1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17 package io.github.tonywasher.joceanus.prometheus.security;
18
19 import io.github.tonywasher.joceanus.gordianknot.api.base.GordianException;
20 import io.github.tonywasher.joceanus.gordianknot.api.factory.GordianFactory;
21 import io.github.tonywasher.joceanus.gordianknot.api.factory.GordianFactory.GordianFactoryLock;
22 import io.github.tonywasher.joceanus.gordianknot.api.factory.GordianFactoryType;
23 import io.github.tonywasher.joceanus.gordianknot.api.keypair.GordianKeyPair;
24 import io.github.tonywasher.joceanus.gordianknot.api.keyset.GordianBadCredentialsException;
25 import io.github.tonywasher.joceanus.gordianknot.api.keyset.GordianKeySet;
26 import io.github.tonywasher.joceanus.gordianknot.api.lock.GordianKeyPairLock;
27 import io.github.tonywasher.joceanus.gordianknot.api.lock.GordianKeySetLock;
28 import io.github.tonywasher.joceanus.gordianknot.api.lock.GordianLockFactory;
29 import io.github.tonywasher.joceanus.gordianknot.api.lock.GordianPasswordLockSpec;
30 import io.github.tonywasher.joceanus.gordianknot.api.zip.GordianZipLock;
31 import io.github.tonywasher.joceanus.gordianknot.util.GordianGenerator;
32 import io.github.tonywasher.joceanus.oceanus.base.OceanusException;
33 import io.github.tonywasher.joceanus.prometheus.exc.PrometheusDataException;
34 import io.github.tonywasher.joceanus.prometheus.exc.PrometheusLogicException;
35 import io.github.tonywasher.joceanus.prometheus.exc.PrometheusSecurityException;
36
37 import java.nio.ByteBuffer;
38 import java.util.Arrays;
39
40
41
42
43
44
45 public class PrometheusSecurityPasswordManager {
46
47
48
49 private static final String NLS_ERRORPASS = PrometheusSecurityResource.SECURITY_BAD_PASSWORD.getValue();
50
51
52
53
54 private final GordianFactory theFactory;
55
56
57
58
59 private final GordianLockFactory theLockFactory;
60
61
62
63
64 private final GordianPasswordLockSpec theLockSpec;
65
66
67
68
69 private final PrometheusSecurityPasswordCache theCache;
70
71
72
73
74 private PrometheusSecurityDialogController theDialog;
75
76
77
78
79
80
81
82
83 public PrometheusSecurityPasswordManager(final GordianFactory pFactory,
84 final PrometheusSecurityDialogController pDialog) throws OceanusException {
85 this(pFactory, new GordianPasswordLockSpec(), pDialog);
86 }
87
88
89
90
91
92
93
94
95
96 public PrometheusSecurityPasswordManager(final GordianFactory pFactory,
97 final GordianPasswordLockSpec pLockSpec,
98 final PrometheusSecurityDialogController pDialog) throws OceanusException {
99
100 theFactory = pFactory;
101 theLockFactory = theFactory.getLockFactory();
102 theDialog = pDialog;
103 theLockSpec = pLockSpec;
104
105
106 theCache = new PrometheusSecurityPasswordCache(this, theLockSpec);
107 }
108
109
110
111
112
113
114 public GordianFactory getSecurityFactory() {
115 return theFactory;
116 }
117
118
119
120
121
122
123 public GordianPasswordLockSpec getLockSpec() {
124 return theLockSpec;
125 }
126
127
128
129
130
131
132 public void setDialogController(final PrometheusSecurityDialogController pDialog) {
133 theDialog = pDialog;
134 }
135
136
137
138
139
140
141
142
143 public GordianFactoryLock newFactoryLock(final String pSource) throws OceanusException {
144
145 try {
146 final GordianFactory myFactory = GordianGenerator.createRandomFactory(GordianFactoryType.BC);
147 return (GordianFactoryLock) requestPassword(pSource, true, p -> createFactoryLock(myFactory, p));
148
149 } catch (GordianException e) {
150 throw new PrometheusSecurityException(e);
151 }
152 }
153
154
155
156
157
158
159
160
161
162 public GordianFactoryLock newFactoryLock(final GordianFactory pFactory,
163 final String pSource) throws OceanusException {
164 return (GordianFactoryLock) requestPassword(pSource, true, p -> createFactoryLock(pFactory, p));
