From e6a30ca03b47e31ff6693107363eab915c35bbb3 Mon Sep 17 00:00:00 2001 From: Viacheslav Kukhtyn Date: Fri, 8 Jan 2021 17:32:43 +0200 Subject: [PATCH] Add credentials for REST API call node --- .../credentials/AnonymousCredentials.java | 22 +++++++++++ .../engine/credentials/BasicCredentials.java | 26 +++++++++++++ .../CertPemCredentials.java} | 6 +-- .../engine/mqtt/TbMqttNodeConfiguration.java | 4 +- .../engine/mqtt/azure/TbAzureIotHubNode.java | 6 +-- .../azure/TbAzureIotHubNodeConfiguration.java | 3 -- ...als.java => MqttAnonymousCredentials.java} | 12 +----- ...entials.java => MqttBasicCredentials.java} | 23 ++--------- .../credentials/MqttCertPemCredentials.java | 21 ++++++++++ .../credentials/MqttClientCredentials.java | 16 ++++---- .../rule/engine/rest/TbHttpClient.java | 9 ++++- .../rest/TbRestApiCallNodeConfiguration.java | 4 ++ .../credentials/HttpAnonymousCredentials.java | 21 ++++++++++ .../credentials/HttpBasicCredentials.java | 31 +++++++++++++++ .../credentials/HttpCertPemCredentials.java | 21 ++++++++++ .../credentials/HttpClientCredentials.java | 38 +++++++++++++++++++ .../credentials/HttpBasicCredentialsTest.java | 34 +++++++++++++++++ 17 files changed, 246 insertions(+), 51 deletions(-) create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/AnonymousCredentials.java create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/BasicCredentials.java rename rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/{mqtt/credentials/CertPemClientCredentials.java => credentials/CertPemCredentials.java} (98%) rename rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/{AnonymousCredentials.java => MqttAnonymousCredentials.java} (73%) rename rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/{BasicCredentials.java => MqttBasicCredentials.java} (66%) create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttCertPemCredentials.java create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpAnonymousCredentials.java create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpBasicCredentials.java create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpCertPemCredentials.java create mode 100644 rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpClientCredentials.java create mode 100644 rule-engine/rule-engine-components/src/test/java/org/thingsboard/rule/engine/rest/credentials/HttpBasicCredentialsTest.java diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/AnonymousCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/AnonymousCredentials.java new file mode 100644 index 0000000000..176899341b --- /dev/null +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/AnonymousCredentials.java @@ -0,0 +1,22 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.credentials; + +import com.fasterxml.jackson.annotation.JsonIgnoreProperties; + +@JsonIgnoreProperties(ignoreUnknown = true) +public class AnonymousCredentials { +} diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/BasicCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/BasicCredentials.java new file mode 100644 index 0000000000..63eab59045 --- /dev/null +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/BasicCredentials.java @@ -0,0 +1,26 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.credentials; + +import com.fasterxml.jackson.annotation.JsonIgnoreProperties; +import lombok.Data; + +@Data +@JsonIgnoreProperties(ignoreUnknown = true) +public class BasicCredentials { + private String username; + private String password; +} diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/CertPemClientCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/CertPemCredentials.java similarity index 98% rename from rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/CertPemClientCredentials.java rename to rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/CertPemCredentials.java index df9f9f8275..055741584c 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/CertPemClientCredentials.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/credentials/CertPemCredentials.java @@ -13,7 +13,7 @@ * See the License for the specific language governing permissions and * limitations under the License. */ -package org.thingsboard.rule.engine.mqtt.credentials; +package org.thingsboard.rule.engine.credentials; import com.fasterxml.jackson.annotation.JsonIgnoreProperties; import io.netty.handler.ssl.ClientAuth; @@ -55,8 +55,7 @@ import java.util.Optional; @Data @Slf4j @JsonIgnoreProperties(ignoreUnknown = true) -public class CertPemClientCredentials implements MqttClientCredentials { - +public class CertPemCredentials { private static final String TLS_VERSION = "TLSv1.2"; private String caCert; @@ -64,7 +63,6 @@ public class CertPemClientCredentials implements MqttClientCredentials { private String privateKey; private String password; - @Override public Optional initSslContext() { try { Security.addProvider(new BouncyCastleProvider()); diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/TbMqttNodeConfiguration.