pion-net
4.0.9
|
#include <HTTPCookieAuth.hpp>
Inherits pion::net::HTTPAuth.
Public Member Functions | |
HTTPCookieAuth (PionUserManagerPtr userManager, const std::string &login="/login", const std::string &logout="/logout", const std::string &redirect="") | |
virtual | ~HTTPCookieAuth () |
virtual destructor | |
virtual bool | handleRequest (HTTPRequestPtr &request, TCPConnectionPtr &tcp_conn) |
virtual void | setOption (const std::string &name, const std::string &value) |
![]() | |
HTTPAuth (PionUserManagerPtr userManager) | |
default constructor | |
virtual | ~HTTPAuth () |
virtual destructor | |
void | addRestrict (const std::string &resource) |
void | addPermit (const std::string &resource) |
virtual bool | addUser (std::string const &username, std::string const &password) |
virtual bool | updateUser (std::string const &username, std::string const &password) |
virtual bool | removeUser (std::string const &username) |
virtual PionUserPtr | getUser (std::string const &username) |
Protected Member Functions | |
bool | processLogin (HTTPRequestPtr &http_request, TCPConnectionPtr &tcp_conn) |
void | handleUnauthorized (HTTPRequestPtr &http_request, TCPConnectionPtr &tcp_conn) |
void | handleRedirection (HTTPRequestPtr &http_request, TCPConnectionPtr &tcp_conn, const std::string &redirection_url, const std::string &new_cookie="", bool delete_cookie=false) |
void | handleOk (HTTPRequestPtr &http_request, TCPConnectionPtr &tcp_conn, const std::string &new_cookie="", bool delete_cookie=false) |
void | expireCache (const PionDateTime &time_now) |
![]() | |
bool | needAuthentication (HTTPRequestPtr const &http_request) const |
bool | findResource (const AuthResourceSet &resource_set, const std::string &resource) const |
void | setLogger (PionLogger log_ptr) |
sets the logger to be used |
Additional Inherited Members | |
![]() | |
typedef std::set< std::string > | AuthResourceSet |
data type for a set of resources to be authenticated | |
![]() | |
PionLogger | m_logger |
primary logging interface used by this class | |
PionUserManagerPtr | m_user_manager |
container used to manager user objects | |
AuthResourceSet | m_restrict_list |
collection of resources that require authentication | |
AuthResourceSet | m_white_list |
collection of resources that do NOT require authentication | |
boost::mutex | m_resource_mutex |
mutex used to protect access to the resources |
HTTPCookieAuth: handles HTTP authentication and session management in accordance with RFC 2617 (http://tools.ietf.org/html/rfc2617 ) using cookies.
Definition at line 28 of file HTTPCookieAuth.hpp.
pion::net::HTTPCookieAuth::HTTPCookieAuth | ( | PionUserManagerPtr | userManager, |
const std::string & | login = "/login" , |
||
const std::string & | logout = "/logout" , |
||
const std::string & | redirect = "" |
||
) |
default constructor
userManager | |
login | - URL resource for login request. Typical login request has format: http://website/login?user="username"&pass="password"&url="redirection_url" |
logout | - URL resource for logout request. Typical logout request has format: http://website/logout?url="redirection_url" |
redirect | - if not empty, URL for redirection in case of authentication failure if empty - send code 401 on authentication failure |
Definition at line 31 of file HTTPCookieAuth.cpp.
References pion::net::HTTPAuth::setLogger().
|
protected |
Cache expiration cleanup. (Call it periodically)
Definition at line 261 of file HTTPCookieAuth.cpp.
Referenced by handleRequest().
|
protected |
used to send OK responses with new cookie
http_request | the new HTTP request to handle |
tcp_conn | the TCP connection that has the new request |
Definition at line 237 of file HTTPCookieAuth.cpp.
References pion::net::HTTPResponseWriter::create(), and pion::net::TCPConnection::finish().
Referenced by processLogin().
|
protected |
used to send redirection responses
http_request | the new HTTP request to handle |
tcp_conn | the TCP connection that has the new request |
Definition at line 199 of file HTTPCookieAuth.cpp.
References pion::net::HTTPResponseWriter::create(), and pion::net::TCPConnection::finish().
Referenced by handleUnauthorized(), and processLogin().
|
virtual |
attempts to validate authentication of a new HTTP request. If request valid, pointer to user identity object (if any) will be preserved in the request and return "true". If request not authenticated, appropriate response is sent over tcp_conn and return "false";
Note: if request matches "login" resource, then login sequences attempted. If "name" and "pass" attributes match user definition, a random cookie is created and associated with given user session. If request contains "url" attribute, then page redirection response returned. Otherwise - empty 204 response.
request | the new HTTP request to handle |
tcp_conn | the TCP connection that has the new request |
Implements pion::net::HTTPAuth.
Definition at line 53 of file HTTPCookieAuth.cpp.
References expireCache(), handleUnauthorized(), pion::net::HTTPAuth::needAuthentication(), and processLogin().
|
protected |
used to send responses when access to resource is not authorized
http_request | the new HTTP request to handle |
tcp_conn | the TCP connection that has the new request |
Definition at line 171 of file HTTPCookieAuth.cpp.
References pion::net::HTTPResponseWriter::create(), pion::net::TCPConnection::finish(), and handleRedirection().
Referenced by handleRequest(), and processLogin().
|
protected |
check if given request is a login/logout and process it
http_request | the new HTTP request to handle |
tcp_conn | the TCP connection that has the new request |
Definition at line 105 of file HTTPCookieAuth.cpp.
References pion::algo::base64_encode(), handleOk(), handleRedirection(), handleUnauthorized(), pion::net::HTTPAuth::m_user_manager, pion::net::HTTPServer::stripTrailingSlash(), and pion::algo::url_decode().
Referenced by handleRequest().
|
virtual |
sets a configuration option Valid options:
name | the name of the option to change |
value | the value of the option |
Reimplemented from pion::net::HTTPAuth.
Definition at line 93 of file HTTPCookieAuth.cpp.