165 }
166
167
168
169
170
171
172
173
174
175 public GordianFactoryLock resolveFactoryLock(final byte[] pLockBytes,
176 final String pSource) throws OceanusException {
177
178 GordianFactoryLock myFactory = theCache.lookUpResolvedFactoryLock(pLockBytes);
179
180
181 if (myFactory == null) {
182 myFactory = theCache.attemptKnownPasswordsForFactoryLock(pLockBytes);
183 }
184
185
186 if (myFactory == null) {
187 myFactory = (GordianFactoryLock) requestPassword(pSource, false, p -> resolveFactoryLock(pLockBytes, p));
188 }
189
190
191 return myFactory;
192 }
193
194
195
196
197
198
199
200
201 public GordianFactoryLock similarFactoryLock(final Object pReference) throws OceanusException {
202
203 try {
204
205 final GordianFactory myFactory = GordianGenerator.createRandomFactory(GordianFactoryType.BC);
206
207
208 final ByteBuffer myPassword = theCache.lookUpResolvedPassword(pReference);
209
210
211 return theCache.createSimilarFactoryLock(myFactory, myPassword);
212
213 } catch (GordianException e) {
214 throw new PrometheusSecurityException(e);
215 }
216 }
217
218
219
220
221
222
223
224
225 public GordianKeySetLock newKeySetLock(final String pSource) throws OceanusException {
226
227 try {
228 final GordianKeySet myKeySet = theFactory.getKeySetFactory().generateKeySet(theLockSpec.getKeySetSpec());
229 return (GordianKeySetLock) requestPassword(pSource, true, p -> createKeySetLock(myKeySet, p));
230
231 } catch (GordianException e) {
232 throw new PrometheusSecurityException(e);
233 }
234 }
235
236
237
238
239
240
241
242
243
244 public GordianKeySetLock newKeySetLock(final GordianKeySet pKeySet,
245 final String pSource) throws OceanusException {
246 return (GordianKeySetLock) requestPassword(pSource, true, p -> createKeySetLock(pKeySet, p));
247 }
248
249
250
251
252
253
254
255
256
257 public GordianKeySetLock resolveKeySetLock(final byte[] pLockBytes,
258 final String pSource) throws OceanusException {
259
260 GordianKeySetLock myKeySet = theCache.lookUpResolvedKeySetLock(pLockBytes);
261
262
263 if (myKeySet == null) {
264 myKeySet = theCache.attemptKnownPasswordsForKeySetLock(pLockBytes);
265 }
266
267
268 if (myKeySet == null) {
269 myKeySet = (GordianKeySetLock) requestPassword(pSource, false, p -> resolveKeySetLock(pLockBytes, p));
270 }
271
272
273 return myKeySet;
274 }
275
276
277
278
279
280
281
282
283 public GordianKeySetLock similarKeySetLock(final Object pReference) throws OceanusException {
284
285 try {
286
287 final GordianKeySet myKeySet = theFactory.getKeySetFactory().generateKeySet(theLockSpec.getKeySetSpec());
288
289
290 final ByteBuffer myPassword = theCache.lookUpResolvedPassword(pReference);
291
292
293 return theCache.createSimilarKeySetLock(myKeySet, myPassword);
294
295 } catch (GordianException e) {
296 throw new PrometheusSecurityException(e);
297 }
298 }
299
300
301
302
303
304
305
306
307
308 public GordianKeyPairLock newKeyPairLock(final GordianKeyPair pKeyPair,
309 final String pSource) throws OceanusException {
310 return (GordianKeyPairLock) requestPassword(pSource, true, p -> createKeyPairLock(pKeyPair, p));
311 }
312
313
314
315
316
317
318
319
320
321
322 public GordianKeyPairLock resolveKeyPairLock(final byte[] pLockBytes,
323 final GordianKeyPair pKeyPair,
324 final String pSource) throws OceanusException {
325
326 GordianKeyPairLock myKeyPair = theCache.lookUpResolvedKeyPairLock(pLockBytes, pKeyPair);
327
328
329 if (myKeyPair == null) {
330 myKeyPair = theCache.attemptKnownPasswordsForKeyPairLock(pLockBytes, pKeyPair);
331 }
332
333
334 if (myKeyPair == null) {
335 myKeyPair = (GordianKeyPairLock) requestPassword(pSource, false, p -> resolveKeyPairLock(pLockBytes, pKeyPair, p));
336 }
337
338
339 return myKeyPair;
340 }
341
342
343
344
345
346
347
348
349
