1 package org.cacert.gigi.output.template;
3 import java.io.IOException;
4 import java.io.PrintWriter;
5 import java.util.HashMap;
8 import javax.servlet.http.HttpServletRequest;
9 import javax.servlet.http.HttpSession;
11 import org.cacert.gigi.GigiApiException;
12 import org.cacert.gigi.localisation.Language;
13 import org.cacert.gigi.pages.LoginPage;
14 import org.cacert.gigi.pages.Page;
15 import org.cacert.gigi.util.RandomToken;
18 * A generic HTML-form that handles CSRF-token creation.
20 public abstract class Form implements Outputable {
22 public static class PermamentFormException extends RuntimeException {
24 public PermamentFormException(GigiApiException cause) {
29 public synchronized GigiApiException getCause() {
30 return (GigiApiException) super.getCause();
34 public static final String CSRF_FIELD = "csrf";
36 private static final String SUBMIT_EXCEPTION = "form-submit-exception";
38 private final String csrf;
40 private final String action;
43 * Creates a new {@link Form}.
46 * the request to register the form against.
48 public Form(HttpServletRequest hsr) {
53 * Creates a new {@link Form}.
56 * the request to register the form against.
58 * the target path where the form should be submitted.
60 public Form(HttpServletRequest hsr, String action) {
61 csrf = RandomToken.generateToken(32);
63 HttpSession hs = hsr.getSession();
64 hs.setAttribute("form/" + getClass().getName() + "/" + csrf, this);
68 * Update the forms internal state based on submitted data.
71 * the request to take the initial data from.
72 * @return true, iff the form succeeded and the user should be redirected.
73 * @throws GigiApiException
74 * if form data had problems or operations went wrong.
76 public abstract boolean submit(HttpServletRequest req) throws GigiApiException;
79 * Calls {@link #submit(PrintWriter, HttpServletRequest)} while catching and
80 * displaying errors ({@link GigiApiException}), and re-outputing the form
81 * via {@link #output(PrintWriter, Language, Map)}.
84 * the target to write the form and errors to
86 * the request that this submit originated (for submit and for
88 * @return as {@link #submit(PrintWriter, HttpServletRequest)}: true, iff
89 * the form succeeded and the user should be redirected.
91 public boolean submitProtected(PrintWriter out, HttpServletRequest req) {
93 boolean succeeded = submit(req);
95 HttpSession hs = req.getSession();
96 hs.removeAttribute("form/" + getClass().getName() + "/" + csrf);
99 } catch (GigiApiException e) {
100 e.format(out, LoginPage.getLanguage(req));
102 output(out, LoginPage.getLanguage(req), new HashMap<String, Object>());
106 public boolean submitExceptionProtected(HttpServletRequest req) {
109 HttpSession hs = req.getSession();
110 hs.removeAttribute("form/" + getClass().getName() + "/" + csrf);
114 } catch (PermamentFormException e) {
115 req.setAttribute(SUBMIT_EXCEPTION, e);
117 } catch (GigiApiException e) {
118 req.setAttribute(SUBMIT_EXCEPTION, e);
124 * Prints any errors in any form submits on this request.
127 * The request to extract the errors from.
129 * the output stream to the user to write the errors to.
130 * @return true if no permanent errors occurred and the form should be
133 public static boolean printFormErrors(HttpServletRequest req, PrintWriter out) {
134 Object o = req.getAttribute(SUBMIT_EXCEPTION);
135 if (o != null && (o instanceof PermamentFormException)) {
136 ((PermamentFormException) o).getCause().format(out, Page.getLanguage(req));
139 if (o != null && (o instanceof GigiApiException)) {
140 ((GigiApiException) o).format(out, Page.getLanguage(req));
145 protected String getCsrfFieldName() {
150 public void output(PrintWriter out, Language l, Map<String, Object> vars) {
151 if (action == null) {
152 out.println("<form method='POST'>");
154 out.println("<form method='POST' action='" + action + "'>");
156 outputContent(out, l, vars);
157 out.print("<input type='hidden' name='" + CSRF_FIELD + "' value='");
158 out.print(getCSRFToken());
159 out.println("'></form>");
163 * Outputs the forms contents.
166 * Stream to the user.
168 * {@link Language} to translate text to.
170 * Variables supplied from the outside.
172 protected abstract void outputContent(PrintWriter out, Language l, Map<String, Object> vars);
174 protected String getCSRFToken() {
179 * Re-fetches a form e.g. when a Post-request is received.
182 * the request that is directed to the form.
184 * the {@link Class} of the expected form.
185 * @return the form where this request is directed to.
186 * @throws CSRFException
187 * if no CSRF-token is found or the token is wrong.
189 @SuppressWarnings("unchecked")
190 public static <T extends Form> T getForm(HttpServletRequest req, Class<T> target) throws CSRFException {
191 String csrf = req.getParameter(CSRF_FIELD);
193 throw new CSRFException();
195 HttpSession hs = req.getSession();
197 throw new CSRFException();
199 Object f = hs.getAttribute("form/" + target.getName() + "/" + csrf);
201 throw new CSRFException();
203 if ( !(f instanceof Form)) {
204 throw new CSRFException();
206 if ( !target.isInstance(f)) {
207 throw new CSRFException();
209 // Dynamic Cast checked by previous if statement
213 public static class CSRFException extends IOException {
215 private static final long serialVersionUID = 59708247477988362L;