blob: b1ef426015dd75aecfdd1e8ce5b3dcf967bac469 [file] [log] [blame]
<!DOCTYPE HTML>
<html lang="en">
<head>
<title>Source code</title>
<link rel="stylesheet" type="text/css" href="../../../../../../stylesheet.css" title="Style">
</head>
<body>
<main role="main">
<div class="sourceContainer">
<pre><span class="sourceLineNo">001</span><a id="line.1">/*</a>
<span class="sourceLineNo">002</span><a id="line.2"> * Licensed to the Apache Software Foundation (ASF) under one</a>
<span class="sourceLineNo">003</span><a id="line.3"> * or more contributor license agreements. See the NOTICE file</a>
<span class="sourceLineNo">004</span><a id="line.4"> * distributed with this work for additional information</a>
<span class="sourceLineNo">005</span><a id="line.5"> * regarding copyright ownership. The ASF licenses this file</a>
<span class="sourceLineNo">006</span><a id="line.6"> * to you under the Apache License, Version 2.0 (the</a>
<span class="sourceLineNo">007</span><a id="line.7"> * "License"); you may not use this file except in compliance</a>
<span class="sourceLineNo">008</span><a id="line.8"> * with the License. You may obtain a copy of the License at</a>
<span class="sourceLineNo">009</span><a id="line.9"> *</a>
<span class="sourceLineNo">010</span><a id="line.10"> * http://www.apache.org/licenses/LICENSE-2.0</a>
<span class="sourceLineNo">011</span><a id="line.11"> *</a>
<span class="sourceLineNo">012</span><a id="line.12"> * Unless required by applicable law or agreed to in writing,</a>
<span class="sourceLineNo">013</span><a id="line.13"> * software distributed under the License is distributed on an</a>
<span class="sourceLineNo">014</span><a id="line.14"> * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY</a>
<span class="sourceLineNo">015</span><a id="line.15"> * KIND, either express or implied. See the License for the</a>
<span class="sourceLineNo">016</span><a id="line.16"> * specific language governing permissions and limitations</a>
<span class="sourceLineNo">017</span><a id="line.17"> * under the License.</a>
<span class="sourceLineNo">018</span><a id="line.18"> */</a>
<span class="sourceLineNo">019</span><a id="line.19">package org.apache.shiro.authc.credential;</a>
<span class="sourceLineNo">020</span><a id="line.20"></a>
<span class="sourceLineNo">021</span><a id="line.21">import org.apache.shiro.authc.AuthenticationInfo;</a>
<span class="sourceLineNo">022</span><a id="line.22">import org.apache.shiro.authc.AuthenticationToken;</a>
<span class="sourceLineNo">023</span><a id="line.23">import org.apache.shiro.crypto.hash.Hash;</a>
<span class="sourceLineNo">024</span><a id="line.24"></a>
<span class="sourceLineNo">025</span><a id="line.25">/**</a>
<span class="sourceLineNo">026</span><a id="line.26"> * A {@link CredentialsMatcher} that employs best-practices comparisons for hashed text passwords.</a>
<span class="sourceLineNo">027</span><a id="line.27"> * &lt;p/&gt;</a>
<span class="sourceLineNo">028</span><a id="line.28"> * This implementation delegates to an internal {@link PasswordService} to perform the actual password</a>
<span class="sourceLineNo">029</span><a id="line.29"> * comparison. This class is essentially a bridge between the generic CredentialsMatcher interface and the</a>
<span class="sourceLineNo">030</span><a id="line.30"> * more specific {@code PasswordService} component.</a>
<span class="sourceLineNo">031</span><a id="line.31"> *</a>
<span class="sourceLineNo">032</span><a id="line.32"> * @since 1.2</a>
<span class="sourceLineNo">033</span><a id="line.33"> */</a>
<span class="sourceLineNo">034</span><a id="line.34">public class PasswordMatcher implements CredentialsMatcher {</a>
<span class="sourceLineNo">035</span><a id="line.35"></a>
<span class="sourceLineNo">036</span><a id="line.36"> private PasswordService passwordService;</a>
<span class="sourceLineNo">037</span><a id="line.37"></a>
<span class="sourceLineNo">038</span><a id="line.38"> public PasswordMatcher() {</a>
<span class="sourceLineNo">039</span><a id="line.39"> this.passwordService = new DefaultPasswordService();</a>
<span class="sourceLineNo">040</span><a id="line.40"> }</a>
<span class="sourceLineNo">041</span><a id="line.41"></a>
<span class="sourceLineNo">042</span><a id="line.42"> public boolean doCredentialsMatch(AuthenticationToken token, AuthenticationInfo info) {</a>
<span class="sourceLineNo">043</span><a id="line.43"></a>
<span class="sourceLineNo">044</span><a id="line.44"> PasswordService service = ensurePasswordService();</a>
<span class="sourceLineNo">045</span><a id="line.45"></a>
<span class="sourceLineNo">046</span><a id="line.46"> Object submittedPassword = getSubmittedPassword(token);</a>
<span class="sourceLineNo">047</span><a id="line.47"> Object storedCredentials = getStoredPassword(info);</a>
<span class="sourceLineNo">048</span><a id="line.48"> assertStoredCredentialsType(storedCredentials);</a>
<span class="sourceLineNo">049</span><a id="line.49"></a>
<span class="sourceLineNo">050</span><a id="line.50"> if (storedCredentials instanceof Hash) {</a>
<span class="sourceLineNo">051</span><a id="line.51"> Hash hashedPassword = (Hash)storedCredentials;</a>
<span class="sourceLineNo">052</span><a id="line.52"> HashingPasswordService hashingService = assertHashingPasswordService(service);</a>
