use of com.helger.phase4.attachment.WSS4JAttachment in project phase4 by phax.
the class AS4Signer method _createSignedMessage.
@Nonnull
private static Document _createSignedMessage(@Nonnull final IAS4CryptoFactory aCryptoFactory, @Nonnull final Document aPreSigningMessage, @Nonnull final ESoapVersion eSoapVersion, @Nonnull @Nonempty final String sMessagingID, @Nullable final ICommonsList<WSS4JAttachment> aAttachments, @Nonnull @WillNotClose final AS4ResourceHelper aResHelper, final boolean bMustUnderstand, @Nonnull final AS4SigningParams aSigningParams) throws WSSecurityException {
ValueEnforcer.notNull(aCryptoFactory, "CryptoFactory");
ValueEnforcer.notNull(aPreSigningMessage, "PreSigningMessage");
ValueEnforcer.notNull(eSoapVersion, "SoapVersion");
ValueEnforcer.notEmpty(sMessagingID, "MessagingID");
ValueEnforcer.notNull(aResHelper, "ResHelper");
ValueEnforcer.notNull(aSigningParams, "SigningParams");
if (LOGGER.isInfoEnabled())
LOGGER.info("Now signing AS4 message");
// Start signing the document
final WSSecHeader aSecHeader = new WSSecHeader(aPreSigningMessage);
aSecHeader.insertSecurityHeader();
final WSSecSignature aBuilder = new WSSecSignature(aSecHeader);
aBuilder.setKeyIdentifierType(aSigningParams.getKeyIdentifierType().getTypeID());
// Set keystore alias and key password
aBuilder.setUserInfo(aCryptoFactory.getKeyAlias(), aCryptoFactory.getKeyPassword());
aBuilder.setSignatureAlgorithm(aSigningParams.getAlgorithmSign().getAlgorithmURI());
// PMode indicates the DigestAlgorithm as Hash Function
aBuilder.setDigestAlgo(aSigningParams.getAlgorithmSignDigest().getAlgorithmURI());
aBuilder.setSigCanonicalization(aSigningParams.getAlgorithmC14N().getAlgorithmURI());
// Sign the Ebms3 Messaging element itself
aBuilder.getParts().add(new WSEncryptionPart(sMessagingID, "Content"));
// Sign the SOAP body
aBuilder.getParts().add(new WSEncryptionPart("Body", eSoapVersion.getNamespaceURI(), "Content"));
if (CollectionHelper.isNotEmpty(aAttachments)) {
// Modify builder for attachments
// "cid:Attachments" is a predefined ID used inside WSSecSignatureBase
aBuilder.getParts().add(new WSEncryptionPart(MessageHelperMethods.PREFIX_CID + "Attachments", "Content"));
final WSS4JAttachmentCallbackHandler aAttachmentCallbackHandler = new WSS4JAttachmentCallbackHandler(aAttachments, aResHelper);
aBuilder.setAttachmentCallbackHandler(aAttachmentCallbackHandler);
}
// Set the mustUnderstand header of the wsse:Security element as well
final Attr aMustUnderstand = aSecHeader.getSecurityHeaderElement().getAttributeNodeNS(eSoapVersion.getNamespaceURI(), "mustUnderstand");
if (aMustUnderstand != null)
aMustUnderstand.setValue(eSoapVersion.getMustUnderstandValue(bMustUnderstand));
return aBuilder.build(aCryptoFactory.getCrypto());
}
use of com.helger.phase4.attachment.WSS4JAttachment in project phase4 by phax.
the class AS4DumpReader method decryptAS4In.
/**
* Utility method to decrypt dumped .as4in message late.<br>
* Note: this method was mainly created for internal use and does not win the
* prize for the most sexy piece of software in the world ;-)
*
* @param aAS4InData
* The byte array with the dumped data.
* @param aCF
* The Crypto factory to be used. This crypto factory must use use the
* private key that can be used to decrypt this particular message. May
* not be <code>null</code>.
* @param aHttpHeaderConsumer
* An optional HTTP Header map consumer. May be <code>null</code>.
* @param aDecryptedConsumer
* The consumer for the decrypted payload - whatever that is :). May
* not be <code>null</code>.
