Search in sources :

Example 1 with HttpClientBuilder

use of org.keycloak.adapters.HttpClientBuilder in project keycloak by keycloak.

the class LinkAndExchangeServlet method doTokenExchange.

public AccessTokenResponse doTokenExchange(String realm, String token, String requestedIssuer, String clientId, String clientSecret) throws Exception {
    try (CloseableHttpClient client = (CloseableHttpClient) new HttpClientBuilder().disableTrustManager().build()) {
        String exchangeUrl = KeycloakUriBuilder.fromUri(ServletTestUtils.getAuthServerUrlBase()).path("/auth/realms/{realm}/protocol/openid-connect/token").build(realm).toString();
        HttpPost post = new HttpPost(exchangeUrl);
        HashMap<String, String> parameters = new HashMap<>();
        if (clientSecret != null) {
            String authorization = BasicAuthHelper.createHeader(clientId, clientSecret);
            post.setHeader(HttpHeaders.CONTENT_TYPE, ContentType.APPLICATION_FORM_URLENCODED.toString());
            post.setHeader(HttpHeaders.AUTHORIZATION, authorization);
        } else {
            parameters.put("client_id", clientId);
        }
        parameters.put(OAuth2Constants.GRANT_TYPE, OAuth2Constants.TOKEN_EXCHANGE_GRANT_TYPE);
        parameters.put(OAuth2Constants.SUBJECT_TOKEN, token);
        parameters.put(OAuth2Constants.SUBJECT_TOKEN_TYPE, OAuth2Constants.ACCESS_TOKEN_TYPE);
        parameters.put(OAuth2Constants.REQUESTED_ISSUER, requestedIssuer);
        post.setEntity(new StringEntity(getPostDataString(parameters)));
        HttpResponse response = client.execute(post);
        int statusCode = response.getStatusLine().getStatusCode();
        if (statusCode == 200 || statusCode == 400) {
            return JsonSerialization.readValue(EntityUtils.toString(response.getEntity()), AccessTokenResponse.class);
        } else {
            throw new RuntimeException("Unknown error!");
        }
    }
}
Also used : CloseableHttpClient(org.apache.http.impl.client.CloseableHttpClient) HttpPost(org.apache.http.client.methods.HttpPost) StringEntity(org.apache.http.entity.StringEntity) HashMap(java.util.HashMap) HttpResponse(org.apache.http.HttpResponse) HttpClientBuilder(org.keycloak.adapters.HttpClientBuilder)

Example 2 with HttpClientBuilder

use of org.keycloak.adapters.HttpClientBuilder in project keycloak by keycloak.

the class CamelClient method sendRequest.

public static String sendRequest(HttpServletRequest req) throws CxfRsClient.Failure {
    KeycloakSecurityContext session = (KeycloakSecurityContext) req.getAttribute(KeycloakSecurityContext.class.getName());
    HttpClient client = new HttpClientBuilder().disableTrustManager().build();
    StringBuilder sb = new StringBuilder();
    try {
        // Initially let's invoke a simple Camel-Jetty exposed endpoint
        HttpGet get = new HttpGet("http://localhost:8383/admin-camel-endpoint");
        get.addHeader("Authorization", "Bearer " + session.getTokenString());
        try {
            HttpResponse response = client.execute(get);
            if (response.getStatusLine().getStatusCode() != 200) {
                return "There was a failure processing request.  You either didn't configure Keycloak properly or you don't have admin permission? Status code is " + response.getStatusLine().getStatusCode();
            }
            HttpEntity entity = response.getEntity();
            InputStream is = entity.getContent();
            try {
                sb.append(getStringFromInputStream(is));
            } finally {
                is.close();
            }
        } catch (IOException e) {
            throw new RuntimeException(e);
        }
        // Here we invoke a Jetty endpoint, published using Camel RestDSL
        get = new HttpGet("http://localhost:8484/restdsl/hello/world");
        get.addHeader("Authorization", "Bearer " + session.getTokenString());
        try {
            HttpResponse response = client.execute(get);
            if (response.getStatusLine().getStatusCode() != 200) {
                return "There was a failure processing request with the RestDSL endpoint.  You either didn't configure Keycloak properly or you don't have admin permission? Status code is " + response.getStatusLine().getStatusCode();
            }
            HttpEntity entity = response.getEntity();
            InputStream is = entity.getContent();
            try {
                sb.append(getStringFromInputStream(is));
            } finally {
                is.close();
            }
        } catch (IOException e) {
            throw new RuntimeException(e);
        }
    } finally {
        client.getConnectionManager().shutdown();
    }
    return sb.toString();
}
Also used : HttpEntity(org.apache.http.HttpEntity) KeycloakSecurityContext(org.keycloak.KeycloakSecurityContext) InputStream(java.io.InputStream) HttpClient(org.apache.http.client.HttpClient) HttpGet(org.apache.http.client.methods.HttpGet) HttpResponse(org.apache.http.HttpResponse) HttpClientBuilder(org.keycloak.adapters.HttpClientBuilder) IOException(java.io.IOException)

Example 3 with HttpClientBuilder

use of org.keycloak.adapters.HttpClientBuilder in project keycloak by keycloak.

the class CxfRsClient method getCustomers.

