1 package org.cacert.gigi.output.template;
3 import java.io.IOException;
4 import java.io.PrintWriter;
5 import java.util.HashMap;
8 import javax.servlet.http.HttpServletRequest;
9 import javax.servlet.http.HttpSession;
11 import org.cacert.gigi.GigiApiException;
12 import org.cacert.gigi.localisation.Language;
13 import org.cacert.gigi.pages.LoginPage;
14 import org.cacert.gigi.util.RandomToken;
17 * A generic HTML-form that handles CSRF-token creation.
19 public abstract class Form implements Outputable {
21 public static final String CSRF_FIELD = "csrf";
23 private final String csrf;
25 private final String action;
28 * Creates a new {@link Form}.
31 * the request to register the form against.
33 public Form(HttpServletRequest hsr) {
38 * Creates a new {@link Form}.
41 * the request to register the form against.
43 * the target path where the form should be submitted.
45 public Form(HttpServletRequest hsr, String action) {
46 csrf = RandomToken.generateToken(32);
48 HttpSession hs = hsr.getSession();
49 hs.setAttribute("form/" + getClass().getName() + "/" + csrf, this);
53 * Update the forms internal state based on submitted data.
56 * the stream to the user.
58 * the request to take the initial data from.
59 * @return true, iff the form succeeded and the user should be redirected.
60 * @throws GigiApiException
61 * if internal operations went wrong.
63 public abstract boolean submit(PrintWriter out, HttpServletRequest req) throws GigiApiException;
66 * Calls {@link #submit(PrintWriter, HttpServletRequest)} while catching and
67 * displaying errors ({@link GigiApiException}), and re-outputing the form
68 * via {@link #output(PrintWriter, Language, Map)}.
71 * the target to write the form and errors to
73 * the request that this submit originated (for submit and for
75 * @return as {@link #submit(PrintWriter, HttpServletRequest)}: true, iff
76 * the form succeeded and the user should be redirected.
78 public boolean submitProtected(PrintWriter out, HttpServletRequest req) {
80 boolean succeeded = submit(out, req);
84 } catch (GigiApiException e) {
85 e.format(out, LoginPage.getLanguage(req));
87 output(out, LoginPage.getLanguage(req), new HashMap<String, Object>());
91 protected String getCsrfFieldName() {
96 public void output(PrintWriter out, Language l, Map<String, Object> vars) {
98 out.println("<form method='POST'>");
100 out.println("<form method='POST' action='" + action + "'>");
102 outputContent(out, l, vars);
103 out.print("<input type='hidden' name='" + CSRF_FIELD + "' value='");
104 out.print(getCSRFToken());
105 out.println("'></form>");
109 * Outputs the forms contents.
112 * Stream to the user.
114 * {@link Language} to translate text to.
116 * Variables supplied from the outside.
118 protected abstract void outputContent(PrintWriter out, Language l, Map<String, Object> vars);
120 protected String getCSRFToken() {
125 * Re-fetches a form e.g. when a Post-request is received.
128 * the request that is directed to the form.
130 * the {@link Class} of the expected form.
131 * @return the form where this request is directed to.
132 * @throws CSRFException
133 * if no CSRF-token is found or the token is wrong.
135 @SuppressWarnings("unchecked")
136 public static <T extends Form> T getForm(HttpServletRequest req, Class<T> target) throws CSRFException {
137 String csrf = req.getParameter(CSRF_FIELD);
139 throw new CSRFException();
141 HttpSession hs = req.getSession();
143 throw new CSRFException();
145 Object f = hs.getAttribute("form/" + target.getName() + "/" + csrf);
147 throw new CSRFException();
149 if ( !(f instanceof Form)) {
150 throw new CSRFException();
152 if ( !target.isInstance(f)) {
153 throw new CSRFException();
155 // Dynamic Cast checked by previous if statement
159 public static class CSRFException extends IOException {
161 private static final long serialVersionUID = 59708247477988362L;