<span class="sourceLineNo">053</span><a id="line.53"> return hashingService.passwordsMatch(submittedPassword, hashedPassword);</a>
<span class="sourceLineNo">054</span><a id="line.54"> }</a>
<span class="sourceLineNo">055</span><a id="line.55"> //otherwise they are a String (asserted in the 'assertStoredCredentialsType' method call above):</a>
<span class="sourceLineNo">056</span><a id="line.56"> String formatted = (String)storedCredentials;</a>
<span class="sourceLineNo">057</span><a id="line.57"> return passwordService.passwordsMatch(submittedPassword, formatted);</a>
<span class="sourceLineNo">058</span><a id="line.58"> }</a>
<span class="sourceLineNo">059</span><a id="line.59"></a>
<span class="sourceLineNo">060</span><a id="line.60"> private HashingPasswordService assertHashingPasswordService(PasswordService service) {</a>
<span class="sourceLineNo">061</span><a id="line.61"> if (service instanceof HashingPasswordService) {</a>
<span class="sourceLineNo">062</span><a id="line.62"> return (HashingPasswordService) service;</a>
<span class="sourceLineNo">063</span><a id="line.63"> }</a>
<span class="sourceLineNo">064</span><a id="line.64"> String msg = "AuthenticationInfo's stored credentials are a Hash instance, but the " +</a>
<span class="sourceLineNo">065</span><a id="line.65"> "configured passwordService is not a " +</a>
<span class="sourceLineNo">066</span><a id="line.66"> HashingPasswordService.class.getName() + " instance. This is required to perform Hash " +</a>
<span class="sourceLineNo">067</span><a id="line.67"> "object password comparisons.";</a>
<span class="sourceLineNo">068</span><a id="line.68"> throw new IllegalStateException(msg);</a>
<span class="sourceLineNo">069</span><a id="line.69"> }</a>
<span class="sourceLineNo">070</span><a id="line.70"></a>
<span class="sourceLineNo">071</span><a id="line.71"> private PasswordService ensurePasswordService() {</a>
<span class="sourceLineNo">072</span><a id="line.72"> PasswordService service = getPasswordService();</a>
<span class="sourceLineNo">073</span><a id="line.73"> if (service == null) {</a>
<span class="sourceLineNo">074</span><a id="line.74"> String msg = "Required PasswordService has not been configured.";</a>
<span class="sourceLineNo">075</span><a id="line.75"> throw new IllegalStateException(msg);</a>
<span class="sourceLineNo">076</span><a id="line.76"> }</a>
<span class="sourceLineNo">077</span><a id="line.77"> return service;</a>
<span class="sourceLineNo">078</span><a id="line.78"> }</a>
<span class="sourceLineNo">079</span><a id="line.79"></a>
<span class="sourceLineNo">080</span><a id="line.80"> protected Object getSubmittedPassword(AuthenticationToken token) {</a>
<span class="sourceLineNo">081</span><a id="line.81"> return token != null ? token.getCredentials() : null;</a>
<span class="sourceLineNo">082</span><a id="line.82"> }</a>
<span class="sourceLineNo">083</span><a id="line.83"></a>
<span class="sourceLineNo">084</span><a id="line.84"> private void assertStoredCredentialsType(Object credentials) {</a>
<span class="sourceLineNo">085</span><a id="line.85"> if (credentials instanceof String || credentials instanceof Hash) {</a>
<span class="sourceLineNo">086</span><a id="line.86"> return;</a>
<span class="sourceLineNo">087</span><a id="line.87"> }</a>
<span class="sourceLineNo">088</span><a id="line.88"></a>
<span class="sourceLineNo">089</span><a id="line.89"> String msg = "Stored account credentials are expected to be either a " +</a>
<span class="sourceLineNo">090</span><a id="line.90"> Hash.class.getName() + " instance or a formatted hash String.";</a>
<span class="sourceLineNo">091</span><a id="line.91"> throw new IllegalArgumentException(msg);</a>
<span class="sourceLineNo">092</span><a id="line.92"> }</a>
<span class="sourceLineNo">093</span><a id="line.93"></a>
<span class="sourceLineNo">094</span><a id="line.94"> protected Object getStoredPassword(AuthenticationInfo storedAccountInfo) {</a>
<span class="sourceLineNo">095</span><a id="line.95"> Object stored = storedAccountInfo != null ? storedAccountInfo.getCredentials() : null;</a>
<span class="sourceLineNo">096</span><a id="line.96"> //fix for https://issues.apache.org/jira/browse/SHIRO-363</a>
<span class="sourceLineNo">097</span><a id="line.97"> if (stored instanceof char[]) {</a>
<span class="sourceLineNo">098</span><a id="line.98"> stored = new String((char[])stored);</a>
<span class="sourceLineNo">099</span><a id="line.99"> }</a>
<span class="sourceLineNo">100</span><a id="line.100"> return stored;</a>
<span class="sourceLineNo">101</span><a id="line.101"> }</a>
<span class="sourceLineNo">102</span><a id="line.102"></a>
<span class="sourceLineNo">103</span><a id="line.103"> public PasswordService getPasswordService() {</a>
<span class="sourceLineNo">104</span><a id="line.104"> return passwordService;</a>
<span class="sourceLineNo">105</span><a id="line.105"> }</a>
<span class="sourceLineNo">106</span><a id="line.106"></a>
<span class="sourceLineNo">107</span><a id="line.107"> public void setPasswordService(PasswordService passwordService) {</a>
<span class="sourceLineNo">108</span><a id="line.108"> this.passwordService = passwordService;</a>
<span class="sourceLineNo">109</span><a id="line.109"> }</a>
<span class="sourceLineNo">110</span><a id="line.110">}</a>
</pre>
</div>
</main>
</body>
</html>