public static List<String> getCustomers(HttpServletRequest req) throws Failure {
    KeycloakSecurityContext session = (KeycloakSecurityContext) req.getAttribute(KeycloakSecurityContext.class.getName());
    HttpClient client = new HttpClientBuilder().disableTrustManager().build();
    try {
        HttpGet get = new HttpGet(UriUtils.getOrigin(req.getRequestURL().toString()) + "/cxf/customerservice/customers");
        get.addHeader("Authorization", "Bearer " + session.getTokenString());
        try {
            HttpResponse response = client.execute(get);
            if (response.getStatusLine().getStatusCode() != 200) {
                throw new Failure(response.getStatusLine().getStatusCode());
            }
            HttpEntity entity = response.getEntity();
            InputStream is = entity.getContent();
            try {
                return JsonSerialization.readValue(is, TypedList.class);
            } finally {
                is.close();
            }
        } catch (IOException e) {
            throw new RuntimeException(e);
        }
    } finally {
        client.getConnectionManager().shutdown();
    }
}
Also used : HttpEntity(org.apache.http.HttpEntity) KeycloakSecurityContext(org.keycloak.KeycloakSecurityContext) InputStream(java.io.InputStream) HttpClient(org.apache.http.client.HttpClient) HttpGet(org.apache.http.client.methods.HttpGet) HttpResponse(org.apache.http.HttpResponse) HttpClientBuilder(org.keycloak.adapters.HttpClientBuilder) IOException(java.io.IOException)

Example 4 with HttpClientBuilder

use of org.keycloak.adapters.HttpClientBuilder in project keycloak by keycloak.

the class LoginPageTest method acceptLanguageHeader.

@Test
public void acceptLanguageHeader() throws IOException {
    ProfileAssume.assumeCommunity();
    try (CloseableHttpClient httpClient = (CloseableHttpClient) new HttpClientBuilder().build()) {
        ApacheHttpClient4Engine engine = new ApacheHttpClient4Engine(httpClient);
        ResteasyClient client = new ResteasyClientBuilder().httpEngine(engine).build();
        loginPage.open();
        try (Response responseDe = client.target(driver.getCurrentUrl()).request().acceptLanguage("de").get()) {
            Assert.assertTrue(responseDe.readEntity(String.class).contains("Anmeldung bei test"));
            try (Response responseEn = client.target(driver.getCurrentUrl()).request().acceptLanguage("en").get()) {
                Assert.assertTrue(responseEn.readEntity(String.class).contains("Sign in to test"));
            }
        }
        client.close();
    }
}
Also used : Response(javax.ws.rs.core.Response) CloseableHttpClient(org.apache.http.impl.client.CloseableHttpClient) ResteasyClientBuilder(org.jboss.resteasy.client.jaxrs.ResteasyClientBuilder) ResteasyClient(org.jboss.resteasy.client.jaxrs.ResteasyClient) ApacheHttpClient4Engine(org.jboss.resteasy.client.jaxrs.engines.ApacheHttpClient4Engine) HttpClientBuilder(org.keycloak.adapters.HttpClientBuilder) Test(org.junit.Test)

Example 5 with HttpClientBuilder

use of org.keycloak.adapters.HttpClientBuilder in project keycloak by keycloak.

the class AbstractKerberosTest method initHttpClient.

protected void initHttpClient(boolean useSpnego) {
    if (client != null) {
        cleanupApacheHttpClient();
    }
    DefaultHttpClient httpClient = (DefaultHttpClient) new HttpClientBuilder().disableCookieCache(false).build();
    httpClient.getAuthSchemes().register(AuthSchemes.SPNEGO, spnegoSchemeFactory);
    if (useSpnego) {
        Credentials fake = new Credentials() {

            @Override
            public String getPassword() {
                return null;
            }

            @Override
            public Principal getUserPrincipal() {
                return null;
            }
        };
        httpClient.getCredentialsProvider().setCredentials(new AuthScope(null, -1, null), fake);
    }
    ApacheHttpClient4Engine engine = new ApacheHttpClient4Engine(httpClient);
    client = new ResteasyClientBuilder().httpEngine(engine).build();
}
Also used : ResteasyClientBuilder(org.jboss.resteasy.client.jaxrs.ResteasyClientBuilder) ApacheHttpClient4Engine(org.jboss.resteasy.client.jaxrs.engines.ApacheHttpClient4Engine) AuthScope(org.apache.http.auth.AuthScope) HttpClientBuilder(org.keycloak.adapters.HttpClientBuilder) DefaultHttpClient(org.apache.http.impl.client.DefaultHttpClient) Credentials(org.apache.http.auth.Credentials)

Aggregations

HttpClientBuilder (org.keycloak.adapters.HttpClientBuilder)8 HttpClient (org.apache.http.client.HttpClient)4 HttpResponse (org.apache.http.HttpResponse)3 CloseableHttpClient (org.apache.http.impl.client.CloseableHttpClient)3 ResteasyClientBuilder (org.jboss.resteasy.client.jaxrs.ResteasyClientBuilder)3 ApacheHttpClient4Engine (org.jboss.resteasy.client.jaxrs.engines.ApacheHttpClient4Engine)3 IOException (java.io.IOException)2 InputStream (java.io.InputStream)2 HashMap (java.util.HashMap)2 Response (javax.ws.rs.core.Response)2 HttpEntity (org.apache.http.HttpEntity)2 HttpGet (org.apache.http.client.methods.HttpGet)2 ResteasyClient (org.jboss.resteasy.client.jaxrs.ResteasyClient)2 Test (org.junit.Test)2 KeycloakSecurityContext (org.keycloak.KeycloakSecurityContext)2 AuthScope (org.apache.http.auth.AuthScope)1 Credentials (org.apache.http.auth.Credentials)1 HttpPost (org.apache.http.client.methods.HttpPost)1 StringEntity (org.apache.http.entity.StringEntity)1 DefaultHttpClient (org.apache.http.impl.client.DefaultHttpClient)1