2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster/**
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * The contents of this file are subject to the terms
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * of the Common Development and Distribution License
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * (the License). You may not use this file except in
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * compliance with the License.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * You can obtain a copy of the License at
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * https://opensso.dev.java.net/public/CDDLv1.0.html or
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * opensso/legal/CDDLv1.0.txt
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * See the License for the specific language governing
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * permission and limitations under the License.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * When distributing Covered Code, include this CDDL
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * Header Notice in each file and include the License file
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * at opensso/legal/CDDLv1.0.txt.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * If applicable, add the following below the CDDL Header,
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * with the fields enclosed by brackets [] replaced by
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * your own identifying information:
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * "Portions Copyrighted [year] [name of copyright owner]"
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * $Id: SecurityTokenManagerServlet.java,v 1.2 2008/06/25 05:47:21 qcheng Exp $
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster */
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster/*
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * Portions Copyrighted 2013 ForgeRock, Inc.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster */
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterpackage com.sun.identity.liberty.ws.security;
eca9c3fe87f52795747cb9d363962aaf96933107James Phillpotts
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport com.sun.identity.federation.common.FSUtils;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport org.forgerock.openam.utils.ClientUtils;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport com.sun.xml.rpc.server.http.JAXRPCServlet;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport javax.servlet.http.HttpServletRequest;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport javax.servlet.http.HttpServletResponse;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterimport javax.servlet.ServletException;
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster/**
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * This class provides remote interfaces for the
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * <code>SecurityTokenManager</code> class using JAX-RPC. Since JAX-RPC does not
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * provide a mechanism to obtain <code>HttpServletRequest</code> and
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * <code>HttpServletResponse </code>, it is currently extending Sun's
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * implementation of <code>JAXRPCServlet</code>.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * This classes uses the same security mechanism used by <code>SAMLSOAPReceiver
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * </code> for validating the caller.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster */
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Fosterpublic class SecurityTokenManagerServlet extends JAXRPCServlet {
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster private static String DEBUG_SUCCESS_MSG =
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster "SecurityTokenManagerServlet: processing request from server: ";
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster /**
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * Overrides JAXRPCServlet's doPost method to perform the
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * security check on the caller. The logic is implemented
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster * in SAMLSOAPReceiver.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster *
188172aec293f39cd63fec57ee637b3cdd815b5dDirk Hogan * @param request the <code>HttpServletRequest</code> object.
188172aec293f39cd63fec57ee637b3cdd815b5dDirk Hogan * @param response the <code>HttpServletResponse</code> object.
188172aec293f39cd63fec57ee637b3cdd815b5dDirk Hogan * @throws ServletException if there is an error.
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster */
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster @Override
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster public void doPost(HttpServletRequest request, HttpServletResponse response)
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster throws ServletException {
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster if (SecurityTokenManager.debug.messageEnabled()) {
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster SecurityTokenManager.debug.message(DEBUG_SUCCESS_MSG +
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster ClientUtils.getClientIPAddress(request));
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster }
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster FSUtils.checkHTTPRequestLength(request);
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster // Call JAXRPC servlet's doPost
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster super.doPost(request, response);
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster }
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster}
2d0a88b18a041738cfe635b45bd1db56af469c91Allan Foster