Search in sources :

Example 6 with OAuthLoginModule

use of org.olat.login.oauth.OAuthLoginModule in project OpenOLAT by OpenOLAT.

the class ADFSApi method getAccessTokenEndpoint.

public String getAccessTokenEndpoint() {
    OAuthLoginModule oauthModule = CoreSpringFactory.getImpl(OAuthLoginModule.class);
    String endpoint = oauthModule.getAdfsOAuth2Endpoint();
    if (!endpoint.endsWith("/")) {
        endpoint += "/";
    endpoint += "token";
    return endpoint;
Also used : OAuthLoginModule(org.olat.login.oauth.OAuthLoginModule)

Example 7 with OAuthLoginModule

use of org.olat.login.oauth.OAuthLoginModule in project OpenOLAT by OpenOLAT.

the class OpenIdConnectApi method getAuthorizationUrl.

public String getAuthorizationUrl(OAuthConfig config) {
    OAuthLoginModule oauthModule = CoreSpringFactory.getImpl(OAuthLoginModule.class);
    String url = oauthModule.getOpenIdConnectIFAuthorizationEndPoint();
    StringBuilder authorizeUrl = new StringBuilder();
    authorizeUrl.append(url).append("?").append("response_type=").append(OAuthEncoder.encode("id_token token")).append("&client_id=").append(config.getApiKey()).append("&redirect_uri=").append(OAuthEncoder.encode(config.getCallback())).append("&scope=").append(OAuthEncoder.encode("openid email")).append("&state=").append(UUID.randomUUID().toString()).append("&nonce=").append(UUID.randomUUID().toString());
    return authorizeUrl.toString();
Also used : OAuthLoginModule(org.olat.login.oauth.OAuthLoginModule)

Example 8 with OAuthLoginModule

use of org.olat.login.oauth.OAuthLoginModule in project OpenOLAT by OpenOLAT.

the class TequilaApi method getAccessTokenEndpoint.

public String getAccessTokenEndpoint() {
    OAuthLoginModule oauthModule = CoreSpringFactory.getImpl(OAuthLoginModule.class);
    String endpoint = oauthModule.getTequilaOAuth2Endpoint();
    if (!endpoint.endsWith("/")) {
        endpoint += "/";
    endpoint += "token";
    return endpoint;
Also used : OAuthLoginModule(org.olat.login.oauth.OAuthLoginModule)

Example 9 with OAuthLoginModule

use of org.olat.login.oauth.OAuthLoginModule in project OpenOLAT by OpenOLAT.

the class DMZDispatcher method execute.

