OAuth2GetAccessToken.java 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. /**
  2. * ownCloud Android client application
  3. *
  4. * Copyright (C) 2015 ownCloud Inc.
  5. *
  6. * This program is free software: you can redistribute it and/or modify
  7. * it under the terms of the GNU General Public License version 2,
  8. * as published by the Free Software Foundation.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. */
  19. package com.owncloud.android.operations;
  20. import java.util.ArrayList;
  21. import java.util.HashMap;
  22. import java.util.Map;
  23. import org.apache.commons.httpclient.methods.PostMethod;
  24. import org.apache.commons.httpclient.NameValuePair;
  25. import org.json.JSONException;
  26. import org.json.JSONObject;
  27. import com.owncloud.android.authentication.OAuth2Constants;
  28. import com.owncloud.android.lib.common.OwnCloudClient;
  29. import com.owncloud.android.lib.common.operations.RemoteOperation;
  30. import com.owncloud.android.lib.common.operations.RemoteOperationResult;
  31. import com.owncloud.android.lib.common.operations.RemoteOperationResult.ResultCode;
  32. import com.owncloud.android.lib.common.utils.Log_OC;
  33. public class OAuth2GetAccessToken extends RemoteOperation {
  34. private static final String TAG = OAuth2GetAccessToken.class.getSimpleName();
  35. private String mClientId;
  36. private String mRedirectUri;
  37. private String mGrantType;
  38. private String mOAuth2AuthorizationResponse;
  39. private Map<String, String> mOAuth2ParsedAuthorizationResponse;
  40. private Map<String, String> mResultTokenMap;
  41. public OAuth2GetAccessToken(String clientId, String redirectUri, String grantType, String oAuth2AuthorizationResponse) {
  42. mClientId = clientId;
  43. mRedirectUri = redirectUri;
  44. mGrantType = grantType;
  45. mOAuth2AuthorizationResponse = oAuth2AuthorizationResponse;
  46. mOAuth2ParsedAuthorizationResponse = new HashMap<String, String>();
  47. mResultTokenMap = null;
  48. }
  49. /*
  50. public Map<String, String> getResultTokenMap() {
  51. return mResultTokenMap;
  52. }
  53. */
  54. @Override
  55. protected RemoteOperationResult run(OwnCloudClient client) {
  56. RemoteOperationResult result = null;
  57. PostMethod postMethod = null;
  58. try {
  59. parseAuthorizationResponse();
  60. if (mOAuth2ParsedAuthorizationResponse.keySet().contains(OAuth2Constants.KEY_ERROR)) {
  61. if (OAuth2Constants.VALUE_ERROR_ACCESS_DENIED.equals(mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_ERROR))) {
  62. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR_ACCESS_DENIED);
  63. } else {
  64. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR);
  65. }
  66. }
  67. if (result == null) {
  68. NameValuePair[] nameValuePairs = new NameValuePair[4];
  69. nameValuePairs[0] = new NameValuePair(OAuth2Constants.KEY_GRANT_TYPE, mGrantType);
  70. nameValuePairs[1] = new NameValuePair(OAuth2Constants.KEY_CODE, mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_CODE));
  71. nameValuePairs[2] = new NameValuePair(OAuth2Constants.KEY_REDIRECT_URI, mRedirectUri);
  72. nameValuePairs[3] = new NameValuePair(OAuth2Constants.KEY_CLIENT_ID, mClientId);
  73. //nameValuePairs[4] = new NameValuePair(OAuth2Constants.KEY_SCOPE, mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_SCOPE));
  74. postMethod = new PostMethod(client.getWebdavUri().toString());
