@Nonnull @Override public JwtJsonBuilder jsonBuilder() { return new JsonSmartJwtJsonBuilder(); } }
public JsonSmartJwtJsonBuilder() { issuedAt(TimeUtil.currentTimeSeconds()); expirationTime(TimeUtil.currentTimePlusNSeconds(180)); // default JWT lifetime is 3 minutes }
@SuppressWarnings("unchecked") @Nonnull @Override public JwtJsonBuilder claim(@Nonnull String name, @Nonnull Object obj) { Object current = json.get(name); json.put(name, merge(name, current, obj)); return this; }
public static String generateJwtSignature(HttpMethod httpMethod, URI uri, String addonKey, String secret, String contextPath, String subject) throws UnsupportedEncodingException, NoSuchAlgorithmException { JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); JwtWriter jwtWriter = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, secret); // Parse param values and build a map final List<NameValuePair> rawParams = URLEncodedUtils.parse(uri, "UTF-8"); final ImmutableMultimap.Builder<String, String> builder = ImmutableMultimap.builder(); for (NameValuePair rawParam : rawParams) { builder.put(rawParam.getName(), rawParam.getValue()); } final ImmutableMap.Builder<String, String[]> paramsMap = ImmutableMap.builder(); for (Map.Entry<String, Collection<String>> stringCollectionEntry : builder.build().asMap().entrySet()) { final Collection<String> collection = stringCollectionEntry.getValue(); paramsMap.put(stringCollectionEntry.getKey(), collection.toArray(new String[collection.size()])); } final JwtJsonBuilder jsonBuilder = new JsonSmartJwtJsonBuilder() .issuer(addonKey) .queryHash(HttpRequestCanonicalizer.computeCanonicalRequestHash(new CanonicalHttpUriRequest(httpMethod.name(), uri.getPath(), URI.create(contextPath).getPath(), paramsMap.build()))); if (null != subject) { jsonBuilder.subject(subject); } return jwtWriter.jsonToJwt(jsonBuilder.build()); } }
@Nonnull public static String generateJwtToken(TenantContext tenantContext, HttpMethod httpMethod, final URL url) throws UnsupportedEncodingException { final long issuedAt = System.currentTimeMillis() / 1000L; final long expiresAt = issuedAt + 180L; JwtJsonBuilder jwtBuilder = new JsonSmartJwtJsonBuilder() .issuedAt(issuedAt) .expirationTime(expiresAt) .issuer(tenantContext.getKey()); CanonicalHttpUriRequest canonical = new CanonicalHttpUriRequest(httpMethod.toString(), URLUtil.buildPath(url), "/", //Apparently no context is required so skip it. URLUtil.buildQueryValueMap(url)); try { JwtClaimsBuilder.appendHttpRequestClaims(jwtBuilder, canonical); } catch (UnsupportedEncodingException | NoSuchAlgorithmException e) { log.error("Failed to append HTTP request claims", e); } JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); String jwtbuilt = jwtBuilder.build(); String jwtToken = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, tenantContext.getSharedSecret()).jsonToJwt(jwtbuilt); return jwtToken; } }
public static String generateJwtSignature(HttpMethod httpMethod, URI uri, String addonKey, String secret, String contextPath, String subject) throws UnsupportedEncodingException, NoSuchAlgorithmException { JwtWriterFactory jwtWriterFactory = new NimbusJwtWriterFactory(); JwtWriter jwtWriter = jwtWriterFactory.macSigningWriter(SigningAlgorithm.HS256, secret); // Parse param values and build a map final List<NameValuePair> rawParams = URLEncodedUtils.parse(uri, "UTF-8"); final ImmutableMultimap.Builder<String, String> builder = ImmutableMultimap.builder(); for (NameValuePair rawParam : rawParams) { builder.put(rawParam.getName(), rawParam.getValue()); } final ImmutableMap.Builder<String, String[]> paramsMap = ImmutableMap.builder(); for (Map.Entry<String, Collection<String>> stringCollectionEntry : builder.build().asMap().entrySet()) { final Collection<String> collection = stringCollectionEntry.getValue(); paramsMap.put(stringCollectionEntry.getKey(), collection.toArray(new String[collection.size()])); } final JwtJsonBuilder jsonBuilder = new JsonSmartJwtJsonBuilder() .issuer(addonKey) .queryHash(HttpRequestCanonicalizer.computeCanonicalRequestHash(new CanonicalHttpUriRequest(httpMethod.name(), uri.getPath(), URI.create(contextPath).getPath(), paramsMap.build()))); if (null != subject) { jsonBuilder.subject(subject); } return jwtWriter.jsonToJwt(jsonBuilder.build()); } }
@SuppressWarnings("unchecked") private Object merge(String name, Object first, Object second) { if (first instanceof List && second instanceof List) { List merged = new ArrayList((List) first); merged.addAll((List) second); return merged; } else if (first instanceof Map && second instanceof Map) { Map merged = new HashMap((Map) first); // merge each of the entries in second recursively Set<Map.Entry> entries = ((Map) second).entrySet(); for (Map.Entry entry : entries) { merged.put(entry.getKey(), merge(name + "." + entry.getKey(), merged.get(entry.getKey()), entry.getValue())); } return merged; } if (first != null && second != null && !com.google.common.base.Objects.equal(first, second)) { throw new IllegalStateException("Cannot set claim '" + name + "' to '" + second + "'; it's already set as '" + first + "'"); } return second == null ? first : second; } }