import org.cacert.gigi.dbObjects.CACertificate;
import org.cacert.gigi.dbObjects.CertificateProfile;
import org.cacert.gigi.dbObjects.DomainPingConfiguration;
-import org.cacert.gigi.dbObjects.User;
import org.cacert.gigi.localisation.Language;
import org.cacert.gigi.output.Menu;
+import org.cacert.gigi.output.MenuCollector;
import org.cacert.gigi.output.PageMenuItem;
import org.cacert.gigi.output.SimpleMenuItem;
import org.cacert.gigi.output.template.Form.CSRFException;
import org.cacert.gigi.pages.LogoutPage;
import org.cacert.gigi.pages.MainPage;
import org.cacert.gigi.pages.Page;
-import org.cacert.gigi.pages.PolicyIndex;
+import org.cacert.gigi.pages.PasswordResetPage;
import org.cacert.gigi.pages.RootCertPage;
import org.cacert.gigi.pages.StaticPage;
import org.cacert.gigi.pages.TestSecure;
import org.cacert.gigi.pages.Verify;
import org.cacert.gigi.pages.account.ChangePasswordPage;
+import org.cacert.gigi.pages.account.History;
import org.cacert.gigi.pages.account.MyDetails;
+import org.cacert.gigi.pages.account.UserTrainings;
import org.cacert.gigi.pages.account.certs.CertificateAdd;
import org.cacert.gigi.pages.account.certs.Certificates;
import org.cacert.gigi.pages.account.domain.DomainOverview;
import org.cacert.gigi.pages.admin.TTPAdminPage;
import org.cacert.gigi.pages.admin.support.FindDomainPage;
import org.cacert.gigi.pages.admin.support.FindUserPage;
+import org.cacert.gigi.pages.admin.support.SupportEnterTicketPage;
import org.cacert.gigi.pages.admin.support.SupportUserDetailsPage;
import org.cacert.gigi.pages.error.AccessDenied;
import org.cacert.gigi.pages.error.PageNotFound;
import org.cacert.gigi.pages.orga.CreateOrgPage;
import org.cacert.gigi.pages.orga.ViewOrgPage;
import org.cacert.gigi.pages.wot.AssurePage;
+import org.cacert.gigi.pages.wot.MyListingPage;
import org.cacert.gigi.pages.wot.MyPoints;
import org.cacert.gigi.pages.wot.RequestTTPPage;
import org.cacert.gigi.ping.PingerDaemon;
+import org.cacert.gigi.util.AuthorizationContext;
import org.cacert.gigi.util.ServerConstants;
-public class Gigi extends HttpServlet {
+public final class Gigi extends HttpServlet {
private class MenuBuilder {
private HashMap<String, Page> pages = new HashMap<String, Page>();
- private Menu rootMenu;
+ private MenuCollector rootMenu;
public MenuBuilder() {}
return m;
}
- public Menu generateMenu() throws ServletException {
+ public MenuCollector generateMenu() throws ServletException {
putPage("/denied", new AccessDenied(), null);
putPage("/error", new PageNotFound(), null);
- putPage("/login", new LoginPage("Password Login"), "CAcert.org");
- getMenu("CAcert.org").addItem(new SimpleMenuItem("https://" + ServerConstants.getSecureHostNamePort() + "/login", "Certificate Login") {
+ putPage("/login", new LoginPage(), null);
+ getMenu("SomeCA.org").addItem(new SimpleMenuItem("https://" + ServerConstants.getWwwHostNamePort() + "/login", "Password Login") {
@Override
- public boolean isPermitted(User u) {
- return u == null;
+ public boolean isPermitted(AuthorizationContext ac) {
+ return ac == null;
}
});
- putPage("/", new MainPage("CAcert - Home"), null);
- putPage("/roots", new RootCertPage(truststore), "CAcert.org");
- putPage(ChangePasswordPage.PATH, new ChangePasswordPage(), "My Account");
- putPage(LogoutPage.PATH, new LogoutPage("Logout"), "My Account");
+ getMenu("SomeCA.org").addItem(new SimpleMenuItem("https://" + ServerConstants.getSecureHostNamePort() + "/login", "Certificate Login") {
+
+ @Override
+ public boolean isPermitted(AuthorizationContext ac) {
+ return ac == null;
+ }
+ });
+ putPage("/", new MainPage(), null);
+ putPage("/roots", new RootCertPage(truststore), "SomeCA.org");
+
putPage("/secure", new TestSecure(), null);