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/TbMqttNodeConfiguration.java index 10e8ecb3b7..b90e43efd1 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/TbMqttNodeConfiguration.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/TbMqttNodeConfiguration.java @@ -17,7 +17,7 @@ package org.thingsboard.rule.engine.mqtt; import lombok.Data; import org.thingsboard.rule.engine.api.NodeConfiguration; -import org.thingsboard.rule.engine.mqtt.credentials.AnonymousCredentials; +import org.thingsboard.rule.engine.mqtt.credentials.MqttAnonymousCredentials; import org.thingsboard.rule.engine.mqtt.credentials.MqttClientCredentials; @Data @@ -42,7 +42,7 @@ public class TbMqttNodeConfiguration implements NodeConfiguration initSslContext() { - return Optional.empty(); - } +public class MqttAnonymousCredentials extends AnonymousCredentials implements MqttClientCredentials { } - diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/BasicCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttBasicCredentials.java similarity index 66% rename from rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/BasicCredentials.java rename to rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttBasicCredentials.java index fa0adbaca4..44eb18badc 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/BasicCredentials.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttBasicCredentials.java @@ -15,28 +15,13 @@ */ package org.thingsboard.rule.engine.mqtt.credentials; -import io.netty.handler.ssl.SslContext; -import lombok.Data; import org.thingsboard.mqtt.MqttClientConfig; +import org.thingsboard.rule.engine.credentials.BasicCredentials; -import java.util.Optional; - -@Data -public class BasicCredentials implements MqttClientCredentials { - - private String username; - private String password; - - @Override - public Optional initSslContext() { - return Optional.empty(); - } - +public class MqttBasicCredentials extends BasicCredentials implements MqttClientCredentials { @Override public void configure(MqttClientConfig config) { - config.setUsername(username); - config.setPassword(password); + config.setUsername(getUsername()); + config.setPassword(getPassword()); } - } - diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttCertPemCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttCertPemCredentials.java new file mode 100644 index 0000000000..0aef057601 --- /dev/null +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttCertPemCredentials.java @@ -0,0 +1,21 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.mqtt.credentials; + +import org.thingsboard.rule.engine.credentials.CertPemCredentials; + +public class MqttCertPemCredentials extends CertPemCredentials implements MqttClientCredentials { +} diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttClientCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttClientCredentials.java index 4814fb3afb..e5c08320f8 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttClientCredentials.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/mqtt/credentials/MqttClientCredentials.java @@ -23,18 +23,16 @@ import org.thingsboard.rule.engine.mqtt.azure.AzureIotHubSasCredentials; import java.util.Optional; -@JsonTypeInfo( - use = JsonTypeInfo.Id.NAME, - include = JsonTypeInfo.As.PROPERTY, - property = "type") +@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, property = "type") @JsonSubTypes({ - @JsonSubTypes.Type(value = AnonymousCredentials.class, name = "anonymous"), - @JsonSubTypes.Type(value = BasicCredentials.class, name = "basic"), + @JsonSubTypes.Type(value = MqttAnonymousCredentials.class, name = "anonymous"), + @JsonSubTypes.Type(value = MqttBasicCredentials.class, name = "basic"), @JsonSubTypes.Type(value = AzureIotHubSasCredentials.class, name = "sas"), - @JsonSubTypes.Type(value = CertPemClientCredentials.class, name = "cert.PEM")}) + @JsonSubTypes.Type(value = MqttCertPemCredentials.class, name = "cert.PEM")}) public interface MqttClientCredentials { - - Optional initSslContext(); + default Optional initSslContext() { + return Optional.empty(); + } default void configure(MqttClientConfig config) { } diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbHttpClient.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbHttpClient.java index f25d246a2e..08cda8e322 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbHttpClient.