Estás viendo una versión antigua de esta página. Ve a la versión actual.

Comparar con el actual Ver el historial de la página

« Anterior Versión 2 Siguiente »

Aplicaciones FundeWeb 1.x

Si estás trabajando con una aplicación FundeWeb 1.x debes leer la guía ...

Pasos a seguir

Requisitos

Para poder aplicar estos cambios en tu aplicación necesitas:

  • En FundeWeb IDE 2.0: ...

  • En FundeWeb IDE 2.1: ...

Si no cumples los requisitos puedes ...

Hay que modificar o añadir las siguientes carpetas y ficheros:

AuthenticationMethodNotSupportedException.java

Añadir esta clase:

package es.um.atica.apium.security.authentication;

public class AuthenticationMethodNotSupportedException extends RuntimeException {

	private static final long serialVersionUID = -7140000370097499128L;

	private static final String MENSAJE = "No se soporta el método de autenticación: ";

	public AuthenticationMethodNotSupportedException( String message ) {
		super( MENSAJE + message );
	}

	public AuthenticationMethodNotSupportedException( Throwable cause ) {
		super( MENSAJE, cause );
	}

	public AuthenticationMethodNotSupportedException( String message, Throwable cause ) {
		super( MENSAJE + message, cause );
	}
}

AuthenticationMethodSSO.java

Añadir esta clase que es idéntica a es.um.atica.seam.security.authentication.method.AuthenticationMethodSSO.java salvo porque sobrescribe al final el método preAuthenticate() (línea 93):

package es.um.atica.apium.security.authentication;

import java.nio.charset.StandardCharsets;
import java.util.Map;

import org.jboss.seam.log.Log;
import org.jboss.seam.log.Logging;
import org.jboss.seam.util.Strings;
import org.umu.atica.servicios.gesper.gente.entity.Persona;
import org.umu.atica.servicios.gesper.gente.exceptions.PersonaException;
import org.umu.atica.servicios.gesper.gente.exceptions.PersonaNotFoundException;

import buscador.servicios.exceptions.ServiceNotFoundException;
import es.um.atica.seam.security.authentication.method.AuthenticationMethod;
import es.um.atica.seam.utils.CasClient3Util;

/**
 * Clase para definir el metodo de autenticación por SSO mediante CAS de la UMU.
 * 
 * @author juanmiguelbg
 * @version 0.0.3
 */
public class AuthenticationMethodSSO extends AuthenticationMethod {

	private static final Log LOG = Logging.getLog(AuthenticationMethodSSO.class);

    private static final String CLIENT_NAME_KEY = "clientName";
    private static final String CLAVE_CLIENT_NAME = "Cl@ve";
    private static final String CERT_CLIENT_NAME = "Cert";
    private static final String FIRST_NAME_KEY = "FirstName";
    private static final String FAMILY_NAME_KEY = "FamilyName";
    
   /*
     * (non-Javadoc)
     * 
     * @see es.um.atica.util.FundeWebManager#getLog()
     */
    @Override
    protected Log getLog() {
        return LOG;
    }
    
    @Override
	public boolean authenticate() {
		LOG.info("Autenticando a: #0", getCredentials().getUsername());
		getStatusMessages().clearGlobalMessages();
		try {
            if ( isDni( getCredentials().getUsername() ) ) { // Autenticacion Clave - DNI
                loadPersonaByDniCAS( getCredentials().getUsername() );
            } else { // Autenticacion Correo UMU - Ticarum
                loadUser( getCredentials().getUsername() );
            }
			return true;
		} catch (ServiceNotFoundException snfe) {
			LOG.error("Error al buscar el servicio de Gente", snfe);
		} catch (PersonaException pe) {
			LOG.error("Error: al obtener los datos del Usuario en GENTE.", pe);
			processErrorMessage();
		} catch (PersonaNotFoundException pnfe) {
			LOG.error("Error: el usuario no se encuentra en GENTE.", pnfe);
			processErrorMessage();
		} catch ( Throwable t ) {
            LOG.error("Error inesperado.", t);
        }
		return false;
	}

