Search in sources :

Example 1 with CaptchaClientException

use of org.wso2.carbon.identity.captcha.exception.CaptchaClientException in project identity-governance by wso2-extensions.

the class CaptchaFilter method doFilter.

@Override
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
    try {
        if (!CaptchaDataHolder.getInstance().isReCaptchaEnabled()) {
            filterChain.doFilter(servletRequest, servletResponse);
            return;
        }
        // May need multiple reads of request body value from connectors.
        if (servletRequest instanceof HttpServletRequest) {
            String currentPath = ((HttpServletRequest) servletRequest).getRequestURI();
            if (StringUtils.isNotBlank(currentPath) && CaptchaUtil.isPathAvailable(currentPath, CaptchaDataHolder.getInstance().getReCaptchaRequestWrapUrls())) {
                servletRequest = new CaptchaHttpServletRequestWrapper((HttpServletRequest) servletRequest);
            }
        }
        List<CaptchaConnector> captchaConnectors = CaptchaDataHolder.getInstance().getCaptchaConnectors();
        CaptchaConnector selectedCaptchaConnector = null;
        for (CaptchaConnector captchaConnector : captchaConnectors) {
            if (captchaConnector.canHandle(servletRequest, servletResponse) && (selectedCaptchaConnector == null || captchaConnector.getPriority() > selectedCaptchaConnector.getPriority())) {
                selectedCaptchaConnector = captchaConnector;
            }
        }
        if (selectedCaptchaConnector == null) {
            filterChain.doFilter(servletRequest, servletResponse);
            return;
        }
        // Check whether captcha is required or will reach to the max failed attempts with the current attempt.
        CaptchaPreValidationResponse captchaPreValidationResponse = selectedCaptchaConnector.preValidate(servletRequest, servletResponse);
        if (captchaPreValidationResponse == null) {
            // Captcha connector failed to response. Default is success.
            filterChain.doFilter(servletRequest, servletResponse);
            return;
        }
        HttpServletRequest httpRequest = (HttpServletRequest) servletRequest;
        HttpServletResponse httpResponse = (HttpServletResponse) servletResponse;
        if (captchaPreValidationResponse.isCaptchaValidationRequired()) {
            try {
                boolean validCaptcha = selectedCaptchaConnector.verifyCaptcha(servletRequest, servletResponse);
                if (!validCaptcha) {
                    log.warn("Captcha validation failed for the user.");
                    httpResponse.sendRedirect(CaptchaUtil.getOnFailRedirectUrl(httpRequest.getHeader("referer"), captchaPreValidationResponse.getOnCaptchaFailRedirectUrls(), captchaPreValidationResponse.getCaptchaAttributes()));
                    return;
                }
            } catch (CaptchaClientException e) {
                log.warn("Captcha validation failed for the user. Cause : " + e.getMessage());
                httpResponse.sendRedirect(CaptchaUtil.getOnFailRedirectUrl(httpRequest.getHeader("referer"), captchaPreValidationResponse.getOnCaptchaFailRedirectUrls(), captchaPreValidationResponse.getCaptchaAttributes()));
                return;
            }
        }
        // Enable reCaptcha for the destination.
        if (captchaPreValidationResponse.isEnableCaptchaForRequestPath()) {
            if (captchaPreValidationResponse.getCaptchaAttributes() != null) {
                for (Map.Entry<String, String> parameter : captchaPreValidationResponse.getCaptchaAttributes().entrySet()) {
                    servletRequest.setAttribute(parameter.getKey(), parameter.getValue());
                }
            }
            doFilter(captchaPreValidationResponse, servletRequest, servletResponse, filterChain);
            return;
        }
        // Below the no. of max failed attempts, including the current attempt
        if (!captchaPreValidationResponse.isPostValidationRequired() || (!captchaPreValidationResponse.isCaptchaValidationRequired() && !captchaPreValidationResponse.isMaxFailedLimitReached())) {
            doFilter(captchaPreValidationResponse, servletRequest, servletResponse, filterChain);
            return;
        }
        CaptchaHttpServletResponseWrapper responseWrapper = new CaptchaHttpServletResponseWrapper(httpResponse);
        doFilter(captchaPreValidationResponse, servletRequest, responseWrapper, filterChain);
        CaptchaPostValidationResponse postValidationResponse = selectedCaptchaConnector.postValidate(servletRequest, responseWrapper);
        // Check whether this attempt is failed
        if (postValidationResponse == null || postValidationResponse.isSuccessfulAttempt()) {
            if (responseWrapper.isRedirect()) {
                httpResponse.sendRedirect(responseWrapper.getRedirectURL());
            }
            return;
        }
        if (postValidationResponse.isEnableCaptchaResponsePath() && responseWrapper.isRedirect()) {
            httpResponse.sendRedirect(CaptchaUtil.getUpdatedUrl(responseWrapper.getRedirectURL(), postValidationResponse.getCaptchaAttributes()));
        }
    } catch (CaptchaException e) {
        log.error("Error occurred in processing captcha.", e);
        ((HttpServletResponse) servletResponse).sendRedirect(CaptchaUtil.getErrorPage("Server Error", "Something " + "went wrong. Please try again"));
    }
}
Also used : CaptchaConnector(org.wso2.carbon.identity.captcha.connector.CaptchaConnector) CaptchaClientException(org.wso2.carbon.identity.captcha.exception.CaptchaClientException) CaptchaHttpServletRequestWrapper(org.wso2.carbon.identity.captcha.util.CaptchaHttpServletRequestWrapper) HttpServletResponse(javax.servlet.http.HttpServletResponse) CaptchaPostValidationResponse(org.wso2.carbon.identity.captcha.connector.CaptchaPostValidationResponse) HttpServletRequest(javax.servlet.http.HttpServletRequest) CaptchaPreValidationResponse(org.wso2.carbon.identity.captcha.connector.CaptchaPreValidationResponse) CaptchaHttpServletResponseWrapper(org.wso2.carbon.identity.captcha.util.CaptchaHttpServletResponseWrapper) Map(java.util.Map) CaptchaException(org.wso2.carbon.identity.captcha.exception.CaptchaException)

