use of com.pspace.ifs.ksan.gw.format.AccessControlPolicy.AccessControlList in project ksan by infinistor.
the class CopyObject method process.
@Override
public void process() throws GWException {
logger.info(GWConstants.LOG_COPY_OBJECT_START);
String bucket = s3Parameter.getBucketName();
initBucketInfo(bucket);
String object = s3Parameter.getObjectName();
S3Bucket s3Bucket = new S3Bucket();
s3Bucket.setCors(getBucketInfo().getCors());
s3Bucket.setAccess(getBucketInfo().getAccess());
s3Parameter.setBucket(s3Bucket);
GWUtils.checkCors(s3Parameter);
if (s3Parameter.isPublicAccess() && GWUtils.isIgnorePublicAcls(s3Parameter)) {
throw new GWException(GWErrorCode.ACCESS_DENIED, s3Parameter);
}
checkGrantBucket(s3Parameter.isPublicAccess(), String.valueOf(s3Parameter.getUser().getUserId()), GWConstants.GRANT_WRITE);
try {
object = URLDecoder.decode(object, GWConstants.CHARSET_UTF_8);
} catch (UnsupportedEncodingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
DataCopyObject dataCopyObject = new DataCopyObject(s3Parameter);
dataCopyObject.extract();
String cacheControl = dataCopyObject.getCacheControl();
String contentDisposition = dataCopyObject.getContentDisposition();
String contentEncoding = dataCopyObject.getContentEncoding();
String contentLanguage = dataCopyObject.getContentLanguage();
String contentType = dataCopyObject.getContentType();
String contentLengthString = dataCopyObject.getContentLength();
String metadataDirective = dataCopyObject.getMetadataDirective();
String serversideEncryption = dataCopyObject.getServerSideEncryption();
String copySource = dataCopyObject.getCopySource();
String copySourceIfMatch = dataCopyObject.getCopySourceIfMatch();
String copySourceIfNoneMatch = dataCopyObject.getCopySourceIfNoneMatch();
String copySourceIfModifiedSince = dataCopyObject.getCopySourceIfModifiedSince();
String copySourceIfUnmodifiedSince = dataCopyObject.getCopySourceIfUnmodifiedSince();
String expires = dataCopyObject.getExpires();
String customerAlgorithm = dataCopyObject.getServerSideEncryptionCustomerAlgorithm();
String customerKey = dataCopyObject.getServerSideEncryptionCustomerKey();
String customerKeyMD5 = dataCopyObject.getServerSideEncryptionCustomerKeyMD5();
String context = dataCopyObject.getServerSideEncryptionContext();
String bucketKeyEnabled = dataCopyObject.getServerSideEncryptionBucketKeyEnabled();
String copySourceCustomerAlgorithm = dataCopyObject.getCopySourceServerSideEncryptionCustomerAlgorithm();
String copySourceCustomerKey = dataCopyObject.getCopySourceServerSideEncryptionCustomerKey();
String copySourceCustomerKeyMD5 = dataCopyObject.getCopySourceServerSideEncryptionCustomerKeyMD5();
Map<String, String> userMetadata = dataCopyObject.getUserMetadata();
// Check copy source
if (Strings.isNullOrEmpty(copySource)) {
logger.error(GWConstants.LOG_COPY_SOURCE_IS_NULL);
throw new GWException(GWErrorCode.BAD_REQUEST, s3Parameter);
}
try {
copySource = URLDecoder.decode(copySource, GWConstants.CHARSET_UTF_8);
} catch (UnsupportedEncodingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
if (copySource.startsWith(GWConstants.SLASH)) {
copySource = copySource.substring(1);
} else if (copySource.contains(GWConstants.S3_ARN)) {
logger.error(GWConstants.LOG_COPY_SOURCE_IS_NOT_IMPLEMENTED, copySource);
throw new GWException(GWErrorCode.NOT_IMPLEMENTED, s3Parameter);
}
String[] sourcePath = copySource.split(GWConstants.SLASH, 2);
if (sourcePath.length != 2) {
throw new GWException(GWErrorCode.INVALID_ARGUMENT, s3Parameter);
}
String srcBucket = sourcePath[0];
String srcObjectName = sourcePath[1];
String srcVersionId = null;
setSrcBucket(srcBucket);
if (srcObjectName.contains(GWConstants.SUB_PARAMETER_VERSIONID) == true) {
String[] source = sourcePath[1].split(GWConstants.PARAMETER_BACKSLASH_VERSIONID, 2);
srcObjectName = source[0];
srcVersionId = source[1].replaceAll(GWConstants.DOUBLE_QUOTE, "");
}
s3Parameter.setSrcBucketName(srcBucket);
s3Parameter.setSrcVersionId(srcVersionId);
s3Parameter.setSrcPath(srcObjectName);
logger.debug(GWConstants.LOG_SOURCE_INFO, srcBucket, srcObjectName, srcVersionId);
String versioningStatus = getBucketVersioning(srcBucket);
Metadata srcMeta = null;
if (GWConstants.VERSIONING_ENABLED.equalsIgnoreCase(versioningStatus)) {
if (!Strings.isNullOrEmpty(srcVersionId) && !GWConstants.VERSIONING_DISABLE_TAIL.equals(srcVersionId)) {
srcMeta = open(srcBucket, srcObjectName, srcVersionId);
} else {
srcMeta = open(srcBucket, srcObjectName);
}
} else {
srcMeta = open(srcBucket, srcObjectName);
}
srcVersionId = srcMeta.getVersionId();
srcMeta.setAcl(GWUtils.makeOriginalXml(srcMeta.getAcl(), s3Parameter));
checkGrantObject(s3Parameter.isPublicAccess(), srcMeta, String.valueOf(s3Parameter.getUser().getUserId()), GWConstants.GRANT_READ);
// get metadata
S3Metadata s3Metadata = null;
ObjectMapper objectMapper = new ObjectMapper();
try {
s3Metadata = objectMapper.readValue(srcMeta.getMeta(), S3Metadata.class);
} catch (JsonProcessingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.INTERNAL_SERVER_ERROR, s3Parameter);
}
// Check match
if (!Strings.isNullOrEmpty(copySourceIfMatch)) {
logger.debug(GWConstants.LOG_SOURCE_ETAG_MATCH, s3Metadata.getETag(), copySourceIfMatch.replace(GWConstants.DOUBLE_QUOTE, ""));
if (!GWUtils.maybeQuoteETag(s3Metadata.getETag()).equals(copySourceIfMatch.replace(GWConstants.DOUBLE_QUOTE, ""))) {
throw new GWException(GWErrorCode.PRECONDITION_FAILED, s3Parameter);
}
}
if (!Strings.isNullOrEmpty(copySourceIfNoneMatch)) {
logger.debug(GWConstants.LOG_SOURCE_ETAG_MATCH, s3Metadata.getETag(), copySourceIfNoneMatch.replace(GWConstants.DOUBLE_QUOTE, ""));
if (GWUtils.maybeQuoteETag(s3Metadata.getETag()).equals(copySourceIfNoneMatch.replace(GWConstants.DOUBLE_QUOTE, ""))) {
throw new GWException(GWErrorCode.DOES_NOT_MATCH, String.format(GWConstants.LOG_ETAG_IS_MISMATCH), s3Parameter);
}
}
if (!Strings.isNullOrEmpty(copySourceIfModifiedSince)) {
long copySourceIfModifiedSinceLong = Long.parseLong(copySourceIfModifiedSince);
if (copySourceIfModifiedSinceLong != -1) {
Date modifiedSince = new Date(copySourceIfModifiedSinceLong);
if (s3Metadata.getLastModified().before(modifiedSince)) {
throw new GWException(GWErrorCode.DOES_NOT_MATCH, String.format(GWConstants.LOG_MATCH_BEFORE, s3Metadata.getLastModified(), modifiedSince), s3Parameter);
}
}
}
if (!Strings.isNullOrEmpty(copySourceIfUnmodifiedSince)) {
long copySourceIfUnmodifiedSinceLong = Long.parseLong(copySourceIfUnmodifiedSince);
if (copySourceIfUnmodifiedSinceLong != -1) {
Date unmodifiedSince = new Date(copySourceIfUnmodifiedSinceLong);
if (s3Metadata.getLastModified().after(unmodifiedSince)) {
throw new GWException(GWErrorCode.PRECONDITION_FAILED, String.format(GWConstants.LOG_MATCH_AFTER, s3Metadata.getLastModified(), unmodifiedSince), s3Parameter);
}
}
}
accessControlPolicy = new AccessControlPolicy();
accessControlPolicy.aclList = new AccessControlList();
accessControlPolicy.aclList.grants = new ArrayList<Grant>();
accessControlPolicy.owner = new Owner();
accessControlPolicy.owner.id = String.valueOf(s3Parameter.getUser().getUserId());
accessControlPolicy.owner.displayName = s3Parameter.getUser().getUserName();
String aclXml = GWUtils.makeAclXml(accessControlPolicy, null, dataCopyObject.hasAclKeyword(), null, dataCopyObject.getAcl(), getBucketInfo(), String.valueOf(s3Parameter.getUser().getUserId()), s3Parameter.getUser().getUserName(), dataCopyObject.getGrantRead(), dataCopyObject.getGrantWrite(), dataCopyObject.getGrantFullControl(), dataCopyObject.getGrantReadAcp(), dataCopyObject.getGrantWriteAcp(), s3Parameter);
boolean bReplaceMetadata = false;
logger.debug(GWConstants.LOG_COPY_OBJECT_METADATA_DIRECTIVE, metadataDirective);
if (!Strings.isNullOrEmpty(metadataDirective) && metadataDirective.equalsIgnoreCase(GWConstants.REPLACE)) {
bReplaceMetadata = true;
}
s3Metadata.setOwnerId(String.valueOf(s3Parameter.getUser().getUserId()));
