1
22
23 package com.liferay.portal.servlet.filters.sso.ntlm;
24
25 import com.liferay.portal.kernel.log.Log;
26 import com.liferay.portal.kernel.log.LogFactoryUtil;
27 import com.liferay.portal.kernel.servlet.BrowserSnifferUtil;
28 import com.liferay.portal.kernel.servlet.HttpHeaders;
29 import com.liferay.portal.kernel.servlet.HttpMethods;
30 import com.liferay.portal.kernel.util.GetterUtil;
31 import com.liferay.portal.security.ldap.PortalLDAPUtil;
32 import com.liferay.portal.servlet.filters.BasePortalFilter;
33 import com.liferay.portal.util.PortalInstances;
34
35 import javax.servlet.FilterChain;
36 import javax.servlet.http.HttpServletRequest;
37 import javax.servlet.http.HttpServletResponse;
38
39 import jcifs.ntlmssp.Type1Message;
40 import jcifs.ntlmssp.Type2Message;
41
42 import jcifs.util.Base64;
43
44
50 public class NtlmPostFilter extends BasePortalFilter {
51
52 protected Log getLog() {
53 return _log;
54 }
55
56 protected void processFilter(
57 HttpServletRequest request, HttpServletResponse response,
58 FilterChain filterChain)
59 throws Exception {
60
61 long companyId = PortalInstances.getCompanyId(request);
62
63 if (PortalLDAPUtil.isNtlmEnabled(companyId) &&
64 BrowserSnifferUtil.isIe(request) &&
65 request.getMethod().equals(HttpMethods.POST)) {
66
67 String authorization = GetterUtil.getString(
68 request.getHeader(HttpHeaders.AUTHORIZATION));
69
70 if (authorization.startsWith("NTLM ")) {
71 byte[] src = Base64.decode(authorization.substring(5));
72
73 if (src[8] == 1) {
74 Type1Message type1 = new Type1Message(src);
75 Type2Message type2 = new Type2Message(
76 type1, new byte[8], null);
77
78 authorization = Base64.encode(type2.toByteArray());
79
80 response.setHeader(
81 HttpHeaders.WWW_AUTHENTICATE, "NTLM " + authorization);
82 response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
83 response.setContentLength(0);
84
85 response.flushBuffer();
86
87 return;
88 }
89 }
90 }
91
92 processFilter(NtlmPostFilter.class, request, response, filterChain);
93 }
94
95 private static Log _log = LogFactoryUtil.getLog(NtlmPostFilter.class);
96
97 }