View Javadoc

1   /*
2    * Copyright 2005-2010 the original author or authors.
3    *
4    * Licensed under the Apache License, Version 2.0 (the "License");
5    * you may not use this file except in compliance with the License.
6    * You may obtain a copy of the License at
7    *
8    *      http://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS,
12   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13   * See the License for the specific language governing permissions and
14   * limitations under the License.
15   */
16  
17  package org.springframework.ws.soap.security.xwss.callback;
18  
19  import java.io.IOException;
20  import javax.security.auth.callback.Callback;
21  import javax.security.auth.callback.UnsupportedCallbackException;
22  
23  import com.sun.xml.wss.impl.callback.PasswordCallback;
24  import com.sun.xml.wss.impl.callback.UsernameCallback;
25  
26  import org.springframework.security.core.Authentication;
27  import org.springframework.security.core.context.SecurityContextHolder;
28  import org.springframework.ws.soap.security.callback.AbstractCallbackHandler;
29  
30  /**
31   * Callback handler that adds username/password information to a mesage using an Spring Security [email protected]
32   * org.springframework.security.core.context.SecurityContext}.
33   * <p/>
34   * This class handles <code>UsernameCallback</code>s and <code>PasswordCallback</code>s, and throws an
35   * <code>UnsupportedCallbackException</code> for others
36   *
37   * @author Arjen Poutsma
38   * @since 1.5.0
39   */
40  public class SpringUsernamePasswordCallbackHandler extends AbstractCallbackHandler {
41  
42      @Override
43      protected void handleInternal(Callback callback) throws IOException, UnsupportedCallbackException {
44          if (callback instanceof UsernameCallback) {
45              Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
46              if (authentication != null && authentication.getName() != null) {
47                  UsernameCallback usernameCallback = (UsernameCallback) callback;
48                  usernameCallback.setUsername(authentication.getName());
49                  return;
50              }
51              else {
52                  logger.warn(
53                          "Cannot handle UsernameCallback: Spring Security SecurityContext contains no Authentication");
54              }
55          }
56          else if (callback instanceof PasswordCallback) {
57              Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
58              if (authentication != null && authentication.getName() != null) {
59                  PasswordCallback passwordCallback = (PasswordCallback) callback;
60                  passwordCallback.setPassword(authentication.getCredentials().toString());
61                  return;
62              }
63              else {
64                  logger.warn(
65                          "Canot handle PasswordCallback: Spring Security SecurityContext contains no Authentication");
66              }
67          }
68          throw new UnsupportedCallbackException(callback);
69      }
70  }