s3Metadata.setOwnerName(s3Parameter.getUser().getUserName());
if (userMetadata.size() > 0) {
for (String key : userMetadata.keySet()) {
logger.info(GWConstants.LOG_COPY_OBJECT_USER_METADATA, key, userMetadata.get(key));
}
if (bReplaceMetadata) {
logger.info(GWConstants.LOG_COPY_OBJECT_REPLACE_USER_METADATA, userMetadata.toString());
s3Metadata.setUserMetadataMap(userMetadata);
}
}
if (!Strings.isNullOrEmpty(cacheControl) && bReplaceMetadata) {
s3Metadata.setCacheControl(cacheControl);
}
if (!Strings.isNullOrEmpty(contentDisposition) && bReplaceMetadata) {
s3Metadata.setContentDisposition(contentDisposition);
}
if (!Strings.isNullOrEmpty(contentEncoding) && bReplaceMetadata) {
s3Metadata.setContentEncoding(contentEncoding);
}
if (!Strings.isNullOrEmpty(contentLanguage) && bReplaceMetadata) {
s3Metadata.setContentLanguage(contentLanguage);
}
if (!Strings.isNullOrEmpty(contentType) && bReplaceMetadata) {
s3Metadata.setContentType(contentType);
}
if (Strings.isNullOrEmpty(contentLengthString)) {
logger.error(GWErrorCode.MISSING_CONTENT_LENGTH.getMessage());
throw new GWException(GWErrorCode.MISSING_CONTENT_LENGTH, s3Parameter);
}
/*else {
try {
long contentLength = Long.parseLong(contentLengthString);
s3Metadata.setContentLength(contentLength);
} catch (NumberFormatException e) {
logger.error(e.getMessage());
throw new S3Exception(S3ErrorCode.INVALID_ARGUMENT, e);
}
}*/
String jsonmeta = "";
// update
if (s3Parameter.getSrcBucketName().equals(bucket) && s3Parameter.getSrcPath().equals(object)) {
if (!Strings.isNullOrEmpty(metadataDirective) && bReplaceMetadata) {
// update metadata
try {
S3Metadata metaClass = objectMapper.readValue(srcMeta.getMeta(), S3Metadata.class);
s3Metadata.setTier(GWConstants.AWS_TIER_STANTARD);
s3Metadata.setContentLength(metaClass.getContentLength());
s3Metadata.setETag(metaClass.getETag());
} catch (JsonProcessingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Metadata.setLastModified(new Date());
try {
jsonmeta = objectMapper.writeValueAsString(s3Metadata);
} catch (JsonProcessingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
logger.debug(GWConstants.LOG_COPY_OBJECT_META, jsonmeta);
srcMeta.setMeta(jsonmeta);
updateObjectMeta(srcMeta);
s3Parameter.getResponse().setCharacterEncoding(GWConstants.CHARSET_UTF_8);
XMLOutputFactory xmlOutputFactory = XMLOutputFactory.newInstance();
try (Writer writer = s3Parameter.getResponse().getWriter()) {
s3Parameter.getResponse().setContentType(GWConstants.XML_CONTENT_TYPE);
XMLStreamWriter xmlout = xmlOutputFactory.createXMLStreamWriter(writer);
xmlout.writeStartDocument();
xmlout.writeStartElement(GWConstants.COPY_OBJECT_RESULT);
xmlout.writeDefaultNamespace(GWConstants.AWS_XMLNS);
writeSimpleElement(xmlout, GWConstants.LAST_MODIFIED, formatDate(s3Metadata.getLastModified()));
writeSimpleElement(xmlout, GWConstants.ETAG, GWUtils.maybeQuoteETag(s3Metadata.getETag()));
xmlout.writeEndElement();
xmlout.flush();
} catch (XMLStreamException | IOException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
return;
} else {
logger.error(GWErrorCode.INVALID_REQUEST.getMessage());
throw new GWException(GWErrorCode.INVALID_REQUEST, s3Parameter);
}
}
Metadata objMeta = createCopy(srcBucket, srcObjectName, srcVersionId, bucket, object);
versioningStatus = getBucketVersioning(bucket);
String versionId = null;
if (GWConstants.VERSIONING_ENABLED.equalsIgnoreCase(versioningStatus)) {
versionId = String.valueOf(System.nanoTime());
} else {
versionId = GWConstants.VERSIONING_DISABLE_TAIL;
}
S3ObjectOperation objectOperation = new S3ObjectOperation(objMeta, s3Metadata, s3Parameter, versionId, null);
S3Object s3Object = objectOperation.copyObject(srcMeta);
s3Metadata.setETag(s3Object.getEtag());
s3Metadata.setSize(s3Object.getFileSize());
s3Metadata.setTier(GWConstants.AWS_TIER_STANTARD);
s3Metadata.setLastModified(s3Object.getLastModified());
s3Metadata.setDeleteMarker(s3Object.getDeleteMarker());