putPage(Verify.PATH, new Verify(), null);
- putPage(AssurePage.PATH + "/*", new AssurePage(), "Web of Trust");
putPage(Certificates.PATH + "/*", new Certificates(), "Certificates");
- putPage(MyDetails.PATH, new MyDetails(), "My Account");
- putPage(RegisterPage.PATH, new RegisterPage(), "CAcert.org");
+ putPage(RegisterPage.PATH, new RegisterPage(), "SomeCA.org");
putPage(CertificateAdd.PATH, new CertificateAdd(), "Certificates");
- putPage(MailOverview.DEFAULT_PATH, new MailOverview("My email addresses"), "Certificates");
- putPage(DomainOverview.PATH + "*", new DomainOverview("Domains"), "Certificates");
- putPage(MyPoints.PATH, new MyPoints("My Points"), "Web of Trust");
+ putPage(MailOverview.DEFAULT_PATH, new MailOverview(), "Certificates");
+ putPage(DomainOverview.PATH + "*", new DomainOverview(), "Certificates");
+
+ putPage(AssurePage.PATH + "/*", new AssurePage(), "Web of Trust");
+ putPage(MyPoints.PATH, new MyPoints(), "Web of Trust");
+ putPage(MyListingPage.PATH, new MyListingPage(), "Web of Trust");
putPage(RequestTTPPage.PATH, new RequestTTPPage(), "Web of Trust");
+
putPage(TTPAdminPage.PATH + "/*", new TTPAdminPage(), "Admin");
putPage(CreateOrgPage.DEFAULT_PATH, new CreateOrgPage(), "Organisation Admin");
putPage(ViewOrgPage.DEFAULT_PATH + "/*", new ViewOrgPage(), "Organisation Admin");
- putPage(FindDomainPage.PATH, new FindDomainPage("Find Domain"), "System Admin");
- putPage(FindUserPage.PATH, new FindUserPage("Find User"), "System Admin");
- putPage(SupportUserDetailsPage.PATH + "*", new SupportUserDetailsPage("Support: User Details"), null);
+
+ putPage(SupportEnterTicketPage.PATH, new SupportEnterTicketPage(), "Support Console");
+ putPage(FindUserPage.PATH, new FindUserPage(), "Support Console");
+ putPage(FindDomainPage.PATH, new FindDomainPage(), "Support Console");
+
+ putPage(SupportUserDetailsPage.PATH + "*", new SupportUserDetailsPage(), null);
+ putPage(ChangePasswordPage.PATH, new ChangePasswordPage(), "My Account");
+ putPage(LogoutPage.PATH, new LogoutPage(), "My Account");
+ putPage(History.PATH, new History(false), "My Account");
+ putPage(History.SUPPORT_PATH, new History(true), null);
+ putPage(UserTrainings.PATH, new UserTrainings(false), "My Account");
+ putPage(MyDetails.PATH, new MyDetails(), "My Account");
+ putPage(UserTrainings.SUPPORT_PATH, new UserTrainings(true), null);
+
+ putPage(PasswordResetPage.PATH, new PasswordResetPage(), null);
+
if (testing) {
try {
Class<?> manager = Class.forName("org.cacert.gigi.pages.Manager");
throw new ServletException(e);
}
baseTemplate = new Template(Gigi.class.getResource("Gigi.templ"));
- rootMenu = new Menu("Main");
- Menu about = new Menu("About CAcert.org");
- categories.add(about);
-
- about.addItem(new SimpleMenuItem("//blog.cacert.org/", "CAcert News"));
- about.addItem(new SimpleMenuItem("//wiki.cacert.org/", "Wiki Documentation"));
- putPage(PolicyIndex.DEFAULT_PATH, new PolicyIndex(), "About CAcert.org");
- about.addItem(new SimpleMenuItem("//wiki.cacert.org/FAQ/Privileges", "Point System"));
- about.addItem(new SimpleMenuItem("//bugs.cacert.org/", "Bug Database"));
- about.addItem(new SimpleMenuItem("//wiki.cacert.org/Board", "CAcert Board"));
- about.addItem(new SimpleMenuItem("//lists.cacert.org/wws", "Mailing Lists"));
- about.addItem(new SimpleMenuItem("//blog.CAcert.org/feed", "RSS News Feed"));
+ rootMenu = new MenuCollector();
Menu languages = new Menu("Translations");
for (Locale l : Language.getSupportedLocales()) {
categories.add(languages);
for (Menu menu : categories) {
menu.prepare();
- rootMenu.addItem(menu);
+ rootMenu.put(menu);
}
- rootMenu.prepare();
+ // rootMenu.prepare();
return rootMenu;
}
