⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 subjectpip.java

📁 一个完整的XACML工程,学习XACML技术的好例子!
💻 JAVA
字号:
/*
* Copyright (c) 2006, University of Kent
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without 
* modification, are permitted provided that the following conditions are met:
*
* Redistributions of source code must retain the above copyright notice, this 
* list of conditions and the following disclaimer.
* 
* Redistributions in binary form must reproduce the above copyright notice, 
* this list of conditions and the following disclaimer in the documentation 
* and/or other materials provided with the distribution. 
*
* 1. Neither the name of the University of Kent nor the names of its 
* contributors may be used to endorse or promote products derived from this 
* software without specific prior written permission. 
*
* 2. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS  
* IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
* THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 
* PURPOSE ARE DISCLAIMED. 
*
* 3. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE 
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 
* POSSIBILITY OF SUCH DAMAGE.
*
* 4. YOU AGREE THAT THE EXCLUSIONS IN PARAGRAPHS 2 AND 3 ABOVE ARE REASONABLE
* IN THE CIRCUMSTANCES.  IN PARTICULAR, YOU ACKNOWLEDGE (1) THAT THIS
* SOFTWARE HAS BEEN MADE AVAILABLE TO YOU FREE OF CHARGE, (2) THAT THIS
* SOFTWARE IS NOT "PRODUCT" QUALITY, BUT HAS BEEN PRODUCED BY A RESEARCH
* GROUP WHO DESIRE TO MAKE THIS SOFTWARE FREELY AVAILABLE TO PEOPLE WHO WISH
* TO USE IT, AND (3) THAT BECAUSE THIS SOFTWARE IS NOT OF "PRODUCT" QUALITY
* IT IS INEVITABLE THAT THERE WILL BE BUGS AND ERRORS, AND POSSIBLY MORE
* SERIOUS FAULTS, IN THIS SOFTWARE.
*
* 5. This license is governed, except to the extent that local laws
* necessarily apply, by the laws of England and Wales.
*/
/*
 * ActionPIP.java
 *
 * Created on 02 November 2006, 12:19
 *
 * To change this template, choose Tools | Template Manager
 * and open the template in the editor.
 */

package uk.ac.kent.dpa.custom.pip;

import org.globus.wsrf.security.authorization.*;
import org.w3c.dom.*;
import javax.security.auth.Subject;
import javax.xml.rpc.handler.MessageContext;
import javax.xml.namespace.QName;
import org.apache.commons.logging.Log;
import org.apache.commons.logging.LogFactory;
import org.globus.wsrf.impl.security.authorization.exceptions.*;
import java.util.*;
import java.security.Principal;
import org.apache.axis.message.addressing.*;
import org.apache.axis.message.MessageElement;
import uk.ac.kent.dpa.custom.authz.util.Merge;
import uk.ac.kent.dpa.custom.authz.util.Normalise;
import issrg.web.service.EncodeXML;
import javax.xml.parsers.*;

/**
 *
 * @author Linying Su
 */

public class SubjectPIP implements PIP {
    
    static Log logger = LogFactory.getLog(SubjectPIP.class.getName());
    private issrg.web.service.PermisWebService permis = null;
    /** Creates a new instance of ActionPIP */
    public SubjectPIP() {
    }
    
    public void collectAttributes(Subject subject, MessageContext ctx, QName operation) throws AttributeException {

        Merge merge = new Merge();
        ArrayList list = new ArrayList();
        for (Iterator i=subject.getPrincipals().iterator();i.hasNext();) {
            Principal principal = (Principal)i.next();
            list.add(principal);
        }
        Principal[] subjectPrincipal = new Principal[list.size()];
        subjectPrincipal = (Principal[])list.toArray(subjectPrincipal);
        try {
            Element sub = permis.getCreds(Normalise.normalise(subjectPrincipal[0].getName()),"Subject");
            logger.debug("the subject PIP is called for "+subjectPrincipal[0].getName());
            for (int i=1; i<subjectPrincipal.length; i++) {
                logger.debug(subjectPrincipal[i].getName());
                Element sub1 = permis.getCreds(subjectPrincipal[i].getName(),"Subject");
                sub = merge.merge(sub,sub1);
            }
            Element pre = null;
            if (ctx!=null) pre = (Element)ctx.getProperty("request.context");
            if (pre!=null) {
                sub = new Merge().merge(pre,sub);
            }
            if (ctx!=null) ctx.setProperty("request.context",sub);
            logger.debug("the current request context");
            logger.debug(new EncodeXML().encode(sub,0));
        } catch (Exception e) {
            throw new AttributeException("Permis service error : "+e);
        }
    }  
    
    public void initialize(PDPConfig pdpConfig, String name, String id) throws InitializeException {    
        logger.info("to initialise the custom subject PIP (scope:"+name+") for the service "+id);
        String fileName = (String)pdpConfig.getProperty(name,"customConfig");
        logger.debug("customConfig="+fileName);
        try {
            permis = new issrg.web.service.PermisWebService();
            permis.initialise(fileName,1);//create PermisRBAC in CVS mode
        } catch (issrg.web.service.PermisWebServiceException pe) {
            throw new InitializeException("PermisRBAC initialise error : "+pe);
        }
    }
    
    public void close() throws CloseException {     
    }
}

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -