1 package org.cacert.gigi.output.template;
3 import java.io.IOException;
4 import java.io.PrintWriter;
7 import javax.servlet.http.HttpServletRequest;
8 import javax.servlet.http.HttpSession;
10 import org.cacert.gigi.GigiApiException;
11 import org.cacert.gigi.localisation.Language;
12 import org.cacert.gigi.util.RandomToken;
15 * A generic HTML-form that handles CSRF-token creation.
17 public abstract class Form implements Outputable {
19 public static final String CSRF_FIELD = "csrf";
21 private final String csrf;
23 private final String action;
26 * Creates a new {@link Form}.
29 * the request to register the form against.
31 public Form(HttpServletRequest hsr) {
36 * Creates a new {@link Form}.
39 * the request to register the form against.
41 * the target path where the form should be submitted.
43 public Form(HttpServletRequest hsr, String action) {
44 csrf = RandomToken.generateToken(32);
46 HttpSession hs = hsr.getSession();
47 hs.setAttribute("form/" + getClass().getName() + "/" + csrf, this);
51 * Update the forms internal state based on submitted data.
54 * the stream to the user.
56 * the request to take the initial data from.
57 * @return true, iff the form succeeded and the user should be redirected.
58 * @throws GigiApiException
59 * if internal operations went wrong.
61 public abstract boolean submit(PrintWriter out, HttpServletRequest req) throws GigiApiException;
63 protected String getCsrfFieldName() {
68 public void output(PrintWriter out, Language l, Map<String, Object> vars) {
70 out.println("<form method='POST'>");
72 out.println("<form method='POST' action='" + action + "'>");
74 outputContent(out, l, vars);
75 out.print("<input type='hidden' name='" + CSRF_FIELD + "' value='");
76 out.print(getCSRFToken());
77 out.println("'></form>");
81 * Outputs the forms contents.
86 * {@link Language} to translate text to.
88 * Variables supplied from the outside.
90 protected abstract void outputContent(PrintWriter out, Language l, Map<String, Object> vars);
92 protected String getCSRFToken() {
97 * Re-fetches a form e.g. when a Post-request is received.
100 * the request that is directed to the form.
102 * the {@link Class} of the expected form.
103 * @return the form where this request is directed to.
104 * @throws CSRFException
105 * if no CSRF-token is found or the token is wrong.
107 @SuppressWarnings("unchecked")
108 public static <T extends Form> T getForm(HttpServletRequest req, Class<T> target) throws CSRFException {
109 String csrf = req.getParameter(CSRF_FIELD);
111 throw new CSRFException();
113 HttpSession hs = req.getSession();
115 throw new CSRFException();
117 Object f = hs.getAttribute("form/" + target.getName() + "/" + csrf);
119 throw new CSRFException();
121 if ( !(f instanceof Form)) {
122 throw new CSRFException();
124 if ( !target.isInstance(f)) {
125 throw new CSRFException();
127 // Dynamic Cast checked by previous if statement
131 public static class CSRFException extends IOException {
133 private static final long serialVersionUID = 59708247477988362L;