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbHttpClient.java @@ -17,6 +17,7 @@ package org.thingsboard.rule.engine.rest; import io.netty.channel.EventLoopGroup; import io.netty.channel.nio.NioEventLoopGroup; +import io.netty.handler.ssl.SslContext; import io.netty.handler.ssl.SslContextBuilder; import lombok.Data; import lombok.extern.slf4j.Slf4j; @@ -133,7 +134,7 @@ public class TbHttpClient { } else { this.eventLoopGroup = new NioEventLoopGroup(); Netty4ClientHttpRequestFactory nettyFactory = new Netty4ClientHttpRequestFactory(this.eventLoopGroup); - nettyFactory.setSslContext(SslContextBuilder.forClient().build()); + nettyFactory.setSslContext(initSslContext()); nettyFactory.setReadTimeout(config.getReadTimeoutMs()); httpClient = new AsyncRestTemplate(nettyFactory); } @@ -142,6 +143,11 @@ public class TbHttpClient { } } + private SslContext initSslContext() throws SSLException { + return this.config.getCredentials().initSslContext() + .orElse(SslContextBuilder.forClient().build()); + } + private void checkSystemProxyProperties() throws TbNodeException { boolean useHttpProxy = !StringUtils.isEmpty(System.getProperty("http.proxyHost")) && !StringUtils.isEmpty(System.getProperty("http.proxyPort")); boolean useHttpsProxy = !StringUtils.isEmpty(System.getProperty("https.proxyHost")) && !StringUtils.isEmpty(System.getProperty("https.proxyPort")); @@ -226,6 +232,7 @@ public class TbHttpClient { private HttpHeaders prepareHeaders(TbMsgMetaData metaData) { HttpHeaders headers = new HttpHeaders(); config.getHeaders().forEach((k, v) -> headers.add(TbNodeUtils.processPattern(k, metaData), TbNodeUtils.processPattern(v, metaData))); + config.getCredentials().getBasicAuthHeaderValue().ifPresent(v -> headers.add("Authorization", v)); return headers; } diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbRestApiCallNodeConfiguration.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbRestApiCallNodeConfiguration.java index bcc6ad60c8..961e2602bc 100644 --- a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbRestApiCallNodeConfiguration.java +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/TbRestApiCallNodeConfiguration.java @@ -18,6 +18,8 @@ package org.thingsboard.rule.engine.rest; import com.fasterxml.jackson.annotation.JsonIgnoreProperties; import lombok.Data; import org.thingsboard.rule.engine.api.NodeConfiguration; +import org.thingsboard.rule.engine.rest.credentials.HttpAnonymousCredentials; +import org.thingsboard.rule.engine.rest.credentials.HttpClientCredentials; import java.util.Collections; import java.util.Map; @@ -42,6 +44,7 @@ public class TbRestApiCallNodeConfiguration implements NodeConfiguration getBasicAuthHeaderValue() { + String authString = getUsername() + ":" + getPassword(); + String encodedAuthString = new String(Base64.encodeBase64(authString.getBytes(StandardCharsets.UTF_8))); + return Optional.of("Basic " + encodedAuthString); + } +} diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpCertPemCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpCertPemCredentials.java new file mode 100644 index 0000000000..3aac4a596f --- /dev/null +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpCertPemCredentials.java @@ -0,0 +1,21 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.rest.credentials; + +import org.thingsboard.rule.engine.credentials.CertPemCredentials; + +public class HttpCertPemCredentials extends CertPemCredentials implements HttpClientCredentials { +} diff --git a/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpClientCredentials.java b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpClientCredentials.java new file mode 100644 index 0000000000..0f81f6ad8b --- /dev/null +++ b/rule-engine/rule-engine-components/src/main/java/org/thingsboard/rule/engine/rest/credentials/HttpClientCredentials.java @@ -0,0 +1,38 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.rest.credentials; + +import com.fasterxml.jackson.annotation.JsonSubTypes; +import com.fasterxml.jackson.annotation.JsonTypeInfo; +import io.netty.handler.ssl.SslContext; + +import java.util.Optional; + +@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, property = "type") +@JsonSubTypes({ + @JsonSubTypes.Type(value = HttpAnonymousCredentials.class, name = "anonymous"), + @JsonSubTypes.Type(value = HttpBasicCredentials.class, name = "basic"), + @JsonSubTypes.Type(value = HttpCertPemCredentials.class, name = "cert.PEM")}) +public interface HttpClientCredentials { + default Optional initSslContext() { + return Optional.empty(); + } + + default Optional getBasicAuthHeaderValue() { + return Optional.empty(); + } +} + diff --git a/rule-engine/rule-engine-components/src/test/java/org/thingsboard/rule/engine/rest/credentials/HttpBasicCredentialsTest.java b/rule-engine/rule-engine-components/src/test/java/org/thingsboard/rule/engine/rest/credentials/HttpBasicCredentialsTest.java new file mode 100644 index 0000000000..abdbd76cc4 --- /dev/null +++ b/rule-engine/rule-engine-components/src/test/java/org/thingsboard/rule/engine/rest/credentials/HttpBasicCredentialsTest.java @@ -0,0 +1,34 @@ +/** + * Copyright © 2016-2020 The Thingsboard Authors + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.thingsboard.rule.engine.rest.credentials; + +import org.junit.Assert; +import org.junit.Test; + +import java.util.Optional; + +public class HttpBasicCredentialsTest { + @Test + public void getBasicAuthHeaderValueTest() { + HttpBasicCredentials credentials = new HttpBasicCredentials(); + credentials.setUsername("testUser"); + credentials.setPassword("testPwd"); + Optional actualHeaderValue = credentials.getBasicAuthHeaderValue(); + Optional expectedHeaderValue = Optional.of("Basic dGVzdFVzZXI6dGVzdFB3ZA=="); + + Assert.assertEquals(expectedHeaderValue, actualHeaderValue); + } +}