 * Main method called by OpenOLATServlet. This processess all requests for
 * users who are not authenticated.
 * @param request
 * @param response
 * @param uriPrefix
public void execute(HttpServletRequest request, HttpServletResponse response) {
    if (rejectRequest(request, response)) {
    UserRequest ureq = null;
    String uriPrefix = DispatcherModule.getLegacyUriPrefix(request);
    try {
        // upon creation URL is checked for
        ureq = new UserRequestImpl(uriPrefix, request, response);
    } catch (NumberFormatException nfe) {
        // a 404 message must be shown -> e.g. robots correct their links.
        if (log.isDebug()) {
            log.debug("Bad Request " + request.getPathInfo());
        DispatcherModule.sendBadRequest(request.getPathInfo(), response);
    try {
        // find out about which subdispatcher is meant
        // e.g. got here because of /dmz/...
        // maybe something like /dmz/registration/
        // add the context path to align with uriPrefix e.g. /olat/dmz/
        String pathInfo = request.getContextPath() + request.getPathInfo();
        ChiefControllerCreator subPathccc = null;
        // if /olat/dmz/
        boolean dmzOnly = pathInfo.equals(uriPrefix);
        if (!dmzOnly) {
            int sl = pathInfo.indexOf('/', uriPrefix.length());
            String sub;
            if (sl > 1) {
                // e.g. something like /registration/ or /pwchange/
                sub = pathInfo.substring(uriPrefix.length() - 1, sl + 1);
            } else {
                // e.g. something like /info.html from (/dmz/info.html)
                sub = pathInfo;
            // chief controller creator for sub path, e.g.
            subPathccc = dmzServicesByPath.get(sub);
            if (subPathccc != null) {
                UserSession usess = ureq.getUserSession();
                Windows ws = Windows.getWindows(usess);
                synchronized (ws) {
                    // o_clusterOK by:fj per user session
                    ChiefController occ = subPathccc.createChiefController(ureq);
                    Window window = occ.getWindow();
                    window.dispatchRequest(ureq, true);
        // else a /olat/dmz/ request
        UserSession usess = ureq.getUserSession();
        Windows ws = Windows.getWindows(usess);
        // and make it useless under heavily load or 2 concurrent requests
        synchronized (usess) {
            // o_clusterOK by:fj per user session
            Window window;
            boolean windowHere = ws.isExisting(uriPrefix, ureq.getWindowID());
            boolean validDispatchUri = ureq.isValidDispatchURI();
            if (validDispatchUri && !windowHere) {
                // probably valid framework link from previous user && new Session(no window):
                // when a previous user logged off, and 30min later (when the httpsession is invalidated), the next user clicks e.g. on
                // the log-in link in the -same- browser window ->
                // -> there is no window -> create a new one
                window = null;
                // update locale infos
                // request new windows since it is a new usersession, the old one was purged
                ws = Windows.getWindows(usess);
            } else if (validDispatchUri) {
                window = ws.getWindow(ureq);
            } else if (dmzOnly) {
                // e.g. /dmz/ -> start screen, clear previous session data
                window = null;
                // update locale infos
                OAuthLoginModule oauthModule = CoreSpringFactory.getImpl(OAuthLoginModule.class);
                if (canRedirectConfigurableOAuth(request, response, oauthModule)) {
                } else if (canRedirectOAuth(request, oauthModule)) {
                    OAuthSPI oauthSpi = oauthModule.getRootProvider();
                    HttpSession session = request.getSession();
                    OAuthResource.redirect(oauthSpi, response, session);
                // request new windows since it is a new usersession, the old one was purged
                ws = Windows.getWindows(usess);
            } else {
            if (window == null) {
                // no window found, -> start a new WorkFlow/Controller and obtain the window
                // main controller which also implements the windowcontroller for pagestatus and modal dialogs
                Object wSettings = usess.getEntry(WINDOW_SETTINGS);
                ChiefController occ = chiefControllerCreator.createChiefController(ureq);
                window = occ.getWindow();
                String businessPath = (String) usess.removeEntryFromNonClearedStore(DMZDISPATCHER_BUSINESSPATH);
                if (businessPath != null) {
                    List<ContextEntry> ces = BusinessControlFactory.getInstance().createCEListFromString(businessPath);
                    window.getDTabs().activate(ureq, null, ces);
                // apply the settings forward
                usess.putEntryInNonClearedStore(WINDOW_SETTINGS, wSettings);
    } catch (InvalidRequestParameterException e) {
        try {
        } catch (IOException e1) {
            log.error("An exception occured while handling the invalid request parameter exception...", e1);
    } catch (Throwable th) {
        try {
            ChiefController msgcc = MsgFactory.createMessageChiefController(ureq, th);
            // the controller's window must be failsafe also
            msgcc.getWindow().dispatchRequest(ureq, true);
        // do not dispatch (render only), since this is a new Window created as
        // a result of another window's click.
        } catch (Throwable t) {
            log.error("An exception occured while handling the exception...", t);
Also used : Window(org.olat.core.gui.components.Window) OAuthLoginModule(org.olat.login.oauth.OAuthLoginModule) HttpSession(javax.servlet.http.HttpSession) Windows(org.olat.core.gui.Windows) ChiefController(org.olat.core.gui.control.ChiefController) IOException( ContextEntry( UserSessionManager(org.olat.core.util.session.UserSessionManager) InvalidRequestParameterException(org.olat.core.gui.components.form.flexible.impl.InvalidRequestParameterException) ChiefControllerCreator(org.olat.core.gui.control.ChiefControllerCreator) UserSession(org.olat.core.util.UserSession) OAuthSPI(org.olat.login.oauth.OAuthSPI) UserRequest(org.olat.core.gui.UserRequest) UserRequestImpl(org.olat.core.gui.UserRequestImpl)

Example 10 with OAuthLoginModule

use of org.olat.login.oauth.OAuthLoginModule in project openolat by klemens.

the class TequilaApi method getAuthorizationUrl.

public String getAuthorizationUrl(OAuthConfig config) {
    OAuthLoginModule oauthModule = CoreSpringFactory.getImpl(OAuthLoginModule.class);
    String endpoint = oauthModule.getTequilaOAuth2Endpoint();
    if (!endpoint.endsWith("/")) {
        endpoint += "/";
    String url = endpoint + "auth?response_type=code" + "&client_id=" + urlEncode(config.getApiKey()) + "&scope=" + config.getScope() + "&redirect_uri=" + urlEncode(config.getCallback());
    return url;
Also used : OAuthLoginModule(org.olat.login.oauth.OAuthLoginModule)


OAuthLoginModule (org.olat.login.oauth.OAuthLoginModule)12 IOException ( HttpSession (javax.servlet.http.HttpSession)2 UserRequest (org.olat.core.gui.UserRequest)2 UserRequestImpl (org.olat.core.gui.UserRequestImpl)2 Windows (org.olat.core.gui.Windows)2 Window (org.olat.core.gui.components.Window)2 InvalidRequestParameterException (org.olat.core.gui.components.form.flexible.impl.InvalidRequestParameterException)2 ChiefController (org.olat.core.gui.control.ChiefController)2 ChiefControllerCreator (org.olat.core.gui.control.ChiefControllerCreator)2 ContextEntry ( UserSession (org.olat.core.util.UserSession)2 UserSessionManager (org.olat.core.util.session.UserSessionManager)2 OAuthSPI (org.olat.login.oauth.OAuthSPI)2