    private void loadPersonaByDniCAS( String username )
            throws PersonaException, PersonaNotFoundException, ServiceNotFoundException {
        try {
            loadPersonaByIdentificador( username );
        } catch ( PersonaNotFoundException pnfe ) {
            LOG.warn( "El usuario no se encuentra en GENTE, completamos con datos del CAS.", pnfe );
            loadPersonaByDniClave( username );
        }
    }

    private void loadPersonaByDniClave( String username ) {
        Map<String, Object> atributos = CasClient3Util.getPrincipalAttributes( CasClient3Util.getCasClient3Principal() );
        LOG.info( "Atributos: #0", atributos );
        String client = (String) atributos.get( CLIENT_NAME_KEY );
        if ( !Strings.isEmpty( client )
                && ( CLAVE_CLIENT_NAME.equals( client ) || CERT_CLIENT_NAME.equals( client ) ) ) {
            String nombre = new String( ( ( String ) atributos.get( FIRST_NAME_KEY ) ).getBytes(), StandardCharsets.UTF_8 );
            String apellidos = new String( ( ( String ) atributos.get( FAMILY_NAME_KEY ) ).getBytes(),
                    StandardCharsets.UTF_8 );
            Persona persona = new Persona( username, nombre, apellidos, null );
            getUmuIdentity().setPersona( persona );
        }
    }
    
    @Override
	public void preAuthenticate() {
		Map<String, Object> atributos = CasClient3Util.getPrincipalAttributes( CasClient3Util.getCasClient3Principal() );
		String client = ( String ) atributos.get( CLIENT_NAME_KEY );
		if ( !Strings.isEmpty( client ) && CLAVE_CLIENT_NAME.equals( client ) ) {
			throw new AuthenticationMethodNotSupportedException( CLAVE_CLIENT_NAME );
		}
	}
}

AuthenticationFactorySSO.java

Añadir esta clase asegurándonos que en el return del método createAuthenticationMethod() ponemos el nombre completo de la clase anterior (línea 11):

package es.um.atica.apium.security.authentication;

import es.um.atica.seam.security.authentication.credentials.CredentialsDefaultUmu;
import es.um.atica.seam.security.authentication.credentials.CredentialsUmu;
import es.um.atica.seam.security.authentication.factories.AuthenticationFactory;
import es.um.atica.seam.security.authentication.method.AuthenticationMethod;

public class AuthenticationFactorySSO implements AuthenticationFactory {

	public AuthenticationMethod createAuthenticationMethod() {
		return new es.um.atica.apium.security.authentication.AuthenticationMethodSSO();
	}

	public CredentialsUmu createCredentials() {
		return new CredentialsDefaultUmu();
	}
}

AuthenticationManagerBean.java

Modificar esta clase haciendo que extienda a AbstractAuthenticationManagerBean en lugar de a FundeWebManagerBean (línea 37) y asegurándonos que el return del método getFactoria() en el caso SSO ponemos el nombre completo de la clase anterior (línea 119):

package es.um.atica.apium.security.authentication;

import static org.jboss.seam.ScopeType.SESSION;
import static org.jboss.seam.annotations.Install.FRAMEWORK;

import java.io.Serializable;
import java.util.MissingResourceException;
import java.util.ResourceBundle;

import javax.faces.model.SelectItem;

import org.jboss.seam.Component;
import org.jboss.seam.annotations.Install;
import org.jboss.seam.annotations.Name;
import org.jboss.seam.annotations.Observer;
import org.jboss.seam.annotations.Scope;
import org.jboss.seam.annotations.Startup;
import org.jboss.seam.annotations.intercept.BypassInterceptors;
import org.jboss.seam.contexts.Contexts;
import org.jboss.seam.core.SeamResourceBundle;
import org.jboss.seam.log.Log;
import org.jboss.seam.log.Logging;

import es.um.atica.apium.security.authentication.ws.AuthenticationFactoryCorreo;
import es.um.atica.seam.security.CredentialsAdapter;
import es.um.atica.seam.security.UmuIdentity;
import es.um.atica.seam.security.authentication.AbstractAuthenticationManagerBean;
import es.um.atica.seam.security.authentication.credentials.CredentialsUmu;
import es.um.atica.seam.security.authentication.factories.AuthenticationFactory;
import es.um.atica.seam.security.authentication.method.AuthenticationMethod;

