return storeBytesInAttachment;
767 }
768
769 public void setStoreBytesInAttachment(boolean storeBytesInAttachment) {
770 this.storeBytesInAttachment = storeBytesInAttachment;
771 }
772
773 public boolean isExpandXopInclude() {
774 return expandXopInclude;
775 }
776
777 public void setExpandXopInclude(boolean expandXopInclude) {
778 this.expandXopInclude = expandXopInclude;
779 }
780
781 public Serializer getEncryptionSerializer() {
782 return encryptionSerializer;
783 }
784
785 public void setEncryptionSerializer(Serializer encryptionSerializer) {
786 this.encryptionSerializer = encryptionSerializer;
787 }
788
789 public boolean isAddUsernameTokenCreated() {
790 return addUsernameTokenCreated;
791 }
792
793 public void setAddUsernameTokenCreated(boolean addUsernameTokenCreated) {
794 this.addUsernameTokenCreated = addUsernameTokenCreated;
795 }
796
797 public boolean isAddUsernameTokenNonce() {
798 return addUsernameTokenNonce;
799 }
800
801 public void setAddUsernameTokenNonce(boolean addUsernameTokenNonce) {
802 this.addUsernameTokenNonce = addUsernameTokenNonce;
803 }
804
805 public WSDocInfo getWsDocInfo() {
806 return wsDocInfo;
807 }
808
809 public void setWsDocInfo(WSDocInfo wsDocInfo) {
810 this.wsDocInfo = wsDocInfo;
811 }
812
813 public Provider getSignatureProvider() {
814 return signatureProvider;
815 }
816
817
818
819
820 public void setSignatureProvider(Provider signatureProvider) {
821 this.signatureProvider = signatureProvider;
822 }
823 }