s3Metadata.setVersionId(s3Object.getVersionId());
try {
jsonmeta = objectMapper.writeValueAsString(s3Metadata);
} catch (JsonProcessingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
logger.debug(GWConstants.LOG_COPY_OBJECT_META, jsonmeta);
try {
int result;
objMeta.set(s3Object.getEtag(), srcMeta.getTag(), jsonmeta, aclXml, s3Object.getFileSize());
objMeta.setVersionId(versionId, GWConstants.OBJECT_TYPE_FILE, true);
result = insertObject(bucket, object, objMeta);
if (result != 0) {
logger.error(GWConstants.LOG_COPY_OBJECT_FAILED, bucket, object);
}
logger.debug(GWConstants.LOG_COPY_OBJECT_INFO, bucket, object, s3Object.getFileSize(), s3Object.getEtag(), srcMeta.getAcl(), srcMeta.getAcl(), versionId);
} catch (GWException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Parameter.getResponse().setCharacterEncoding(GWConstants.CHARSET_UTF_8);
XMLOutputFactory xmlOutputFactory = XMLOutputFactory.newInstance();
try (Writer writer = s3Parameter.getResponse().getWriter()) {
s3Parameter.getResponse().setContentType(GWConstants.XML_CONTENT_TYPE);
XMLStreamWriter xmlout = xmlOutputFactory.createXMLStreamWriter(writer);
xmlout.writeStartDocument();
xmlout.writeStartElement(GWConstants.COPY_OBJECT_RESULT);
xmlout.writeDefaultNamespace(GWConstants.AWS_XMLNS);
writeSimpleElement(xmlout, GWConstants.LAST_MODIFIED, formatDate(s3Metadata.getLastModified()));
writeSimpleElement(xmlout, GWConstants.ETAG, GWUtils.maybeQuoteETag(s3Object.getEtag()));
xmlout.writeEndElement();
xmlout.flush();
} catch (XMLStreamException | IOException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
}
use of com.pspace.ifs.ksan.gw.format.AccessControlPolicy.AccessControlList in project ksan by infinistor.
the class PutObjectAcl method process.
@Override
public void process() throws GWException {
logger.info(GWConstants.LOG_PUT_OBJECT_ACL_START);
String bucket = s3Parameter.getBucketName();
String object = s3Parameter.getObjectName();
initBucketInfo(bucket);
S3Bucket s3Bucket = new S3Bucket();
s3Bucket.setCors(getBucketInfo().getCors());
s3Bucket.setAccess(getBucketInfo().getAccess());
s3Parameter.setBucket(s3Bucket);
GWUtils.checkCors(s3Parameter);
if (s3Parameter.isPublicAccess() && GWUtils.isIgnorePublicAcls(s3Parameter)) {
throw new GWException(GWErrorCode.ACCESS_DENIED, s3Parameter);
}
DataPutObjectAcl dataPutObjectAcl = new DataPutObjectAcl(s3Parameter);
dataPutObjectAcl.extract();
String versionId = dataPutObjectAcl.getVersionId();
Metadata objMeta = null;
if (Strings.isNullOrEmpty(versionId)) {
objMeta = open(bucket, object);
} else {
objMeta = open(bucket, object, versionId);
}
objMeta.setAcl(GWUtils.makeOriginalXml(objMeta.getAcl(), s3Parameter));
checkGrantObjectOwner(s3Parameter.isPublicAccess(), objMeta, String.valueOf(s3Parameter.getUser().getUserId()), GWConstants.GRANT_WRITE_ACP);
accessControlPolicy = new AccessControlPolicy();
accessControlPolicy.aclList = new AccessControlList();
accessControlPolicy.aclList.grants = new ArrayList<Grant>();
accessControlPolicy.owner = new Owner();
accessControlPolicy.owner.id = String.valueOf(s3Parameter.getUser().getUserId());
accessControlPolicy.owner.displayName = s3Parameter.getUser().getUserName();
String xml = GWUtils.makeAclXml(accessControlPolicy, null, dataPutObjectAcl.hasAclKeyword(), dataPutObjectAcl.getAclXml(), dataPutObjectAcl.getAcl(), getBucketInfo(), String.valueOf(s3Parameter.getUser().getUserId()), s3Parameter.getUser().getUserName(), dataPutObjectAcl.getGrantRead(), dataPutObjectAcl.getGrantWrite(), dataPutObjectAcl.getGrantFullControl(), dataPutObjectAcl.getGrantReadAcp(), dataPutObjectAcl.getGrantWriteAcp(), s3Parameter);
logger.debug(GWConstants.LOG_ACL, xml);
objMeta.setAcl(xml);
updateObjectAcl(objMeta);
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
}
use of com.pspace.ifs.ksan.gw.format.AccessControlPolicy.AccessControlList in project ksan by infinistor.
the class PutBucketAcl method process.