* @throws WSSecurityException
* In case of error
* @throws Phase4Exception
* In case of error
* @throws IOException
* In case of error
* @throws MessagingException
* In case of error
*/
public static void decryptAS4In(@Nonnull final byte[] aAS4InData, final IAS4CryptoFactory aCF, @Nullable final Consumer<HttpHeaderMap> aHttpHeaderConsumer, @Nonnull final Consumer<byte[]> aDecryptedConsumer) throws WSSecurityException, Phase4Exception, IOException, MessagingException {
final HttpHeaderMap hm = new HttpHeaderMap();
int nHttpStart = 0;
int nHttpEnd = -1;
boolean bLastWasCR = false;
for (int i = 0; i < aAS4InData.length; ++i) {
final byte b = aAS4InData[i];
if (b == '\n') {
if (bLastWasCR) {
nHttpEnd = i;
break;
}
bLastWasCR = true;
final String sLine = new String(aAS4InData, nHttpStart, i - nHttpStart, StandardCharsets.ISO_8859_1);
final String[] aParts = StringHelper.getExplodedArray(':', sLine, 2);
hm.addHeader(aParts[0].trim(), aParts[1].trim());
nHttpStart = i + 1;
} else {
if (b != '\r')
bLastWasCR = false;
}
}
if (aHttpHeaderConsumer != null)
aHttpHeaderConsumer.accept(hm);
LOGGER.info("Now at byte " + nHttpEnd + " having " + hm.getCount() + " HTTP headers");
WebScopeManager.onGlobalBegin(MockServletContext.create());
try (final WebScoped w = new WebScoped();
final AS4RequestHandler rh = new AS4RequestHandler(aCF, DefaultPModeResolver.DEFAULT_PMODE_RESOLVER, IAS4IncomingAttachmentFactory.DEFAULT_INSTANCE, new AS4IncomingMessageMetadata(EAS4MessageMode.REQUEST))) {
final IAS4ServletMessageProcessorSPI aSPI = new IAS4ServletMessageProcessorSPI() {
public AS4MessageProcessorResult processAS4UserMessage(final IAS4IncomingMessageMetadata aMessageMetadata, final HttpHeaderMap aHttpHeaders, final Ebms3UserMessage aUserMessage, final IPMode aPMode, final Node aPayload, final ICommonsList<WSS4JAttachment> aIncomingAttachments, final IAS4MessageState aState, final ICommonsList<Ebms3Error> aProcessingErrorMessages) {
try {
final byte[] aDecryptedBytes = StreamHelper.getAllBytes(aIncomingAttachments.getFirst().getInputStreamProvider());
aDecryptedConsumer.accept(aDecryptedBytes);
LOGGER.info("Handled decrypted payload with " + aDecryptedBytes.length + " bytes");
return AS4MessageProcessorResult.createSuccess();
} catch (final Exception ex) {
throw new IllegalStateException(ex);
}
}
public AS4SignalMessageProcessorResult processAS4SignalMessage(final IAS4IncomingMessageMetadata aMessageMetadata, final HttpHeaderMap aHttpHeaders, final Ebms3SignalMessage aSignalMessage, final IPMode aPMode, final IAS4MessageState aState, final ICommonsList<Ebms3Error> aProcessingErrorMessages) {
LOGGER.error("Unexpected signal msg");
return AS4SignalMessageProcessorResult.createSuccess();
}
};
rh.setProcessorSupplier(() -> new CommonsArrayList<>(aSPI));
rh.handleRequest(new NonBlockingByteArrayInputStream(aAS4InData, nHttpEnd, aAS4InData.length - nHttpEnd), hm, new IAS4ResponseAbstraction() {
public void setStatus(final int nStatusCode) {
}
public void setMimeType(final IMimeType aMimeType) {
}
public void setContent(final HttpHeaderMap aHeaderMap, final IHasInputStream aHasIS) {
}
public void setContent(final byte[] aResultBytes, final Charset aCharset) {
}
});
} finally {
WebScopeManager.onGlobalEnd();
}
}
use of com.helger.phase4.attachment.WSS4JAttachment in project phase4 by phax.
the class Phase4PeppolServletMessageProcessorSPI method processAS4UserMessage.