350 public GordianKeyPairLock similarKeyPairLock(final GordianKeyPair pKeyPair,
351 final Object pReference) throws OceanusException {
352
353 final ByteBuffer myPassword = theCache.lookUpResolvedPassword(pReference);
354
355
356 return theCache.createSimilarKeyPairLock(pKeyPair, myPassword);
357 }
358
359
360
361
362
363
364
365
366 public void resolveZipLock(final GordianZipLock pZipLock,
367 final String pSource) throws OceanusException {
368 switch (pZipLock.getLockType()) {
369 case KEYSET_PASSWORD:
370 resolveKeySetZipLock(pZipLock, pSource);
371 break;
372 case FACTORY_PASSWORD:
373 resolveFactoryZipLock(pZipLock, pSource);
374 break;
375 case KEYPAIR_PASSWORD:
376 default:
377 throw new PrometheusLogicException("KeyPair zipLock not supported yet");
378 }
379 }
380
381
382
383
384
385
386
387
388 private void resolveKeySetZipLock(final GordianZipLock pZipLock,
389 final String pSource) throws OceanusException {
390
391 try {
392
393 final byte[] myLockBytes = pZipLock.getLockBytes();
394
395
396 final GordianKeySetLock myLock = resolveKeySetLock(myLockBytes, pSource);
397
398
399 if (myLock != null) {
400 pZipLock.unlock(myLock);
401 }
402
403 } catch (GordianException e) {
404 throw new PrometheusSecurityException(e);
405 }
406 }
407
408
409
410
411
412
413
414
415 private void resolveFactoryZipLock(final GordianZipLock pZipLock,
416 final String pSource) throws OceanusException {
417
418 try {
419
420 final byte[] myLockBytes = pZipLock.getLockBytes();
421
422
423 final GordianFactoryLock myLock = resolveFactoryLock(myLockBytes, pSource);
424
425
426 if (myLock != null) {
427 pZipLock.unlock(myLock);
428 }
429
430 } catch (GordianException e) {
431 throw new PrometheusSecurityException(e);
432 }
433 }
434
435
436
437
438
439
440
441
442
443
444 public Object requestPassword(final String pSource,
445 final boolean pNeedConfirm,
446 final PrometheusProcessPassword pProcessor) throws OceanusException {
447
448 Object myResult = null;
449
450
451 theDialog.createTheDialog(pSource, pNeedConfirm);
452
453
454 boolean isPasswordOk = false;
455 char[] myPassword = null;
456 while (theDialog.showTheDialog()) {
457 try {
458
459 myPassword = theDialog.getPassword();
460
461
462 final String myError = PrometheusPassCheck.validatePassword(myPassword);
463 if (myError != null) {
464 theDialog.reportBadPassword(myError);
465 continue;
466 }
467
468
469 theDialog.showTheSpinner(true);
470 myResult = pProcessor.processPassword(myPassword);
471
472
473 isPasswordOk = true;
474 break;
475
476 } catch (GordianBadCredentialsException e) {
477 theDialog.reportBadPassword(NLS_ERRORPASS);
478 if (myPassword != null) {
479 Arrays.fill(myPassword, (char) 0);
480 }
481
482 } finally {
483 if (myPassword != null) {
484 Arrays.fill(myPassword, (char) 0);
485 myPassword = null;
486 }
487 }
488 }
489
490
491 theDialog.releaseDialog();
492
493
494 if (!isPasswordOk) {
495
496 throw new PrometheusDataException(NLS_ERRORPASS);
497 }
498
499
500 return myResult;
501 }
502
503
504
505
506 @FunctionalInterface
507 public interface PrometheusProcessPassword {
508
509
510
511
512
513
514
515
516 Object processPassword(char[] pPassword) throws OceanusException;
517 }
518
519
520
521
522
523
524
525
526
527 private GordianFactoryLock createFactoryLock(final GordianFactory pFactory,
528 final char[] pPassword) throws OceanusException {
529
530 try {
531 final GordianFactoryLock myLock = theFactory.newFactoryLock(pFactory, theLockSpec, pPassword);
532 theCache.addResolvedFactory(myLock, pPassword);
533 return myLock;
534
535 } catch (GordianException e) {
536 throw new PrometheusSecurityException(e);
537 }
538 }
539
540
541
542
543
544
545
546
547
548 private GordianFactoryLock resolveFactoryLock(final byte[] pLockBytes,
549 final char[] pPassword) throws OceanusException {