@Override
public void process() throws GWException {
logger.info(GWConstants.LOG_PUT_BUCKET_ACL_START);
String bucket = s3Parameter.getBucketName();
initBucketInfo(bucket);
S3Bucket s3Bucket = new S3Bucket();
s3Bucket.setCors(getBucketInfo().getCors());
s3Bucket.setAccess(getBucketInfo().getAccess());
s3Parameter.setBucket(s3Bucket);
GWUtils.checkCors(s3Parameter);
if (s3Parameter.isPublicAccess() && GWUtils.isIgnorePublicAcls(s3Parameter)) {
throw new GWException(GWErrorCode.ACCESS_DENIED, s3Parameter);
}
checkGrantBucketOwner(s3Parameter.isPublicAccess(), String.valueOf(s3Parameter.getUser().getUserId()), GWConstants.GRANT_WRITE_ACP);
DataPutBucketAcl dataPutBucketAcl = new DataPutBucketAcl(s3Parameter);
dataPutBucketAcl.extract();
AccessControlPolicy preAccessControlPolicy = null;
try {
XmlMapper xmlMapper = new XmlMapper();
preAccessControlPolicy = xmlMapper.readValue(getBucketInfo().getAcl(), AccessControlPolicy.class);
} catch (JsonMappingException e) {
logger.error(e.getMessage());
new GWException(GWErrorCode.INTERNAL_SERVER_ERROR, s3Parameter);
} catch (JsonProcessingException e) {
logger.error(e.getMessage());
new GWException(GWErrorCode.INTERNAL_SERVER_ERROR, s3Parameter);
}
accessControlPolicy = new AccessControlPolicy();
accessControlPolicy.aclList = new AccessControlList();
accessControlPolicy.aclList.grants = new ArrayList<Grant>();
accessControlPolicy.owner = new Owner();
accessControlPolicy.owner.id = String.valueOf(s3Parameter.getUser().getUserId());
accessControlPolicy.owner.displayName = s3Parameter.getUser().getUserName();
String xml = GWUtils.makeAclXml(accessControlPolicy, preAccessControlPolicy, dataPutBucketAcl.hasAclKeyword(), dataPutBucketAcl.getAclXml(), dataPutBucketAcl.getAcl(), getBucketInfo(), String.valueOf(s3Parameter.getUser().getUserId()), s3Parameter.getUser().getUserName(), dataPutBucketAcl.getGrantRead(), dataPutBucketAcl.getGrantWrite(), dataPutBucketAcl.getGrantFullControl(), dataPutBucketAcl.getGrantReadAcp(), dataPutBucketAcl.getGrantWriteAcp(), s3Parameter);
logger.debug(GWConstants.LOG_ACL, xml);
updateBucketAcl(bucket, xml);
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
}
use of com.pspace.ifs.ksan.gw.format.AccessControlPolicy.AccessControlList in project ksan by infinistor.
the class PutObject method process.
@Override
public void process() throws GWException {
logger.info(GWConstants.LOG_PUT_OBJECT_START);
String bucket = s3Parameter.getBucketName();
initBucketInfo(bucket);
String object = s3Parameter.getObjectName();
logger.debug(GWConstants.LOG_BUCKET_OBJECT, bucket, object);
S3Bucket s3Bucket = new S3Bucket();
s3Bucket.setCors(getBucketInfo().getCors());
s3Bucket.setAccess(getBucketInfo().getAccess());
s3Parameter.setBucket(s3Bucket);
GWUtils.checkCors(s3Parameter);
if (s3Parameter.isPublicAccess() && GWUtils.isIgnorePublicAcls(s3Parameter)) {
throw new GWException(GWErrorCode.ACCESS_DENIED, s3Parameter);
}
checkGrantBucket(s3Parameter.isPublicAccess(), String.valueOf(s3Parameter.getUser().getUserId()), GWConstants.GRANT_WRITE);
DataPutObject dataPutObject = new DataPutObject(s3Parameter);
dataPutObject.extract();
S3Metadata s3Metadata = new S3Metadata();
String cacheControl = dataPutObject.getCacheControl();
String contentDisposition = dataPutObject.getContentDisposition();
String contentEncoding = dataPutObject.getContentEncoding();
String contentLanguage = dataPutObject.getContentLanguage();
String contentType = dataPutObject.getContentType();
String contentLengthString = dataPutObject.getContentLength();
String decodedContentLengthString = dataPutObject.getDecodedContentLength();
String contentMD5String = dataPutObject.getContentMD5();
String customerAlgorithm = dataPutObject.getServerSideEncryptionCustomerAlgorithm();
String customerKey = dataPutObject.getServerSideEncryptionCustomerKey();
String customerKeyMD5 = dataPutObject.getServerSideEncryptionCustomerKeyMD5();
String serversideEncryption = dataPutObject.getServerSideEncryption();
s3Metadata.setOwnerId(String.valueOf(s3Parameter.getUser().getUserId()));
s3Metadata.setOwnerName(s3Parameter.getUser().getUserName());
s3Metadata.setUserMetadataMap(dataPutObject.getUserMetadata());