Example 2 with CaptchaClientException

use of org.wso2.carbon.identity.captcha.exception.CaptchaClientException in project identity-governance by wso2-extensions.

the class CaptchaUtil method isValidCaptcha.

public static boolean isValidCaptcha(String reCaptchaResponse) throws CaptchaException {
    CloseableHttpClient httpclient = HttpClientBuilder.create().useSystemProperties().build();
    HttpPost httppost = new HttpPost(CaptchaDataHolder.getInstance().getReCaptchaVerifyUrl());
    List<BasicNameValuePair> params = Arrays.asList(new BasicNameValuePair("secret", CaptchaDataHolder.getInstance().getReCaptchaSecretKey()), new BasicNameValuePair("response", reCaptchaResponse));
    httppost.setEntity(new UrlEncodedFormEntity(params, StandardCharsets.UTF_8));
    HttpResponse response;
    try {
        response = httpclient.execute(httppost);
    } catch (IOException e) {
        throw new CaptchaServerException("Unable to get the verification response.", e);
    }
    HttpEntity entity = response.getEntity();
    if (entity == null) {
        throw new CaptchaServerException("reCaptcha verification response is not received.");
    }
    try {
        try (InputStream in = entity.getContent()) {
            JsonObject verificationResponse = new JsonParser().parse(IOUtils.toString(in)).getAsJsonObject();
            if (verificationResponse == null || verificationResponse.get("success") == null || !verificationResponse.get("success").getAsBoolean()) {
                throw new CaptchaClientException("reCaptcha verification failed. Please try again.");
            }
        }
    } catch (IOException e) {
        throw new CaptchaServerException("Unable to read the verification response.", e);
    }
    return true;
}
Also used : CloseableHttpClient(org.apache.http.impl.client.CloseableHttpClient) HttpPost(org.apache.http.client.methods.HttpPost) CaptchaClientException(org.wso2.carbon.identity.captcha.exception.CaptchaClientException) HttpEntity(org.apache.http.HttpEntity) InputStream(java.io.InputStream) HttpResponse(org.apache.http.HttpResponse) JsonObject(com.google.gson.JsonObject) CaptchaServerException(org.wso2.carbon.identity.captcha.exception.CaptchaServerException) UrlEncodedFormEntity(org.apache.http.client.entity.UrlEncodedFormEntity) IOException(java.io.IOException) BasicNameValuePair(org.apache.http.message.BasicNameValuePair) JsonParser(com.google.gson.JsonParser)

Aggregations

CaptchaClientException (org.wso2.carbon.identity.captcha.exception.CaptchaClientException)2 JsonObject (com.google.gson.JsonObject)1 JsonParser (com.google.gson.JsonParser)1 IOException (java.io.IOException)1 InputStream (java.io.InputStream)1 Map (java.util.Map)1 HttpServletRequest (javax.servlet.http.HttpServletRequest)1 HttpServletResponse (javax.servlet.http.HttpServletResponse)1 HttpEntity (org.apache.http.HttpEntity)1 HttpResponse (org.apache.http.HttpResponse)1 UrlEncodedFormEntity (org.apache.http.client.entity.UrlEncodedFormEntity)1 HttpPost (org.apache.http.client.methods.HttpPost)1 CloseableHttpClient (org.apache.http.impl.client.CloseableHttpClient)1 BasicNameValuePair (org.apache.http.message.BasicNameValuePair)1 CaptchaConnector (org.wso2.carbon.identity.captcha.connector.CaptchaConnector)1 CaptchaPostValidationResponse (org.wso2.carbon.identity.captcha.connector.CaptchaPostValidationResponse)1 CaptchaPreValidationResponse (org.wso2.carbon.identity.captcha.connector.CaptchaPreValidationResponse)1 CaptchaException (org.wso2.carbon.identity.captcha.exception.CaptchaException)1 CaptchaServerException (org.wso2.carbon.identity.captcha.exception.CaptchaServerException)1 CaptchaHttpServletRequestWrapper (org.wso2.carbon.identity.captcha.util.CaptchaHttpServletRequestWrapper)1