@Nonnull
public AS4MessageProcessorResult processAS4UserMessage(@Nonnull final IAS4IncomingMessageMetadata aMessageMetadata, @Nonnull final HttpHeaderMap aHttpHeaders, @Nonnull final Ebms3UserMessage aUserMessage, @Nonnull final IPMode aSrcPMode, @Nullable final Node aPayload, @Nullable final ICommonsList<WSS4JAttachment> aIncomingAttachments, @Nonnull final IAS4MessageState aState, @Nonnull final ICommonsList<Ebms3Error> aProcessingErrorMessages) {
if (LOGGER.isDebugEnabled())
LOGGER.debug("Invoking processAS4UserMessage");
final String sMessageID = aUserMessage.getMessageInfo().getMessageId();
final String sService = aUserMessage.getCollaborationInfo().getServiceValue();
final String sAction = aUserMessage.getCollaborationInfo().getAction();
final String sConversationID = aUserMessage.getCollaborationInfo().getConversationId();
final String sLogPrefix = "[" + sMessageID + "] ";
final Locale aDisplayLocale = aState.getLocale();
// Debug log
if (LOGGER.isDebugEnabled()) {
if (aSrcPMode == null)
LOGGER.debug(sLogPrefix + " No Source PMode present");
else
LOGGER.debug(sLogPrefix + " Source PMode = " + aSrcPMode.getID());
LOGGER.debug(sLogPrefix + " AS4 Message ID = '" + sMessageID + "'");
LOGGER.debug(sLogPrefix + " AS4 Service = '" + sService + "'");
LOGGER.debug(sLogPrefix + " AS4 Action = '" + sAction + "'");
LOGGER.debug(sLogPrefix + " AS4 ConversationId = '" + sConversationID + "'");
// Log source properties
if (aUserMessage.getMessageProperties() != null && aUserMessage.getMessageProperties().hasPropertyEntries()) {
LOGGER.debug(sLogPrefix + " AS4 MessageProperties:");
for (final Ebms3Property p : aUserMessage.getMessageProperties().getProperty()) LOGGER.debug(sLogPrefix + " [" + p.getName() + "] = [" + p.getValue() + "]");
} else
LOGGER.debug(sLogPrefix + " No AS4 Mesage Properties present");
if (aPayload == null)
LOGGER.debug(sLogPrefix + " No SOAP Body Payload present");
else
LOGGER.debug(sLogPrefix + " SOAP Body Payload = " + XMLWriter.getNodeAsString(aPayload));
}
// Read all attachments
final ICommonsList<ReadAttachment> aReadAttachments = new CommonsArrayList<>();
if (aIncomingAttachments != null) {
int nAttachmentIndex = 0;
for (final IAS4Attachment aIncomingAttachment : aIncomingAttachments) {
final ReadAttachment a = new ReadAttachment();
a.m_sID = aIncomingAttachment.getId();
a.m_sMimeType = aIncomingAttachment.getMimeType();
a.m_sUncompressedMimeType = aIncomingAttachment.getUncompressedMimeType();
a.m_aCharset = aIncomingAttachment.getCharset();
a.m_eCompressionMode = aIncomingAttachment.getCompressionMode();
try (final InputStream aSIS = aIncomingAttachment.getSourceStream()) {
final NonBlockingByteArrayOutputStream aBAOS = new NonBlockingByteArrayOutputStream();
if (StreamHelper.copyInputStreamToOutputStreamAndCloseOS(aSIS, aBAOS).isSuccess()) {
a.m_aPayloadBytes = aBAOS.getBufferOrCopy();
}
} catch (final IOException | AS4DecompressException ex) {
// Fall through
}
if (a.m_aPayloadBytes == null) {
LOGGER.error(sLogPrefix + "Failed to decompress the payload");
aProcessingErrorMessages.add(EEbmsError.EBMS_DECOMPRESSION_FAILURE.getAsEbms3Error(aDisplayLocale, aState.getMessageID()));
return AS4MessageProcessorResult.createFailure(null);
}
// Read data as SBDH
// Hint for production systems: this may take a huge amount of memory,
// if the payload is large
final ErrorList aSBDHErrors = new ErrorList();
a.m_aSBDH = SBDHReader.standardBusinessDocument().setValidationEventHandler(new WrappedCollectingValidationEventHandler(aSBDHErrors)).read(a.m_aPayloadBytes);
if (a.m_aSBDH == null) {
if (aSBDHErrors.isEmpty()) {
final String sMsg = "Failed to read the provided SBDH document";
LOGGER.error(sLogPrefix + sMsg);
aProcessingErrorMessages.add(EEbmsError.EBMS_OTHER.getAsEbms3Error(aDisplayLocale, aState.getMessageID(), sMsg));
} else {
for (final IError aError : aSBDHErrors) {
final String sMsg = "Peppol SBDH Issue: " + aError.getAsString(aDisplayLocale);
LOGGER.error(sLogPrefix + sMsg);
aProcessingErrorMessages.add(EEbmsError.EBMS_OTHER.getAsEbms3Error(aDisplayLocale, aState.getMessageID(), sMsg));
}
}
return AS4MessageProcessorResult.createFailure(null);
}
aReadAttachments.add(a);
if (LOGGER.isDebugEnabled())
LOGGER.debug(sLogPrefix + "AS4 Attachment " + nAttachmentIndex + " with ID [" + a.m_sID + "] uses [" + a.m_sMimeType + (a.m_sUncompressedMimeType == null ? null : " - uncompressed " + a.m_sUncompressedMimeType) + "] and [" + StringHelper.getToString(a.m_aCharset, "no charset") + "] and length is " + (a.m_aPayloadBytes == null ? "<error>" : Integer.toString(a.m_aPayloadBytes.length)) + " bytes" + (a.m_eCompressionMode == null ? "" : " of compressed payload"));
