/*
* #%L
* Alfresco Repository WAR Community
* %%
* Copyright (C) 2005 - 2016 Alfresco Software Limited
* %%
* This file is part of the Alfresco software.
* If the software was purchased under a paid Alfresco license, the terms of
* the paid license agreement will prevail. Otherwise, the software is
* provided under the following open source license terms:
*
* Alfresco is free software: you can redistribute it and/or modify
* it under the terms of the GNU Lesser General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* Alfresco is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with Alfresco. If not, see
Abstract implementation of web authentication.
* * @author PavelYur * */ public abstract class AbstractAuthenticationHandler implements AuthenticationDriver, ActivateableBean { private final static String HEADER_WWW_AUTHENTICATE = "WWW-Authenticate"; protected Log logger = LogFactory.getLog(getClass()); protected AuthenticationService authenticationService; protected PersonService personService; private boolean isActive = true; public void setAuthenticationService(AuthenticationService authenticationService) { this.authenticationService = authenticationService; } public void setPersonService(PersonService personService) { this.personService = personService; } public void setActive(boolean isActive) { this.isActive = isActive; } public boolean isActive() { return this.isActive; } /** * Returns the value of 'WWW-Authenticate' http header that determine what type of authentication to use by * client. * * @return value */ public abstract String getWWWAuthenticate(); /* (non-Javadoc) * @see org.alfresco.repo.webdav.auth.SharepointAuthenticationHandler#restartLoginChallenge(javax.servlet.ServletContext, javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse) */ public void restartLoginChallenge(ServletContext context, HttpServletRequest request, HttpServletResponse response) { if (logger.isDebugEnabled()) logger.debug("Force the client to prompt for logon details"); response.setHeader(HEADER_WWW_AUTHENTICATE, getWWWAuthenticate()); response.setStatus(HttpServletResponse.SC_UNAUTHORIZED); } }