1   /**
2    * Copyright (c) 2000-2009 Liferay, Inc. All rights reserved.
3    *
4    * Permission is hereby granted, free of charge, to any person obtaining a copy
5    * of this software and associated documentation files (the "Software"), to deal
6    * in the Software without restriction, including without limitation the rights
7    * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
8    * copies of the Software, and to permit persons to whom the Software is
9    * furnished to do so, subject to the following conditions:
10   *
11   * The above copyright notice and this permission notice shall be included in
12   * all copies or substantial portions of the Software.
13   *
14   * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15   * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16   * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17   * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18   * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19   * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20   * SOFTWARE.
21   */
22  
23  package com.liferay.portal.servlet.filters.sso.ntlm;
24  
25  import com.liferay.portal.kernel.log.Log;
26  import com.liferay.portal.kernel.log.LogFactoryUtil;
27  import com.liferay.portal.kernel.servlet.BrowserSnifferUtil;
28  import com.liferay.portal.kernel.servlet.HttpHeaders;
29  import com.liferay.portal.kernel.servlet.HttpMethods;
30  import com.liferay.portal.kernel.util.GetterUtil;
31  import com.liferay.portal.security.ldap.PortalLDAPUtil;
32  import com.liferay.portal.servlet.filters.BasePortalFilter;
33  import com.liferay.portal.util.PortalInstances;
34  
35  import javax.servlet.FilterChain;
36  import javax.servlet.http.HttpServletRequest;
37  import javax.servlet.http.HttpServletResponse;
38  
39  import jcifs.ntlmssp.Type1Message;
40  import jcifs.ntlmssp.Type2Message;
41  
42  import jcifs.util.Base64;
43  
44  /**
45   * <a href="NtlmPostFilter.java.html"><b><i>View Source</i></b></a>
46   *
47   * @author Brian Wing Shun Chan
48   *
49   */
50  public class NtlmPostFilter extends BasePortalFilter {
51  
52      protected Log getLog() {
53          return _log;
54      }
55  
56      protected void processFilter(
57              HttpServletRequest request, HttpServletResponse response,
58              FilterChain filterChain)
59          throws Exception {
60  
61          long companyId = PortalInstances.getCompanyId(request);
62  
63          if (PortalLDAPUtil.isNtlmEnabled(companyId) &&
64              BrowserSnifferUtil.isIe(request) &&
65              request.getMethod().equals(HttpMethods.POST)) {
66  
67              String authorization = GetterUtil.getString(
68                  request.getHeader(HttpHeaders.AUTHORIZATION));
69  
70              if (authorization.startsWith("NTLM ")) {
71                  byte[] src = Base64.decode(authorization.substring(5));
72  
73                  if (src[8] == 1) {
74                      Type1Message type1 = new Type1Message(src);
75                      Type2Message type2 = new Type2Message(
76                          type1, new byte[8], null);
77  
78                      authorization = Base64.encode(type2.toByteArray());
79  
80                      response.setHeader(
81                          HttpHeaders.WWW_AUTHENTICATE, "NTLM " + authorization);
82                      response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
83                      response.setContentLength(0);
84  
85                      response.flushBuffer();
86  
87                      return;
88                  }
89              }
90          }
91  
92          processFilter(NtlmPostFilter.class, request, response, filterChain);
93      }
94  
95      private static Log _log = LogFactoryUtil.getLog(NtlmPostFilter.class);
96  
97  }