550
551 try {
552 final GordianFactoryLock myFactory = theFactory.resolveFactoryLock(pLockBytes, pPassword);
553 theCache.addResolvedFactory(myFactory, pPassword);
554 return myFactory;
555
556 } catch (GordianException e) {
557 throw new PrometheusSecurityException(e);
558 }
559 }
560
561
562
563
564
565
566
567
568
569 private GordianKeySetLock createKeySetLock(final GordianKeySet pKeySet,
570 final char[] pPassword) throws OceanusException {
571
572 try {
573 final GordianKeySetLock myLock = theLockFactory.newKeySetLock(pKeySet, theLockSpec, pPassword);
574 theCache.addResolvedKeySet(myLock, pPassword);
575 return myLock;
576
577 } catch (GordianException e) {
578 throw new PrometheusSecurityException(e);
579 }
580 }
581
582
583
584
585
586
587
588
589
590 private GordianKeySetLock resolveKeySetLock(final byte[] pLockBytes,
591 final char[] pPassword) throws OceanusException {
592
593 try {
594 final GordianKeySetLock myKeySet = theLockFactory.resolveKeySetLock(pLockBytes, pPassword);
595 theCache.addResolvedKeySet(myKeySet, pPassword);
596 return myKeySet;
597
598 } catch (GordianException e) {
599 throw new PrometheusSecurityException(e);
600 }
601 }
602
603
604
605
606
607
608
609
610
611 private GordianKeyPairLock createKeyPairLock(final GordianKeyPair pKeyPair,
612 final char[] pPassword) throws OceanusException {
613
614 try {
615 final GordianKeyPairLock myLock = theLockFactory.newKeyPairLock(theLockSpec, pKeyPair, pPassword);
616 theCache.addResolvedKeyPair(myLock, pPassword);
617 return myLock;
618
619 } catch (GordianException e) {
620 throw new PrometheusSecurityException(e);
621 }
622 }
623
624
625
626
627
628
629
630
631
632
633 private GordianKeyPairLock resolveKeyPairLock(final byte[] pLockBytes,
634 final GordianKeyPair pKeyPair,
635 final char[] pPassword) throws OceanusException {
636
637 try {
638 final GordianKeyPairLock myKeyPair = theLockFactory.resolveKeyPairLock(pLockBytes, pKeyPair, pPassword);
639 theCache.addResolvedKeyPair(myKeyPair, pPassword);
640 return myKeyPair;
641
642 } catch (GordianException e) {
643 throw new PrometheusSecurityException(e);
644 }
645 }
646
647
648
649
650 private enum PrometheusPassCheck {
651
652
653
654 NUMERIC(1),
655
656
657
658
659 LOWERCASE(2),
660
661
662
663
664 UPPERCASE(4),
665
666
667
668
669 SPECIAL(8);
670
671
672
673
674 private static final String NLS_BADLENGTH = PrometheusSecurityResource.SECURITY_BAD_PASSLEN.getValue();
675
676
677
678
679 private static final String NLS_BADCHAR = PrometheusSecurityResource.SECURITY_INVALID_CHARS.getValue();
680
681
682
683
684 private static final String SPECIAL_CHARS = "%$^!@-_+~#&*";
685
686
687
688
689 private static final int MINPASSLEN = 8;
690
691
692
693
694 private final int theFlag;
695
696
697
698
699
700
701 PrometheusPassCheck(final int pFlag) {
702 theFlag = pFlag;
703 }
704
705
706
707
708
709
710 private int getFlag() {
711 return theFlag;
712 }
713
714
715
716
717
718
719
720 static String validatePassword(final char[] pPassword) {
721
722 if (pPassword.length < MINPASSLEN) {
723 return NLS_BADLENGTH;
724 }
725
726
727 int myResult = 0;
728 for (char c : pPassword) {
729 if (Character.isDigit(c)) {
730 myResult |= NUMERIC.getFlag();
731 } else if (Character.isLowerCase(c)) {
732 myResult |= LOWERCASE.getFlag();
733 } else if (Character.isUpperCase(c)) {
734 myResult |= UPPERCASE.getFlag();
735 } else if (SPECIAL_CHARS.indexOf(c) != -1) {
736 myResult |= SPECIAL.getFlag();
737 }
738 }
739
740
741 if (myResult != getExpectedResult()) {
742 return NLS_BADCHAR;
743 }
744 return null;
745 }
746
747
748
749
750
751
752 private static int getExpectedResult() {
753 int myResult = 0;
754 for (PrometheusPassCheck myCheck : values()) {
755 myResult |= myCheck.getFlag();
756 }
757 return myResult;
758 }
759 }
760 }