@Name( "authenticationManagerBean" )
@Scope( SESSION )
@Install( precedence = FRAMEWORK )
@BypassInterceptors
@Startup
public class AuthenticationManagerBean extends AbstractAuthenticationManagerBean implements Serializable {

	/**
	 * serialVersionUID generado automaticamente
	 */
	private static final long serialVersionUID = -6064182119922723132L;

	/** Logger de la clase */
	private static final Log LOG = Logging.getLog( AuthenticationManagerBean.class );

	protected SelectItem[] selectItemsAutentication;

	/** Credencial actual */
	protected CredentialsAdapter credentialsAdapter;

	protected AuthenticationType authenticationType;

	public enum AuthenticationType {
		CORREO, SSO
	}

	private static final String ERROR_FIRMA = "0";

	public AuthenticationManagerBean() { // Por defecto CORREO
		this.credentialsAdapter = ( CredentialsAdapter ) this.getCredentials();
		this.authenticationType = AuthenticationType.CORREO;
		this.activateCredentialsUmu();
		int idx = 0;
		selectItemsAutentication = new SelectItem[AuthenticationType.values().length];
		for ( AuthenticationType type : AuthenticationType.values() ) {
			selectItemsAutentication[idx++] = new SelectItem( type.name(), getAuthenticationTypeLabel( type ) );
		}
	}

	public void activateCredentialsUmu() {
		LOG.info( "Entrar en activateCredentialsUmu: #0", this.authenticationType.name() );
		this.credentialsAdapter.setCredentialsUmu( getFactoria( this.authenticationType ).createCredentials() );
	}

	/**
	 * Metodo para activar una credencial.<br />
	 * Si la que se desea activar, es la que est� actualmente, no se hace nada y se devuelve false. En otro caso se
	 * devolver� true.
	 * 
	 * @param credencial
	 *                   Clase de Credencial a activar.
	 * @return Si => se creo una nueva credencial. No => ya estaba esa misma credencial activa.
	 */
	public boolean activateCredentialsUmu( AuthenticationType authenticationType ) {
		LOG.info( "Entrar en activateCredentialsUmu: #0",
				( authenticationType != null ? authenticationType.name() : "" ) );
		if ( ( this.getCredentialsUmu() != null ) && ( this.authenticationType == authenticationType ) ) {
			if ( LOG.isDebugEnabled() ) {
				LOG.debug( "La credencial actual y la pedida son iguales, luego no se crear� una nueva: #0.",
						this.authenticationType );
			}
			return false;
		}
		if ( authenticationType != null ) {
			this.setAuthenticationType( authenticationType );
		} else { // Por defecto CORREO
			this.setAuthenticationType( AuthenticationType.CORREO );
		}
		this.credentialsAdapter.setCredentialsUmu( getFactoria( this.authenticationType ).createCredentials() );
		return true;
	}

	public AuthenticationMethod getAuthenticationMethod() {
		return this.getFactoria( this.authenticationType ).createAuthenticationMethod();
	}

	/**
	 * @param authenticationType
	 *                           - parametro de Seam por defecto
	 * @return
	 */
	protected AuthenticationFactory getFactoria( AuthenticationType authenticationType ) {
		if ( this.authenticationType == null ) {
			activateCredentialsUmu( AuthenticationType.CORREO );
		}
		switch ( this.authenticationType ) {
			case SSO: // case SSO
				return new es.um.atica.apium.security.authentication.AuthenticationFactorySSO();
			case CORREO: // case CORREO
				return new AuthenticationFactoryCorreo();
			default:
				return new es.um.atica.apium.security.authentication.AuthenticationFactoryRadius();
		}
	}

	protected String getAuthenticationTypeLabel( AuthenticationType authenticationType ) {
		ResourceBundle srb = SeamResourceBundle.getBundle();

		try {
			switch ( authenticationType ) {
				case CORREO:
					return srb.getString( "label.tipo_acceso_correo" );
				case SSO:
					return srb.getString( "label.tipo_acceso_sso" );
				default:
					return srb.getString( "tipo no identificado" );
			}
		} catch ( MissingResourceException mre ) {
			LOG.error( "Error al obtener las etiquetas para los tipos de autenticacion.", mre );
		}
		return "";
	}

