2 * Copyright 2008, 2009 Electronic Business Systems Ltd.
4 * This file is part of GSS.
6 * GSS is free software: you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation, either version 3 of the License, or
9 * (at your option) any later version.
11 * GSS is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with GSS. If not, see <http://www.gnu.org/licenses/>.
19 package gr.ebs.gss.server;
21 import static gr.ebs.gss.server.configuration.GSSConfigurationFactory.getConfiguration;
22 import gr.ebs.gss.client.exceptions.ObjectNotFoundException;
23 import gr.ebs.gss.client.exceptions.RpcException;
24 import gr.ebs.gss.server.domain.Nonce;
25 import gr.ebs.gss.server.domain.User;
26 import gr.ebs.gss.server.ejb.ExternalAPI;
28 import java.io.IOException;
29 import java.io.PrintWriter;
31 import javax.naming.Context;
32 import javax.naming.InitialContext;
33 import javax.naming.NamingException;
34 import javax.rmi.PortableRemoteObject;
35 import javax.servlet.http.HttpServlet;
36 import javax.servlet.http.HttpServletRequest;
37 import javax.servlet.http.HttpServletResponse;
39 import org.apache.commons.logging.Log;
40 import org.apache.commons.logging.LogFactory;
43 * The servlet that handles nonce creation.
47 public class NonceIssuer extends HttpServlet {
49 * The serial version UID of the class.
51 private static final long serialVersionUID = 1L;
54 * The request parameter name for the user.
56 private static final String USER_PARAM = "user";
61 private static Log logger = LogFactory.getLog(NonceIssuer.class);
64 * A helper method that retrieves a reference to the ExternalAPI bean and
65 * stores it for future use.
67 * @return an ExternalAPI instance
68 * @throws RpcException in case an error occurs
70 private ExternalAPI getService() throws RpcException {
72 final Context ctx = new InitialContext();
73 final Object ref = ctx.lookup(getConfiguration().getString("externalApiPath"));
74 return (ExternalAPI) PortableRemoteObject.narrow(ref, ExternalAPI.class);
75 } catch (final NamingException e) {
76 logger.error("Unable to retrieve the ExternalAPI EJB", e);
77 throw new RpcException("An error occurred while contacting the naming service");
82 public void service(HttpServletRequest request, HttpServletResponse response) throws IOException {
83 String username = request.getParameter(USER_PARAM);
86 if (username == null) {
87 String error = "No username supplied";
89 response.setContentType("text/html");
90 response.sendError(HttpServletResponse.SC_FORBIDDEN, error);
94 user = getService().findUser(username);
96 String error = "User was not found";
98 response.setContentType("text/html");
99 response.sendError(HttpServletResponse.SC_FORBIDDEN, error);
102 nonce = getService().createNonce(user.getId());
103 } catch (RpcException e) {
104 String error = "An error occurred while communicating with the service";
105 logger.error(error, e);
106 response.setContentType("text/html");
107 response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, error);
109 } catch (ObjectNotFoundException e) {
110 // The user might not be found in createNonce() since there
111 // is no transaction spanning the consecutive service calls.
112 String error = "The user was not found";
113 logger.error(error, e);
114 response.setContentType("text/html");
115 response.sendError(HttpServletResponse.SC_FORBIDDEN, error);
118 if (logger.isDebugEnabled())
119 logger.debug("user: "+user.getUsername()+" nonce: "+nonce.getEncodedNonce());
120 response.setContentType("text/plain");
121 PrintWriter out = response.getWriter();
122 out.println(nonce.getEncodedNonce());