public static final String CERT_ISSUER = "org.cacert.gigi.issuer";
- public static final String USER = "user";
+ public static final String AUTH_CONTEXT = "auth";
public static final String LOGIN_METHOD = "org.cacert.gigi.loginMethod";
private boolean testing;
- private Menu rootMenu;
+ private MenuCollector rootMenu;
private Map<String, Page> pages;
return page;
}
int idx = pathInfo.lastIndexOf('/');
+ if (idx == -1 || idx == 0) {
+ return null;
+ }
page = pages.get(pathInfo.substring(0, idx) + "/*");
if (page != null) {
return page;
}
-
- int lIdx = pathInfo.lastIndexOf('/', idx);
+ int lIdx = pathInfo.lastIndexOf('/', idx - 1);
if (lIdx == -1) {
return null;
}
- page = pages.get(pathInfo.substring(0, lIdx) + "/" + pathInfo.substring(idx));
+ String lastResort = pathInfo.substring(0, lIdx) + "/*" + pathInfo.substring(idx);
+ page = pages.get(lastResort);
return page;
}
@Override
protected void service(final HttpServletRequest req, final HttpServletResponse resp) throws ServletException, IOException {
- boolean isSecure = req.getServerPort() == ServerConstants.getSecurePort();
+ boolean isSecure = req.isSecure();
addXSSHeaders(resp, isSecure);
// Firefox only sends this, if it's a cross domain access; safari sends
// it always
resp.sendRedirect("https://" + ServerConstants.getWwwHostNamePortSecure() + req.getPathInfo());
return;
}
- User currentPageUser = LoginPage.getUser(req);
- if ( !p.isPermitted(currentPageUser)) {
+ AuthorizationContext currentAuthContext = LoginPage.getAuthorizationContext(req);
+ if ( !p.isPermitted(currentAuthContext)) {
if (hs.getAttribute("loggedin") == null) {
String request = req.getPathInfo();
request = request.split("\\?")[0];
return;
}
HashMap<String, Object> vars = new HashMap<String, Object>();
+ // System.out.println(req.getMethod() + ": " + req.getPathInfo() +
+ // " -> " + p);
Outputable content = new Outputable() {
@Override
};
Language lang = Page.getLanguage(req);
- vars.put(Menu.USER_VALUE, currentPageUser);
+ vars.put(Menu.AUTH_VALUE, currentAuthContext);
vars.put("menu", rootMenu);
vars.put("title", lang.getTranslation(p.getTitle()));
vars.put("static", getStaticTemplateVar(isSecure));
vars.put("year", Calendar.getInstance().get(Calendar.YEAR));
vars.put("content", content);
- if (currentPageUser != null) {
- vars.put("loggedInAs", currentPageUser.getName().toString());
- vars.put("loginMethod", lang.getTranslation((String) req.getSession().getAttribute(LOGIN_METHOD)));
+ if (currentAuthContext != null) {
+ // TODO maybe move this information into the AuthContext object
+ vars.put("loginMethod", req.getSession().getAttribute(LOGIN_METHOD));
+ vars.put("authContext", currentAuthContext);
+
}
resp.setContentType("text/html; charset=utf-8");
baseTemplate.output(resp.getWriter(), lang, vars);
csp.append(";script-src https://" + ServerConstants.getStaticHostNamePortSecure());
csp.append(";style-src https://" + ServerConstants.getStaticHostNamePortSecure());
csp.append(";form-action https://" + ServerConstants.getSecureHostNamePort() + " https://" + ServerConstants.getWwwHostNamePortSecure());
- csp.append(";report-url https://api.cacert.org/security/csp/report");
+ // csp.append(";report-url https://api.cacert.org/security/csp/report");
return csp.toString();
}
csp.append(";script-src http://" + ServerConstants.getStaticHostNamePort());
csp.append(";style-src http://" + ServerConstants.getStaticHostNamePort());
csp.append(";form-action https://" + ServerConstants.getSecureHostNamePort() + " https://" + ServerConstants.getWwwHostNamePort());
- csp.append(";report-url http://api.cacert.org/security/csp/report");
+ // csp.append(";report-url http://api.cacert.org/security/csp/report");
return csp.toString();
}