JWTOptions.java

  1. /*
  2.  * GovWay - A customizable API Gateway
  3.  * https://govway.org
  4.  *
  5.  * Copyright (c) 2005-2025 Link.it srl (https://link.it).
  6.  *
  7.  * This program is free software: you can redistribute it and/or modify
  8.  * it under the terms of the GNU General Public License version 3, as published by
  9.  * the Free Software Foundation.
  10.  *
  11.  * This program is distributed in the hope that it will be useful,
  12.  * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13.  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  14.  * GNU General Public License for more details.
  15.  *
  16.  * You should have received a copy of the GNU General Public License
  17.  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
  18.  *
  19.  */

  20. package org.openspcoop2.utils.security;

  21. import java.util.ArrayList;
  22. import java.util.List;

  23. /**
  24.  * JWEOptions
  25.  *
  26.  * @author Bussu Giovanni (bussu@link.it)
  27.  * @author  $Author$
  28.  * @version $Rev$, $Date$
  29.  *
  30.  */
  31. public class JWTOptions {

  32.     private JOSESerialization serialization;
  33.    
  34.     private boolean permitUseHeaderX5C = true;
  35.     private boolean permitUseHeaderX5U = true;
  36.     private boolean permitUseHeaderX5T = true;
  37.     private boolean permitUseHeaderX5T_256 = true;
  38.     private boolean permitUseHeaderJWK= true;
  39.     private boolean permitUseHeaderJKU = true;
  40.     private boolean permitUseHeaderKID = true;
  41.    

  42.     public JWTOptions(JOSESerialization serialization) {
  43.         this.serialization = serialization;
  44.     }
  45.    
  46.     public JOSESerialization getSerialization() {
  47.         return this.serialization;
  48.     }
  49.     public void setSerialization(JOSESerialization serialization) {
  50.         this.serialization = serialization;
  51.     }
  52.    
  53.     public boolean isPermitUseHeaderX5C() {
  54.         return this.permitUseHeaderX5C;
  55.     }
  56.     public void setPermitUseHeaderX5C(boolean permitUseHeaderX5C) {
  57.         this.permitUseHeaderX5C = permitUseHeaderX5C;
  58.     }

  59.     public boolean isPermitUseHeaderX5U() {
  60.         return this.permitUseHeaderX5U;
  61.     }
  62.     public void setPermitUseHeaderX5U(boolean permitUseHeaderX5U) {
  63.         this.permitUseHeaderX5U = permitUseHeaderX5U;
  64.     }

  65.     public boolean isPermitUseHeaderX5T() {
  66.         return this.permitUseHeaderX5T;
  67.     }
  68.     public void setPermitUseHeaderX5T(boolean permitUseHeaderX5T) {
  69.         this.permitUseHeaderX5T = permitUseHeaderX5T;
  70.     }

  71.     public boolean isPermitUseHeaderX5T_256() {
  72.         return this.permitUseHeaderX5T_256;
  73.     }
  74.     public void setPermitUseHeaderX5T_256(boolean permitUseHeaderX5T_256) {
  75.         this.permitUseHeaderX5T_256 = permitUseHeaderX5T_256;
  76.     }
  77.    
  78.     public boolean isPermitUseHeaderJWK() {
  79.         return this.permitUseHeaderJWK;
  80.     }
  81.     public void setPermitUseHeaderJWK(boolean permitUseHeaderJWK) {
  82.         this.permitUseHeaderJWK = permitUseHeaderJWK;
  83.     }

  84.     public boolean isPermitUseHeaderJKU() {
  85.         return this.permitUseHeaderJKU;
  86.     }
  87.     public void setPermitUseHeaderJKU(boolean permitUseHeaderJKU) {
  88.         this.permitUseHeaderJKU = permitUseHeaderJKU;
  89.     }
  90.    
  91.     public boolean isPermitUseHeaderKID() {
  92.         return this.permitUseHeaderKID;
  93.     }
  94.     public void setPermitUseHeaderKID(boolean permitUseHeaderKID) {
  95.         this.permitUseHeaderKID = permitUseHeaderKID;
  96.     }
  97.    
  98.    
  99.     public List<String> headersNotPermitted(org.apache.cxf.rs.security.jose.common.JoseHeaders hdrs){
  100.         List<String> list = new ArrayList<>();
  101.         if(hdrs.getX509Chain()!=null && !hdrs.getX509Chain().isEmpty()) {
  102.             if(this.isPermitUseHeaderX5C()==false) {
  103.                 list.add(JwtHeaders.JWT_HDR_X5C);
  104.             }
  105.         }
  106.         if(hdrs.getJsonWebKey()!=null) {
  107.             if(this.isPermitUseHeaderJWK()==false) {
  108.                 list.add(JwtHeaders.JWT_HDR_JWK);
  109.             }
  110.         }
  111.         if(hdrs.getX509Url()!=null) {
  112.             if(this.isPermitUseHeaderX5U()==false) {
  113.                 list.add(JwtHeaders.JWT_HDR_X5U);
  114.             }
  115.         }
  116.         if(hdrs.getJsonWebKeysUrl()!=null) {
  117.             if(this.isPermitUseHeaderJKU()==false) {
  118.                 list.add(JwtHeaders.JWT_HDR_JKU);
  119.             }
  120.         }
  121.         if(hdrs.getX509Thumbprint()!=null) {
  122.             if(this.isPermitUseHeaderX5T()==false) {
  123.                 list.add(JwtHeaders.JWT_HDR_X5T);
  124.             }
  125.         }
  126.         if(hdrs.getX509ThumbprintSHA256()!=null) {
  127.             if(this.isPermitUseHeaderX5T_256()==false) {
  128.                 list.add(JwtHeaders.JWT_HDR_X5t_S256);
  129.             }
  130.         }
  131.         if(hdrs.getKeyId()!=null) {
  132.             if(this.isPermitUseHeaderKID()==false) {
  133.                 list.add(JwtHeaders.JWT_HDR_KID);
  134.             }
  135.         }
  136.         return list;
  137.     }
  138. }