]> WPIA git - gigi.git/blob - src/org/cacert/gigi/pages/account/MailCertificates.java
Implement serial based retrival and certificate access control.
[gigi.git] / src / org / cacert / gigi / pages / account / MailCertificates.java
1 package org.cacert.gigi.pages.account;
2
3 import java.io.IOException;
4 import java.io.PrintWriter;
5 import java.security.GeneralSecurityException;
6 import java.sql.PreparedStatement;
7 import java.sql.ResultSet;
8 import java.sql.SQLException;
9 import java.util.HashMap;
10
11 import javax.servlet.http.HttpServletRequest;
12 import javax.servlet.http.HttpServletResponse;
13
14 import org.cacert.gigi.Certificate;
15 import org.cacert.gigi.User;
16 import org.cacert.gigi.database.DatabaseConnection;
17 import org.cacert.gigi.output.CertificateTable;
18 import org.cacert.gigi.pages.LoginPage;
19 import org.cacert.gigi.pages.Page;
20
21 public class MailCertificates extends Page {
22         CertificateTable myTable = new CertificateTable("mailcerts");
23         public static final String PATH = "/account/certs/email";
24
25         public MailCertificates() {
26                 super("Email Certificates");
27         }
28
29         @Override
30         public void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {
31                 PrintWriter out = resp.getWriter();
32                 String pi = req.getPathInfo().substring(PATH.length());
33                 if (pi.length() != 0) {
34                         pi = pi.substring(1);
35                         int id = Integer.parseInt(pi);
36                         Certificate c = new Certificate(id);
37                         if (LoginPage.getUser(req).getId() != c.getOwnerId()) {
38                                 out.println(translate(req, "You do not own this certificate."));
39                                 return;
40                         }
41                         out.println("<pre>");
42                         try {
43                                 out.print(c.cert());
44                         } catch (GeneralSecurityException e) {
45                                 e.printStackTrace();
46                         } catch (SQLException e) {
47                                 e.printStackTrace();
48                         }
49                         out.println("</pre>");
50                         return;
51                 }
52
53                 HashMap<String, Object> vars = new HashMap<String, Object>();
54                 User us = LoginPage.getUser(req);
55                 try {
56                         PreparedStatement ps = DatabaseConnection.getInstance().prepare(
57                                 "SELECT `id`, `CN`, `serial`, `revoked`, `expire`, `disablelogin` FROM `emailcerts` WHERE `memid`=?");
58                         ps.setInt(1, us.getId());
59                         ResultSet rs = ps.executeQuery();
60                         vars.put("mailcerts", rs);
61                         myTable.output(out, getLanguage(req), vars);
62                         rs.close();
63                 } catch (SQLException e) {
64                         e.printStackTrace();
65                 }
66         }
67
68 }