nAttachmentIndex++;
}
}
if (aReadAttachments.size() != 1) {
// In Peppol there must be exactly one payload
final String sMsg = "In Peppol exactly one payload attachment is expected. This request has " + aReadAttachments.size() + " attachments";
LOGGER.error(sLogPrefix + sMsg);
return AS4MessageProcessorResult.createFailure(sMsg);
}
// The one and only
final ReadAttachment aReadAttachment = aReadAttachments.getFirst();
// Extract Peppol values from SBD
final PeppolSBDHDocument aPeppolSBD;
try {
if (LOGGER.isDebugEnabled())
LOGGER.debug(sLogPrefix + "Now evaluating the SBDH against Peppol rules");
final boolean bPerformValueChecks = Phase4PeppolServletConfiguration.isPerformSBDHValueChecks();
aPeppolSBD = new PeppolSBDHDocumentReader(SimpleIdentifierFactory.INSTANCE).setPerformValueChecks(bPerformValueChecks).extractData(aReadAttachment.standardBusinessDocument());
if (LOGGER.isDebugEnabled())
LOGGER.debug(sLogPrefix + "The provided SBDH is valid according to Peppol rules, with value checks being " + (bPerformValueChecks ? "enabled" : "disabled"));
} catch (final PeppolSBDHDocumentReadException ex) {
final String sMsg = "Failed to extract the Peppol data from SBDH. Technical details: " + ex.getClass().getName() + " - " + ex.getMessage();
LOGGER.error(sLogPrefix + sMsg);
return AS4MessageProcessorResult.createFailure(sMsg);
}
if (m_aHandlers.isEmpty()) {
LOGGER.error(sLogPrefix + "No SPI handler is present - the message is unhandled and discarded");
} else {
// Start consistency checks?
final Phase4PeppolReceiverCheckData aReceiverCheckData = m_aReceiverCheckData != null ? m_aReceiverCheckData : Phase4PeppolServletConfiguration.getAsReceiverCheckData();
if (aReceiverCheckData != null) {
if (LOGGER.isDebugEnabled())
LOGGER.debug("Performing check if the provided data is registered in our SMP");
try {
// Get the endpoint information required from the recipient
// Check if an endpoint is registered
final IParticipantIdentifier aReceiverID = aPeppolSBD.getReceiverAsIdentifier();
final IDocumentTypeIdentifier aDocTypeID = aPeppolSBD.getDocumentTypeAsIdentifier();
final IProcessIdentifier aProcessID = aPeppolSBD.getProcessAsIdentifier();
final EndpointType aReceiverEndpoint = _getReceiverEndpoint(sLogPrefix, aReceiverCheckData.getSMPClient(), aReceiverID, aDocTypeID, aProcessID);
if (aReceiverEndpoint == null) {
final String sMsg = "Failed to resolve SMP endpoint for provided receiver ID (" + (aReceiverID == null ? "null" : aReceiverID.getURIEncoded()) + ")/documentType ID (" + (aDocTypeID == null ? "null" : aDocTypeID.getURIEncoded()) + ")/process ID (" + (aProcessID == null ? "null" : aProcessID.getURIEncoded()) + ")/transport profile (" + m_aTransportProfile.getID() + ") - not handling incoming AS4 document";
LOGGER.error(sLogPrefix + sMsg);
return AS4MessageProcessorResult.createFailure(sMsg);
}
// Check if the message is for us
_checkIfReceiverEndpointURLMatches(sLogPrefix, aReceiverCheckData.getAS4EndpointURL(), aReceiverEndpoint);
// Get the recipient certificate from the SMP
_checkIfEndpointCertificateMatches(sLogPrefix, aReceiverCheckData.getAPCertificate(), aReceiverEndpoint);
} catch (final Phase4Exception ex) {
final String sMsg = "The addressing data contained in the SBDH could not be verified. Technical details: " + ex.getClass().getName() + " - " + ex.getMessage();
LOGGER.error(sLogPrefix + sMsg);
return AS4MessageProcessorResult.createFailure(sMsg);
}
} else {
LOGGER.info(sLogPrefix + "Endpoint checks for incoming AS4 messages are disabled");
}
for (final IPhase4PeppolIncomingSBDHandlerSPI aHandler : m_aHandlers) {
try {
if (LOGGER.isDebugEnabled())
LOGGER.debug(sLogPrefix + "Invoking Peppol handler " + aHandler);
aHandler.handleIncomingSBD(aMessageMetadata, aHttpHeaders.getClone(), aUserMessage.clone(), aReadAttachment.payloadBytes(), aReadAttachment.standardBusinessDocument(), aPeppolSBD, aState);
} catch (final Exception ex) {
LOGGER.error(sLogPrefix + "Error invoking Peppol handler " + aHandler, ex);
if (aHandler.exceptionTranslatesToAS4Error()) {
final String sMsg = "The incoming Peppol message could not be processed. Technical details: " + ex.getClass().getName() + " - " + ex.getMessage();
LOGGER.error(sLogPrefix + sMsg);
return AS4MessageProcessorResult.createFailure(sMsg);
}
}
}
}
return AS4MessageProcessorResult.createSuccess();
}
use of com.helger.phase4.attachment.WSS4JAttachment in project phase4 by phax.