	/**
	 * Obtiene la credencial actual.
	 */
	public CredentialsUmu getCredentialsUmu() {
		return this.credentialsAdapter.getCredentialsUmu();
	}

	public AuthenticationType getAuthenticationType() {
		return authenticationType;
	}

	public void setAuthenticationType( AuthenticationType authenticationType ) {
		LOG.debug( "Entra en setAuthenticationType: #0 - #1", authenticationType.hashCode(),
				authenticationType.name() );
		this.authenticationType = authenticationType;
	}

	public boolean isCorreoAuthentication() {
		return this.authenticationType == AuthenticationType.CORREO;
	}

	public boolean isSsoAuthentication() {
		return this.authenticationType == AuthenticationType.SSO;
	}

	public SelectItem[] getSelectItemsAutentication() {
		return selectItemsAutentication;
	}

	@Observer( UmuIdentity.EVENT_AUTHENTICATING_BY_CAS )
	public void activarAuthenticacionSSO() {
		LOG.debug( "Entra en activarAuthenticacionSSO" );
		this.authenticationType = AuthenticationType.SSO;
		this.activateCredentialsUmu();
	}

	/*
	 * (non-Javadoc)
	 * @see es.um.atica.util.FundeWebManager#getLog()
	 */
	@Override
	protected Log getLog() {
		return LOG;
	}

	public static AuthenticationManagerBean instance() {
		if ( !Contexts.isSessionContextActive() ) {
			throw new IllegalStateException( "no session context active" );
		}
		return ( AuthenticationManagerBean ) Component.getInstance( AuthenticationManagerBean.class );
	}

	public static String getErrorfirma() {
		return ERROR_FIRMA;
	}
}

AuthenticatorAction.java

Sustituir la clase completa:

package es.um.atica.apium.security.authentication;

import static org.jboss.seam.annotations.Install.FRAMEWORK;

import org.jboss.seam.annotations.Install;
import org.jboss.seam.annotations.Name;
import org.jboss.seam.annotations.intercept.BypassInterceptors;
import org.jboss.seam.log.Log;
import org.jboss.seam.log.Logging;

import es.um.atica.seam.security.authentication.AbstractAuthenticationManagerBean;
import es.um.atica.seam.security.authentication.AbstractAuthenticatorAction;

@Name( "authenticator" )
@Install( precedence = FRAMEWORK )
@BypassInterceptors
public class AuthenticatorAction extends AbstractAuthenticatorAction {

	private static final Log LOG = Logging.getLog( AuthenticatorAction.class );

	@Override
	protected AbstractAuthenticationManagerBean getAuthenticationManagerBean() {
		return AuthenticationManagerBean.instance();
	}

	/*
	 * (non-Javadoc)
	 * @see es.um.atica.util.FundeWebManagerBean#getLog()
	 */
	@Override
	protected Log getLog() {
		return LOG;
	}
}

messages_en.properties

Añadir al final del fichero las siguientes variables.

es.um.atica.security.authentication.AuthenticationMethodNotSupportedException=Authentication method not supported

messages_es.properties

Añadir al final del fichero las siguientes variables.

es.um.atica.security.authentication.AuthenticationMethodNotSupportedException=M\u00E9todo de autenticaci\u00F3n no soportado

pages.xml

Añadir la siguiente excepción:

<exception class="es.um.atica.apium.security.authentication.AuthenticationMethodNotSupportedException">
	<redirect view-id="/error.xhtml">
		<message severity="error">#{messages['es.um.atica.security.authentication.AuthenticationMethodNotSupportedException']}</message>
	</redirect>
</exception>
  • Sin etiquetas