if (!Strings.isNullOrEmpty(serversideEncryption)) {
if (!GWConstants.AES256.equalsIgnoreCase(serversideEncryption)) {
logger.error(GWErrorCode.NOT_IMPLEMENTED.getMessage() + GWConstants.SERVER_SIDE_OPTION);
throw new GWException(GWErrorCode.NOT_IMPLEMENTED, s3Parameter);
} else {
s3Metadata.setServersideEncryption(serversideEncryption);
}
}
if (!Strings.isNullOrEmpty(cacheControl)) {
s3Metadata.setCacheControl(cacheControl);
}
if (!Strings.isNullOrEmpty(contentDisposition)) {
s3Metadata.setContentDisposition(contentDisposition);
}
if (!Strings.isNullOrEmpty(contentEncoding)) {
s3Metadata.setContentEncoding(contentEncoding);
}
if (!Strings.isNullOrEmpty(contentLanguage)) {
s3Metadata.setContentLanguage(contentLanguage);
}
if (!Strings.isNullOrEmpty(contentType)) {
s3Metadata.setContentType(contentType);
}
if (!Strings.isNullOrEmpty(customerAlgorithm)) {
s3Metadata.setCustomerAlgorithm(customerAlgorithm);
}
if (!Strings.isNullOrEmpty(customerKey)) {
s3Metadata.setCustomerKey(customerKey);
}
if (!Strings.isNullOrEmpty(customerKeyMD5)) {
s3Metadata.setCustomerKeyMD5(customerKeyMD5);
}
if (!Strings.isNullOrEmpty(decodedContentLengthString)) {
contentLengthString = decodedContentLengthString;
}
HashCode contentMD5 = null;
if (!Strings.isNullOrEmpty(contentMD5String)) {
s3Metadata.setContentMD5(contentMD5String);
try {
contentMD5 = HashCode.fromBytes(BaseEncoding.base64().decode(contentMD5String));
} catch (IllegalArgumentException iae) {
PrintStack.logging(logger, iae);
throw new GWException(GWErrorCode.INVALID_DIGEST, iae, s3Parameter);
}
if (contentMD5.bits() != MD5.bits()) {
logger.error(GWErrorCode.INVALID_DIGEST.getMessage() + GWConstants.LOG_PUT_OBJECT_HASHCODE_ILLEGAL);
throw new GWException(GWErrorCode.INVALID_DIGEST, s3Parameter);
}
}
long contentLength;
if (Strings.isNullOrEmpty(contentLengthString)) {
logger.error(GWErrorCode.MISSING_CONTENT_LENGTH.getMessage());
throw new GWException(GWErrorCode.MISSING_CONTENT_LENGTH, s3Parameter);
} else {
try {
contentLength = Long.parseLong(contentLengthString);
s3Metadata.setContentLength(contentLength);
} catch (NumberFormatException nfe) {
PrintStack.logging(logger, nfe);
throw new GWException(GWErrorCode.INVALID_ARGUMENT, nfe, s3Parameter);
}
}
accessControlPolicy = new AccessControlPolicy();
accessControlPolicy.aclList = new AccessControlList();
accessControlPolicy.aclList.grants = new ArrayList<Grant>();
accessControlPolicy.owner = new Owner();
accessControlPolicy.owner.id = String.valueOf(s3Parameter.getUser().getUserId());
accessControlPolicy.owner.displayName = s3Parameter.getUser().getUserName();
String aclXml = GWUtils.makeAclXml(accessControlPolicy, null, dataPutObject.hasAclKeyword(), null, dataPutObject.getAcl(), getBucketInfo(), String.valueOf(s3Parameter.getUser().getUserId()), s3Parameter.getUser().getUserName(), dataPutObject.getGrantRead(), dataPutObject.getGrantWrite(), dataPutObject.getGrantFullControl(), dataPutObject.getGrantReadAcp(), dataPutObject.getGrantWriteAcp(), s3Parameter);
logger.debug(GWConstants.LOG_ACL, aclXml);
String bucketEncryption = getBucketInfo().getEncryption();
// check encryption
S3ServerSideEncryption encryption = new S3ServerSideEncryption(bucketEncryption, serversideEncryption, customerAlgorithm, customerKey, customerKeyMD5, s3Parameter);
encryption.build();
// Tagging information
String taggingCount = GWConstants.TAGGING_INIT;
String taggingxml = "";
Tagging tagging = new Tagging();
tagging.tagset = new TagSet();
if (!Strings.isNullOrEmpty(dataPutObject.getTagging())) {
String strtaggingInfo = dataPutObject.getTagging();
String[] strtagset = strtaggingInfo.split(GWConstants.AMPERSAND);
int starttag = 0;
for (String strtag : strtagset) {
if (starttag == 0)
tagging.tagset.tags = new ArrayList<Tag>();
starttag += 1;
Tag tag = new Tag();
String[] keyvalue = strtag.split(GWConstants.EQUAL);
if (keyvalue.length == GWConstants.TAG_KEY_SIZE) {
tag.key = keyvalue[GWConstants.TAG_KEY_INDEX];
tag.value = keyvalue[GWConstants.TAG_VALUE_INDEX];
} else {
tag.key = keyvalue[GWConstants.TAG_KEY_INDEX];
tag.value = "";
}
tagging.tagset.tags.add(tag);
}
try {
taggingxml = new XmlMapper().writeValueAsString(tagging);
} catch (JsonProcessingException e) {