the class AS4CEFOneWayFuncTest method testAS4_TA28.
/**
* Note: Only when using SBDH<br>
* Prerequisite:<br>
* SMSH and RMSH are configured to exchange AS4 messages according to the
* e-SENS profile (One-Way/Push MEP). Producer submits two payloads, first
* being an SBDH document, second being an actual payload (non-XML payload).
* SMSH sends an AS4 User Message to the RMSH.<br>
* <br>
* Predicate: <br>
* Message has two additional MIME parts. The first mime part is the SBDH
* document and the second is the actual payload
*
* @throws Exception
* In case of error
*/
@Test
public void testAS4_TA28() throws Exception {
final ICommonsList<WSS4JAttachment> aAttachments = new CommonsArrayList<>();
aAttachments.add(WSS4JAttachment.createOutgoingFileAttachment(Phase4OutgoingAttachment.builder().data(ClassPathResource.getAsFile(AS4TestConstants.ATTACHMENT_SHORTXML_XML)).mimeTypeXML().build(), s_aResMgr));
aAttachments.add(WSS4JAttachment.createOutgoingFileAttachment(Phase4OutgoingAttachment.builder().data(ClassPathResource.getAsFile(AS4TestConstants.ATTACHMENT_TEST_IMG_JPG)).mimeType(CMimeType.IMAGE_JPG).build(), s_aResMgr));
final AS4MimeMessage aMsg = MimeMessageCreator.generateMimeMessage(m_eSoapVersion, MockMessages.createUserMessageNotSigned(m_eSoapVersion, null, aAttachments).getAsSoapDocument(), aAttachments);
final String sResponse = sendMimeMessage(new HttpMimeMessageEntity(aMsg), true, null);
assertTrue(sResponse.contains(AS4TestConstants.RECEIPT_ASSERTCHECK));
}
use of com.helger.phase4.attachment.WSS4JAttachment in project phase4 by phax.
the class AS4CEFOneWayFuncTest method testAS4_TA10.
/**
* Prerequisite:<br>
* SMSH and RMSH are configured to exchange AS4 messages according to the
* e-SENS profile (One-Way/Push MEP). Producer submits a message to the SMSH
* with xml (UTF-16) payload and metadata information including payload
* character set info.<br>
* <br>
* Predicate: <br>
* The SMSH generates an AS4 message with the property "CharacterSet" present
* and set to the value "UTF-16".
*
* @throws Exception
* In case of error
*/
@Test
public void testAS4_TA10() throws Exception {
final ICommonsList<WSS4JAttachment> aAttachments = new CommonsArrayList<>();
final WSS4JAttachment aAttachment = WSS4JAttachment.createOutgoingFileAttachment(Phase4OutgoingAttachment.builder().data(ClassPathResource.getAsFile(AS4TestConstants.ATTACHMENT_SHORTXML_XML)).mimeTypeXML().compressionGZIP().build(), s_aResMgr);
aAttachment.setCharset(StandardCharsets.UTF_16);
aAttachments.add(aAttachment);
final Document aDoc = createTestSignedUserMessage(m_eSoapVersion, m_aPayload, aAttachments, s_aResMgr);
NodeList aNL = aDoc.getElementsByTagName("eb:PartProperties");
aNL = aNL.item(0).getChildNodes();
boolean bHasCharset = false;
for (int i = 0; i < aNL.getLength(); i++) if (aNL.item(i).getAttributes().getNamedItem("name").getTextContent().equals("CharacterSet"))
if (aNL.item(i).getTextContent().equals("UTF-16")) {
bHasCharset = true;
break;
}
assertTrue(bHasCharset);
}
Aggregations