How to send username and password to callback handler and how to invoke login module?

Viewed 134

I want to access the web page view1.jsp

The web.xml file is

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://xmlns.jcp.org/xml/ns/javaee" xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd" id="WebApp_ID" version="3.1">
  <display-name>library management system</display-name>
  <login-config>
     <auth-method>FORM</auth-method>
     <realm-name>jaascon</realm-name>
     <form-login-config>
          <form-login-page>/login.jsp</form-login-page>
          <form-error-page>/error.jsp</form-error-page>
     </form-login-config>
</login-config>
<security-role>
    <role-name>*</role-name>
</security-role>
<security-constraint>
    <web-resource-collection>
         <web-resource-name>test</web-resource-name>
         <url-pattern>/view1.jsp</url-pattern>
         <http-method>POST</http-method>
         <http-method>GET</http-method>
    </web-resource-collection>
    <auth-constraint>
         <role-name>*</role-name>
    </auth-constraint>
</security-constraint>
</web-app>




The login module is

package p1;
import java.io.IOException;
import java.util.ArrayList;
import java.util.List;
import java.util.Map;

import javax.security.auth.Subject;
import javax.security.auth.callback.Callback;
import javax.security.auth.callback.CallbackHandler;
import javax.security.auth.callback.NameCallback;
import javax.security.auth.callback.PasswordCallback;
import javax.security.auth.callback.UnsupportedCallbackException;
import javax.security.auth.login.FailedLoginException;
import javax.security.auth.login.LoginException;
import javax.security.auth.spi.LoginModule;
import p1.cbhandler;
import p1.roleprincipal;
import p1.userprincipal;
import java.sql.*;

public class lgmodule implements LoginModule {

  private CallbackHandler handler;
  private Subject subject;
  private userprincipal userPrincipal;
  private roleprincipal rolePrincipal;
  private String login;
  private ArrayList<String> userGroups =new ArrayList<String>();
   static private String name;
   static private String password;
   static private Map options;
  static boolean f=false;

   @Override
  public void initialize(Subject subject, CallbackHandler handler,
                Map<String, ?> sharedState, Map<String, ?> options) {
        this.subject = subject;
        this.handler = handler;
        this.options=options; 
    }
 
  @Override 
  public boolean login() throws LoginException{
    System.setProperty("java.security.auth.login.config", "C:/apache-tomcat-9.0.62/webapps/test/jaascon.config");
       if (handler == null){
            throw new LoginException("Error: no CallbackHandler available " + "to garner authentication information from the user");
        }
   ArrayList<String> l=new ArrayList<String>();
  l.add("user1");
  l.add("user2");
    Callback[] cbarray=new Callback[2];
    cbarray[0]=new NameCallback("username: ");
    cbarray[1]=new PasswordCallback("password: ",false);
    try {
      handler.handle(cbarray);
    }
    catch(Exception e) {
      e.printStackTrace();
    }
     name=(String)((NameCallback) cbarray[0]).getName(); 
     password=new  String(((PasswordCallback) cbarray[1]).getPassword()); 
        String sql ="select username from usertable where username=? and password=?";
     String sql1="select rolename from rolestable where username=?";
      ResultSet rs = null,rs1=null;
      PreparedStatement stmt = null,stmt1=null;
             boolean b=false;
             String s="";
      try {
        Class.forName("com.mysql.cj.jdbc.Driver");
          Connection con=DriverManager.getConnection("jdbc:mysql://localhost:3306/mydb" ,"root","Dinesh@1972002");    
          stmt = con.prepareStatement(sql);
          stmt.setString(1, name);
          stmt.setString(2, new String(password));  
          rs = stmt.executeQuery(); 
            stmt1=con.prepareStatement(sql1);
            stmt1.setString(1,name);
            rs1=stmt1.executeQuery();
             b=rs1.next();
            s=rs1.getString(1); 
          
          if (rs.next()) { 
              f=true; 
            userGroups.add(s);


          }
          else { 
      System.out.println("authentication failure");

      //throw new FailedLoginException(rs.getString(1));
    }
       } catch (Exception e) {

           throw new LoginException("Error when loading user from the database " +e
            );

       }
   
       return f;
  }


  @Override
  public boolean commit() throws LoginException {

    userPrincipal = new userprincipal(name);
    subject.getPrincipals().add(userPrincipal);

    if (userGroups != null && userGroups.size() > 0) {
      for (String groupName : userGroups) {
        rolePrincipal = new roleprincipal(groupName);
        subject.getPrincipals().add(rolePrincipal);
      }
    }

    return true;
  }

  @Override
  public boolean abort() throws LoginException {     
      return f;
  }

  @Override
  public boolean logout() throws LoginException {
    subject.getPrincipals().remove(userPrincipal);
    subject.getPrincipals().remove(rolePrincipal);
    return true;
 
 
    
}

}

The callback handler file is


package p1;
 
import java.io.IOException;
 
import javax.security.auth.callback.Callback;
import javax.security.auth.callback.CallbackHandler;
import javax.security.auth.callback.NameCallback;
import javax.security.auth.callback.PasswordCallback;
import javax.security.auth.callback.UnsupportedCallbackException;
 
 

 public class cbhandler implements CallbackHandler {
 





 
 private String username = null;
 private String password = null;
  
 
 public cbhandler(String username, String password) {
     this.username = username;
     this.password = password;
 }
 
 
 @Override
 public void handle(Callback[] callbacks) throws IOException,
   UnsupportedCallbackException {
   //System.setProperty("java.security.auth.login.config","C:/apache-tomcat-9.0.62/webapps/test/jaascon.config");

 
   
     for (int i = 0; i < callbacks.length; i++) {
        if (callbacks[i] instanceof NameCallback) {
           NameCallback nameCallback = (NameCallback) callbacks[i];
           nameCallback.setName(username);
        } else if (callbacks[i] instanceof PasswordCallback) {
           PasswordCallback passwordCallback = (PasswordCallback) callbacks[i];
           passwordCallback.setPassword(password.toCharArray());
        } else {
           throw new UnsupportedCallbackException(callbacks[i], "The submitted Callback is unsupported");
        }
     }
 }
}

The login.jsp page is


<!DOCTYPE html>
<html>
<head>
    <style>
        div{
            margin: 100px;
            padding: 100px;
            background-color: dodgerblue;
        }
    </style>
</head>
<body>
<h1 style="display: flex;justify-content: center;">Login</h1>
<div>
<div style="position:relative;left:100px">
<form name="loginform" action="j_security_check" method="Post">
enter user name:<input type="text" name="j_username"><br>
enter password:<input type="password" name="j_password"><br>
<input name="login" type="submit" value="LOGIN" id="submit" class="button blue">
</div>
</div>
</form>

The configuration file(jaascon.config) is

jaascon{
  p1.lgmodule required 
 debug=true;
};

I want to authenticate my webapp using java authentication and authorization system(jaas). How to send username and password to callback handler and how the login method will be invoked?.

0 Answers
Related