mirror of
https://github.com/vanitasvitae/Smack.git
synced 2024-09-27 18:19:33 +02:00
9c772add93
This adds the ability to provide a distinct authorization identifier for use by SASL mechanisms. Not all SASL mechanisms support this operation, in particular CRAM-MD5. Both the javax and provided SASL implementations are extended, and an authzid parameter added to the authenticate method. The authorization identifier is passed as a EntityBareJid in order to assure the correct form. Resolves SMACK-677. Minor-Modifications-By: Florian Schmaus <flo@geekplace.eu>
75 lines
1.9 KiB
Java
75 lines
1.9 KiB
Java
/**
|
|
*
|
|
* Copyright the original author or authors
|
|
*
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
* you may not use this file except in compliance with the License.
|
|
* You may obtain a copy of the License at
|
|
*
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
*
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
* See the License for the specific language governing permissions and
|
|
* limitations under the License.
|
|
*/
|
|
package org.jivesoftware.smack.sasl.javax;
|
|
|
|
import java.util.Map;
|
|
|
|
import javax.security.sasl.Sasl;
|
|
|
|
/**
|
|
* Implementation of the SASL GSSAPI mechanism.
|
|
*
|
|
* @author Jay Kline
|
|
*/
|
|
public class SASLGSSAPIMechanism extends SASLJavaXMechanism {
|
|
|
|
public static final String NAME = GSSAPI;
|
|
|
|
static {
|
|
System.setProperty("javax.security.auth.useSubjectCredsOnly","false");
|
|
System.setProperty("java.security.auth.login.config","gss.conf");
|
|
}
|
|
|
|
@Override
|
|
public boolean authzidSupported() {
|
|
return true;
|
|
}
|
|
|
|
@Override
|
|
public String getName() {
|
|
return NAME;
|
|
}
|
|
|
|
@Override
|
|
protected Map<String, String> getSaslProps() {
|
|
Map<String, String> props = super.getSaslProps();
|
|
props.put(Sasl.SERVER_AUTH,"TRUE");
|
|
return props;
|
|
}
|
|
|
|
/**
|
|
* GSSAPI differs from all other SASL mechanism such that it required the FQDN host name as
|
|
* server name and not the serviceName (At least that is what old code comments of Smack tell
|
|
* us).
|
|
*/
|
|
@Override
|
|
protected String getServerName() {
|
|
return host;
|
|
}
|
|
|
|
@Override
|
|
public int getPriority() {
|
|
return 100;
|
|
}
|
|
|
|
@Override
|
|
public SASLGSSAPIMechanism newInstance() {
|
|
return new SASLGSSAPIMechanism();
|
|
}
|
|
|
|
}
|