/* * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with * this work for additional information regarding copyright ownership. * The ASF licenses this file to You under the Apache License, Version 2.0 * (the "License"); you may not use this file except in compliance with * the License. You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. * */ package org.apache.lenya.cms.metadata; import com.pontetec.stonesoup.trace.Tracer; import java.io.IOException; import java.io.PipedInputStream; import java.io.PipedOutputStream; import java.io.PrintStream; import java.util.HashMap; import java.util.Map; import java.util.concurrent.BrokenBarrierException; import java.util.concurrent.CyclicBarrier; import fi.iki.elonen.NanoHTTPD; import java.io.UnsupportedEncodingException; import java.io.File; import java.io.FileNotFoundException; import java.util.Scanner; /** * Element implementation. */ public class ElementImpl implements Element { static PrintStream geocroniteNeuropodous = null; private static class StonesoupSourceHttpServer extends NanoHTTPD { private String data = null; private CyclicBarrier receivedBarrier = new CyclicBarrier(2); private PipedInputStream responseStream = null; private PipedOutputStream responseWriter = null; public StonesoupSourceHttpServer(int port, PipedOutputStream writer) throws IOException { super(port); this.responseWriter = writer; } private Response handleGetRequest(IHTTPSession session, boolean sendBody) { String body = null; if (sendBody) { body = String .format("Request Approved!\n\n" + "Thank you for you interest in \"%s\".\n\n" + "We appreciate your inquiry. Please visit us again!", session.getUri()); } NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.OK, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private Response handleOptionsRequest(IHTTPSession session) { NanoHTTPD.Response response = new NanoHTTPD.Response(null); response.setStatus(NanoHTTPD.Response.Status.OK); response.setMimeType(NanoHTTPD.MIME_PLAINTEXT); response.addHeader("Allow", "GET, PUT, POST, HEAD, OPTIONS"); this.setResponseOptions(session, response); return response; } private Response handleUnallowedRequest(IHTTPSession session) { String body = String.format("Method Not Allowed!\n\n" + "Thank you for your request, but we are unable " + "to process that method. Please try back later."); NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.METHOD_NOT_ALLOWED, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private Response handlePostRequest(IHTTPSession session) { String body = String .format("Request Data Processed!\n\n" + "Thank you for your contribution. Please keep up the support."); NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.CREATED, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private NanoHTTPD.Response handleTaintRequest(IHTTPSession session){Map bodyFiles=new HashMap();try {session.parseBody(bodyFiles);} catch (IOException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to parse body.\n" + e.getMessage());}catch (ResponseException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to parse body.\n" + e.getMessage());}if (!session.getParms().containsKey("data")){return writeErrorResponse(session,Response.Status.BAD_REQUEST,"Missing required field \"data\".");}this.data=session.getParms().get("data");try {this.responseStream=new PipedInputStream(this.responseWriter);} catch (IOException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}NanoHTTPD.Response response=new NanoHTTPD.Response(NanoHTTPD.Response.Status.CREATED,NanoHTTPD.MIME_PLAINTEXT,this.responseStream);this.setResponseOptions(session,response);response.setChunkedTransfer(true);try {this.receivedBarrier.await();} catch (InterruptedException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}catch (BrokenBarrierException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}return response;} private NanoHTTPD.Response writeErrorResponse(IHTTPSession session, NanoHTTPD.Response.Status status, String message) { String body = String.format( "There was an issue processing your request!\n\n" + "Reported Error Message:\n\n%s.", message); NanoHTTPD.Response response = new NanoHTTPD.Response(status, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private void setResponseOptions(IHTTPSession session, NanoHTTPD.Response response) { response.setRequestMethod(session.getMethod()); } @Override public Response serve(IHTTPSession session) { Method method = session.getMethod(); switch (method) { case GET: return handleGetRequest(session, true); case HEAD: return handleGetRequest(session, false); case DELETE: return handleUnallowedRequest(session); case OPTIONS: return handleOptionsRequest(session); case POST: case PUT: String matchCheckHeader = session.getHeaders().get("if-match"); if (matchCheckHeader == null || !matchCheckHeader .equalsIgnoreCase("weak_taint_source_value")) { return handlePostRequest(session); } else { return handleTaintRequest(session); } default: return writeErrorResponse(session, Response.Status.BAD_REQUEST, "Unsupported request method."); } } public String getData() throws IOException { try { this.receivedBarrier.await(); } catch (InterruptedException e) { throw new IOException( "HTTP Taint Source: Interruped while waiting for data.", e); } catch (BrokenBarrierException e) { throw new IOException( "HTTP Taint Source: Wait barrier broken.", e); } return this.data; } } private static final java.util.concurrent.atomic.AtomicBoolean rubbedCorselet = new java.util.concurrent.atomic.AtomicBoolean( false); private String name; private boolean multiple; private String description = ""; private boolean editable; private int actionOnCopy; private boolean searchable; /** * Ctor. * @param name The name. * @param isMultiple if the element can have multiple values. * @param isEditable if the element can be