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
if (tagging != null) {
if (tagging.tagset != null && tagging.tagset.tags != null) {
for (Tag t : tagging.tagset.tags) {
// key, value 길이 체크
if (t.key.length() > GWConstants.TAG_KEY_MAX) {
logger.error(GWConstants.LOG_PUT_OBJECT_TAGGING_KEY_LENGTH, t.key.length());
throw new GWException(GWErrorCode.INVALID_TAG, s3Parameter);
}
if (t.value.length() > GWConstants.TAG_VALUE_MAX) {
logger.error(GWConstants.LOG_PUT_OBJECT_TAGGING_VALUE_LENGTH, t.value.length());
throw new GWException(GWErrorCode.INVALID_TAG, s3Parameter);
}
}
}
if (tagging.tagset != null && tagging.tagset.tags != null) {
if (tagging.tagset.tags.size() > GWConstants.TAG_MAX_SIZE) {
logger.error(GWConstants.LOG_PUT_OBJECT_TAGGING_SIZE, tagging.tagset.tags.size());
throw new GWException(GWErrorCode.BAD_REQUEST, s3Parameter);
}
taggingCount = String.valueOf(tagging.tagset.tags.size());
}
}
}
if (!Strings.isNullOrEmpty(dataPutObject.getObjectLockMode())) {
try {
logger.debug(GWConstants.LOG_OBJECT_LOCK, getBucketInfo().getObjectLock());
ObjectLockConfiguration oc = new XmlMapper().readValue(getBucketInfo().getObjectLock(), ObjectLockConfiguration.class);
if (!oc.objectLockEnabled.equals(GWConstants.STATUS_ENABLED)) {
logger.error(GWConstants.LOG_PUT_OBJECT_LOCK_STATUS, oc.objectLockEnabled);
throw new GWException(GWErrorCode.INVALID_REQUEST, s3Parameter);
}
} catch (IOException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
if (!dataPutObject.getObjectLockMode().equals(GWConstants.GOVERNANCE) && !dataPutObject.getObjectLockMode().equals(GWConstants.COMPLIANCE)) {
logger.error(GWConstants.LOG_PUT_OBJECT_LOCK_MODE, dataPutObject.getObjectLockMode());
throw new GWException(GWErrorCode.INVALID_ARGUMENT, s3Parameter);
}
s3Metadata.setLockMode(dataPutObject.getObjectLockMode());
}
if (!Strings.isNullOrEmpty(dataPutObject.getObjectLockRetainUntilDate())) {
if (!dataPutObject.getObjectLockMode().equals(GWConstants.GOVERNANCE) && !dataPutObject.getObjectLockMode().equals(GWConstants.COMPLIANCE)) {
logger.error(GWConstants.LOG_PUT_OBJECT_LOCK_MODE, dataPutObject.getObjectLockMode());
throw new GWException(GWErrorCode.INVALID_ARGUMENT, s3Parameter);
}
try {
ObjectLockConfiguration oc = new XmlMapper().readValue(getBucketInfo().getObjectLock(), ObjectLockConfiguration.class);
if (!oc.objectLockEnabled.equals(GWConstants.STATUS_ENABLED)) {
logger.error(GWConstants.LOG_PUT_OBJECT_LOCK_STATUS, oc.objectLockEnabled);
throw new GWException(GWErrorCode.INVALID_REQUEST, s3Parameter);
}
} catch (IOException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Metadata.setLockExpires(dataPutObject.getObjectLockRetainUntilDate());
}
if (!Strings.isNullOrEmpty(dataPutObject.getObjectLockLegalHold())) {
try {
ObjectLockConfiguration oc = new XmlMapper().readValue(getBucketInfo().getObjectLock(), ObjectLockConfiguration.class);
if (!oc.objectLockEnabled.equals(GWConstants.STATUS_ENABLED)) {
logger.error(GWConstants.LOG_PUT_OBJECT_LOCK_STATUS, oc.objectLockEnabled);
throw new GWException(GWErrorCode.INVALID_REQUEST, s3Parameter);
}
} catch (IOException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Metadata.setLegalHold(dataPutObject.getObjectLockLegalHold());
}
String versioningStatus = getBucketVersioning(bucket);
String versionId = null;
Metadata objMeta = null;
try {
// check exist object
objMeta = open(bucket, object);
if (GWConstants.VERSIONING_ENABLED.equalsIgnoreCase(versioningStatus)) {
versionId = String.valueOf(System.nanoTime());
} else {
versionId = GWConstants.VERSIONING_DISABLE_TAIL;
}
} catch (GWException e) {
logger.info(e.getMessage());
if (GWConfig.getReplicaCount() > 1) {
objMeta = create(bucket, object);
} else {
objMeta = createLocal(bucket, object);
}
if (GWConstants.VERSIONING_ENABLED.equalsIgnoreCase(versioningStatus)) {
versionId = String.valueOf(System.nanoTime());
} else {
versionId = GWConstants.VERSIONING_DISABLE_TAIL;
}
}
S3ObjectOperation objectOperation = new S3ObjectOperation(objMeta, s3Metadata, s3Parameter, versionId, encryption);
S3Object s3Object = objectOperation.putObject();
s3Metadata.setETag(s3Object.getEtag());
s3Metadata.setSize(s3Object.getFileSize());
s3Metadata.setContentLength(s3Object.getFileSize());
