- // Authorization authorization =
- // subject.getPrivateCredentials(Authorization.class).iterator().next();
- // if (request != null && authorization.getName() != null) {
- // request.setAttribute(HttpContext.REMOTE_USER,
- // authorization.getName());
- // request.setAttribute(HttpContext.AUTHORIZATION, authorization);
- //
- // HttpSession httpSession = request.getSession();
- // if (httpSession.getAttribute(HttpContext.AUTHORIZATION) == null) {
- //
- // String sessionId = request.getSession().getId();
- // Collection<ServiceReference<CmsSession>> sr;
- // try {
- // sr = bc.getServiceReferences(CmsSession.class,
- // "(" + CmsSession.CMS_SESSION_ID + "=" + sessionId + ")");
- // } catch (InvalidSyntaxException e) {
- // throw new CmsException("Cannot get CMS session for id " + sessionId,
- // e);
- // }
- // CmsSession cmsSession;
- // if (sr.size() == 1) {
- // cmsSession = bc.getService(sr.iterator().next());
- // } else if (sr.size() == 0) {
- // Hashtable<String, String> props = new Hashtable<>();
- // props.put(CmsSession.CMS_DN, authorization.getName());
- // props.put(CmsSession.CMS_SESSION_ID, sessionId);
- // cmsSession = new CmsSessionImpl(sessionId, authorization);
- // bc.registerService(CmsSession.class, cmsSession, props);
- // if (log.isDebugEnabled())
- // log.debug("Initialized " + cmsSession + " for " +
- // authorization.getName());
- // } else
- // throw new CmsException(sr.size() + " CMS sessions registered for " +
- // sessionId);
- // cmsSession.addHttpSession(request);
- // if (log.isTraceEnabled())
- // log.trace("Added " + request.getServletPath() + " to " + cmsSession +
- // " (" + request.getRequestURI()
- // + ")");
- // httpSession.setAttribute(HttpContext.AUTHORIZATION, authorization);
- // }
- // subject.getPrivateCredentials().add(request.getSession());
- // }
+ if (locale != null)
+ subject.getPublicCredentials().add(locale);
+
+// if (singleUser) {
+// OsUserUtils.loginAsSystemUser(subject);
+// }
+ UserAdmin userAdmin = CmsContextImpl.getCmsContext().getUserAdmin();
+ Authorization authorization;
+ if (callbackHandler == null) {// anonymous
+ authorization = userAdmin.getAuthorization(null);
+ } else if (bindAuthorization != null) {// bind
+ authorization = bindAuthorization;
+ } else {// Kerberos
+ User authenticatingUser;
+ Set<KerberosPrincipal> kerberosPrincipals = subject.getPrincipals(KerberosPrincipal.class);
+ if (kerberosPrincipals.isEmpty()) {
+ if (authenticatedUser == null) {
+ if (log.isTraceEnabled())
+ log.trace("Neither kerberos nor user admin login succeeded. Login failed.");
+ throw new CredentialNotFoundException("Bad credentials.");
+ } else {
+ authenticatingUser = authenticatedUser;
+ }
+ } else {
+ KerberosPrincipal kerberosPrincipal = kerberosPrincipals.iterator().next();
+ LdapName dn = IpaUtils.kerberosToDn(kerberosPrincipal.getName());
+ authenticatingUser = new AuthenticatingUser(dn);
+ if (authenticatedUser != null && !authenticatingUser.getName().equals(authenticatedUser.getName()))
+ throw new LoginException("Kerberos login " + authenticatingUser.getName()
+ + " is inconsistent with user admin login " + authenticatedUser.getName());
+ }
+ authorization = Subject.doAs(subject, new PrivilegedAction<Authorization>() {
+
+ @Override
+ public Authorization run() {
+ Authorization authorization = userAdmin.getAuthorization(authenticatingUser);
+ return authorization;
+ }
+
+ });
+ if (authorization == null)
+ throw new LoginException(
+ "User admin found no authorization for authenticated user " + authenticatingUser.getName());
+ }
+
+ // Log and monitor new login
+ RemoteAuthRequest request = (RemoteAuthRequest) sharedState.get(CmsAuthUtils.SHARED_STATE_HTTP_REQUEST);
+ CmsAuthUtils.addAuthorization(subject, authorization);
+
+ // Unlock keyring (underlying login to the JCR repository)
+ char[] password = (char[]) sharedState.get(CmsAuthUtils.SHARED_STATE_PWD);
+ if (password != null) {
+ ServiceReference<CryptoKeyring> keyringSr = bc.getServiceReference(CryptoKeyring.class);
+ if (keyringSr != null) {
+ CryptoKeyring keyring = bc.getService(keyringSr);
+ Subject.doAs(subject, new PrivilegedAction<Void>() {
+
+ @Override
+ public Void run() {
+ try {
+ keyring.unlock(password);
+ } catch (Exception e) {
+ e.printStackTrace();
+ log.warn("Could not unlock keyring with the password provided by " + authorization.getName()
+ + ": " + e.getMessage());
+ }
+ return null;
+ }
+
+ });
+ }
+ }
+
+ // Register CmsSession with initial subject
+ CmsAuthUtils.registerSessionAuthorization(request, subject, authorization, locale);
+
+ if (log.isDebugEnabled())
+ log.debug("Logged in to CMS: " + subject);