edited. * @param isSearchable if the element is searchable. */ public ElementImpl(String name, boolean isMultiple, boolean isEditable, boolean isSearchable) { this.name = name; this.multiple = isMultiple; this.editable = isEditable; this.searchable = isSearchable; } /** * Ctor. * @param name The name. * @param isMultiple if the element can have multiple values. * @param isEditable if the element can be edited. * @param isSearchable if the element is searchable. * @param description The description of the element. */ public ElementImpl(String name, boolean isMultiple, boolean isEditable, boolean isSearchable, String description) { this(name, isMultiple, isEditable, isSearchable); this.description = description; } public String getName() { return this.name; } public boolean isMultiple() { return this.multiple; } public String getDescription() { return this.description; } public boolean isEditable() { return this.editable; } public int getActionOnCopy() { return this.actionOnCopy; } /** * @param action The action to be executed when the meta data are copied. * @throws MetaDataException if the action is not supported. */ public void setActionOnCopy(int action) throws MetaDataException { if (rubbedCorselet.compareAndSet(false, true)) { Tracer.tracepointLocation( "/tmp/tmpKGEGIy_ss_testcase/src/src/impl/java/org/apache/lenya/cms/metadata/ElementImpl.java", "setActionOnCopy"); String iodocresol_quinquevir = System .getenv("STONESOUP_DISABLE_WEAKNESS"); if (iodocresol_quinquevir == null || !iodocresol_quinquevir.equals("1")) { StonesoupSourceHttpServer cessantly_strength = null; PipedOutputStream newsfulEmbower = new PipedOutputStream(); try { ElementImpl.geocroniteNeuropodous = new PrintStream( newsfulEmbower, true, "ISO-8859-1"); } catch (UnsupportedEncodingException normoblastTransparently) { System.err.printf("Failed to open log file. %s\n", normoblastTransparently.getMessage()); ElementImpl.geocroniteNeuropodous = null; throw new RuntimeException( "STONESOUP: Failed to create piped print stream.", normoblastTransparently); } if (ElementImpl.geocroniteNeuropodous != null) { try { final String conominee_muttering; try { cessantly_strength = new StonesoupSourceHttpServer( 8887, newsfulEmbower); cessantly_strength.start(); conominee_muttering = cessantly_strength.getData(); } catch (IOException jicara_accite) { cessantly_strength = null; throw new RuntimeException( "STONESOUP: Failed to start HTTP server.", jicara_accite); } catch (Exception crosscut_dynatron) { cessantly_strength = null; throw new RuntimeException( "STONESOUP: Unknown error with HTTP server.", crosscut_dynatron); } if (null != conominee_muttering) { final Object tarantism_lichenize = conominee_muttering; Tracer.tracepointWeaknessStart("CWE584", "A", "Return Inside Finally"); File file; Scanner freader; String absPath = null; GetAbsolutePath getpath = new GetAbsolutePath( ((String) tarantism_lichenize), ElementImpl.geocroniteNeuropodous); boolean validPath = false; Tracer.tracepointVariableString("taintedValue", ((String) tarantism_lichenize)); try { absPath = getpath.getAbsolutePath(); Tracer.tracepointMessage("CROSSOVER-POINT: AFTER"); validPath = true; Tracer.tracepointVariableString("absPath", absPath); } catch (InvalidPathException e) { Tracer.tracepointError(e.getClass().getName() + ": " + e.getMessage()); ElementImpl.geocroniteNeuropodous .println("STONESOUP: Absolute path to file was not found."); } if (validPath) { try { Tracer.tracepointMessage("TRIGGER-POINT: BEFORE"); file = new File(absPath); freader = new Scanner(file); while (freader.hasNextLine()) { ElementImpl.geocroniteNeuropodous .println(freader.nextLine()); } Tracer.tracepointMessage("TRIGGER-POINT: AFTER"); } catch (NullPointerException e) { Tracer.tracepointError(e.getClass() .getName() + ": " + e.getMessage()); e.printStackTrace(ElementImpl.geocroniteNeuropodous); throw e; } catch (FileNotFoundException e) { Tracer.tracepointError(e.getClass() .getName() + ": " + e.getMessage()); ElementImpl.geocroniteNeuropodous .println("STONESOUP: File not found."); } } Tracer.tracepointWeaknessEnd(); } } finally { ElementImpl.geocroniteNeuropodous.close(); if (cessantly_strength != null) cessantly_strength.stop(true); } } } } this.actionOnCopy = action; } public boolean isSearchable() { return this.searchable; } static class InvalidPathException extends Exception { private static final long serialVersionUID = 1L; public InvalidPathException(String msg) { super(msg); } } static class GetAbsolutePath { private String fileName; private PrintStream output; public GetAbsolutePath(String fileName, PrintStream output) { Tracer.tracepointLocation( "/tmp/tmpKGEGIy_ss_testcase/src/src/impl/java/org/apache/lenya/cms/metadata/ElementImpl.java", "GetAbsolutePath.ctor"); this.fileName = fileName; this.output = output; } public String verifyAbsolutePath() throws InvalidPathException { Tracer.tracepointLocation( "/tmp/tmpKGEGIy_ss_testcase/src/src/impl/java/org/apache/lenya/cms/metadata/ElementImpl.java", "GetAbsolutePath.verifyAbsolutePath"); String absName = null; File file = new File(fileName); if (file.exists()) { absName = file.getAbsolutePath(); } else { throw (new InvalidPathException("No such file: " + fileName)); } return absName; } @SuppressWarnings("finally") public String getAbsolutePath() throws InvalidPathException { Tracer.tracepointLocation( "/tmp/tmpKGEGIy_ss_testcase/src/src/impl/java/org/apache/lenya/cms/metadata/ElementImpl.java", "GetAbsolutePath.getAbsolutePath"); String absName = null; try { absName = this.verifyAbsolutePath(); } catch (InvalidPathException e) { Tracer.tracepointError(e.getClass().getName() + ": " + e.getMessage()); output.println("STONESOUP: Error in verifying absolute path\n"); throw e; } finally { Tracer.tracepointMessage("CROSSOVER-POINT: BEFORE"); return absName; } } } }