s3Metadata.setTier(GWConstants.AWS_TIER_STANTARD);
s3Metadata.setLastModified(s3Object.getLastModified());
s3Metadata.setDeleteMarker(s3Object.getDeleteMarker());
s3Metadata.setVersionId(s3Object.getVersionId());
s3Metadata.setTaggingCount(taggingCount);
if (encryption.isEnableSSEServer()) {
s3Metadata.setServersideEncryption(GWConstants.AES256);
}
s3Parameter.setFileSize(s3Object.getFileSize());
ObjectMapper jsonMapper = new ObjectMapper();
String jsonmeta = "";
try {
jsonmeta = jsonMapper.writeValueAsString(s3Metadata);
} catch (JsonProcessingException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
logger.debug(GWConstants.LOG_PUT_OBJECT_PRIMARY_DISK_ID, objMeta.getPrimaryDisk().getId());
try {
int result;
objMeta.set(s3Object.getEtag(), taggingxml, jsonmeta, aclXml, s3Object.getFileSize());
objMeta.setVersionId(versionId, GWConstants.OBJECT_TYPE_FILE, true);
result = insertObject(bucket, object, objMeta);
logger.debug(GWConstants.LOG_PUT_OBJECT_INFO, bucket, object, s3Object.getFileSize(), s3Object.getEtag(), aclXml, versionId);
} catch (GWException e) {
PrintStack.logging(logger, e);
throw new GWException(GWErrorCode.SERVER_ERROR, s3Parameter);
}
s3Parameter.getResponse().addHeader(HttpHeaders.ETAG, GWUtils.maybeQuoteETag(s3Object.getEtag()));
if (GWConstants.VERSIONING_ENABLED.equalsIgnoreCase(versioningStatus)) {
s3Parameter.getResponse().addHeader(GWConstants.X_AMZ_VERSION_ID, s3Object.getVersionId());
logger.debug(GWConstants.LOG_PUT_OBJECT_VERSIONID, s3Object.getVersionId());
}
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
}
use of com.pspace.ifs.ksan.gw.format.AccessControlPolicy.AccessControlList in project ksan by infinistor.
the class CreateBucket method process.
@Override
public void process() throws GWException {
logger.info(GWConstants.LOG_CREATE_BUCKET_START);
String bucket = s3Parameter.getBucketName();
logger.debug(GWConstants.LOG_CREATE_BUCKET_NAME, bucket);
checkBucketName(bucket);
if (isExistBucket(bucket) || bucket.equalsIgnoreCase(GWConstants.WEBSITE)) {
logger.info(GWConstants.LOG_CREATE_BUCKET_EXIST, bucket);
initBucketInfo(bucket);
if (isBucketOwner(String.valueOf(s3Parameter.getUser().getUserId()))) {
throw new GWException(GWErrorCode.BUCKET_ALREADY_OWNED_BY_YOU, s3Parameter);
}
throw new GWException(GWErrorCode.BUCKET_ALREADY_EXISTS, s3Parameter);
}
DataCreateBucket dataCreateBucket = new DataCreateBucket(s3Parameter);
dataCreateBucket.extract();
accessControlPolicy = new AccessControlPolicy();
accessControlPolicy.aclList = new AccessControlList();
accessControlPolicy.aclList.grants = new ArrayList<Grant>();
accessControlPolicy.owner = new Owner();
accessControlPolicy.owner.id = String.valueOf(s3Parameter.getUser().getUserId());
accessControlPolicy.owner.displayName = s3Parameter.getUser().getUserName();
String xml = GWUtils.makeAclXml(accessControlPolicy, null, dataCreateBucket.hasAclKeyword(), null, dataCreateBucket.getAcl(), getBucketInfo(), String.valueOf(s3Parameter.getUser().getUserId()), s3Parameter.getUser().getUserName(), dataCreateBucket.getGrantRead(), dataCreateBucket.getGrantWrite(), dataCreateBucket.getGrantFullControl(), dataCreateBucket.getGrantReadAcp(), dataCreateBucket.getGrantWriteAcp(), s3Parameter);
logger.debug(GWConstants.LOG_ACL, xml);
int result = 0;
if (!Strings.isNullOrEmpty(dataCreateBucket.getBucketObjectLockEnabled()) && GWConstants.STRING_TRUE.equalsIgnoreCase(dataCreateBucket.getBucketObjectLockEnabled())) {
logger.info(GWConstants.LOG_CREATE_BUCKET_VERSIONING_ENABLED_OBJECT_LOCK_TRUE);
String objectLockXml = GWConstants.OBJECT_LOCK_XML;
result = createBucket(bucket, s3Parameter.getUser().getUserName(), String.valueOf(s3Parameter.getUser().getUserId()), xml, "", objectLockXml);
putBucketVersioning(bucket, GWConstants.STATUS_ENABLED);
} else {
result = createBucket(bucket, s3Parameter.getUser().getUserName(), String.valueOf(s3Parameter.getUser().getUserId()), xml, "", "");
}
if (result != 0) {
throw new GWException(GWErrorCode.INTERNAL_SERVER_DB_ERROR, s3Parameter);
}
s3Parameter.getResponse().addHeader(HttpHeaders.LOCATION, GWConstants.SLASH + bucket);
s3Parameter.getResponse().setStatus(HttpServletResponse.SC_OK);
}
Aggregations