  75. postMethod.setRequestBody(nameValuePairs);
  76. int status = client.executeMethod(postMethod);
  77. String response = postMethod.getResponseBodyAsString();
  78. if (response != null && response.length() > 0) {
  79. JSONObject tokenJson = new JSONObject(response);
  80. parseAccessTokenResult(tokenJson);
  81. if (mResultTokenMap.get(OAuth2Constants.KEY_ERROR) != null || mResultTokenMap.get(OAuth2Constants.KEY_ACCESS_TOKEN) == null) {
  82. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR);
  83. } else {
  84. result = new RemoteOperationResult(true, status, postMethod.getResponseHeaders());
  85. ArrayList<Object> data = new ArrayList<Object>();
  86. data.add(mResultTokenMap);
  87. result.setData(data);
  88. }
  89. } else {
  90. client.exhaustResponse(postMethod.getResponseBodyAsStream());
  91. result = new RemoteOperationResult(false, status, postMethod.getResponseHeaders());
  92. }
  93. }
  94. } catch (Exception e) {
  95. result = new RemoteOperationResult(e);
  96. } finally {
  97. if (postMethod != null)
  98. postMethod.releaseConnection(); // let the connection available for other methods
  99. if (result.isSuccess()) {
  100. Log_OC.i(TAG, "OAuth2 TOKEN REQUEST with auth code " + mOAuth2ParsedAuthorizationResponse.get("code") + " to " + client.getWebdavUri() + ": " + result.getLogMessage());
  101. } else if (result.getException() != null) {
  102. Log_OC.e(TAG, "OAuth2 TOKEN REQUEST with auth code " + mOAuth2ParsedAuthorizationResponse.get("code") + " to " + client.getWebdavUri() + ": " + result.getLogMessage(), result.getException());
  103. } else if (result.getCode() == ResultCode.OAUTH2_ERROR) {
  104. Log_OC.e(TAG, "OAuth2 TOKEN REQUEST with auth code " + mOAuth2ParsedAuthorizationResponse.get("code") + " to " + client.getWebdavUri() + ": " + ((mResultTokenMap != null) ? mResultTokenMap.get(OAuth2Constants.KEY_ERROR) : "NULL"));
  105. } else {
  106. Log_OC.e(TAG, "OAuth2 TOKEN REQUEST with auth code " + mOAuth2ParsedAuthorizationResponse.get("code") + " to " + client.getWebdavUri() + ": " + result.getLogMessage());
  107. }
  108. }
  109. return result;
  110. }
  111. private void parseAuthorizationResponse() {
  112. String[] pairs = mOAuth2AuthorizationResponse.split("&");
  113. int i = 0;
  114. String key = "";
  115. String value = "";
  116. while (pairs.length > i) {
  117. int j = 0;
  118. String[] part = pairs[i].split("=");
  119. while (part.length > j) {
  120. String p = part[j];
  121. if (j == 0) {
  122. key = p;
  123. } else if (j == 1) {
  124. value = p;
  125. mOAuth2ParsedAuthorizationResponse.put(key, value);
  126. }
  127. Log_OC.v(TAG, "[" + i + "," + j + "] = " + p);
  128. j++;
  129. }
  130. i++;
  131. }
  132. }
  133. private void parseAccessTokenResult (JSONObject tokenJson) throws JSONException {
  134. mResultTokenMap = new HashMap<String, String>();
  135. if (tokenJson.has(OAuth2Constants.KEY_ACCESS_TOKEN)) {
  136. mResultTokenMap.put(OAuth2Constants.KEY_ACCESS_TOKEN, tokenJson.getString(OAuth2Constants.KEY_ACCESS_TOKEN));
  137. }
  138. if (tokenJson.has(OAuth2Constants.KEY_TOKEN_TYPE)) {
  139. mResultTokenMap.put(OAuth2Constants.KEY_TOKEN_TYPE, tokenJson.getString(OAuth2Constants.KEY_TOKEN_TYPE));
  140. }
  141. if (tokenJson.has(OAuth2Constants.KEY_EXPIRES_IN)) {
  142. mResultTokenMap.put(OAuth2Constants.KEY_EXPIRES_IN, tokenJson.getString(OAuth2Constants.KEY_EXPIRES_IN));
  143. }
  144. if (tokenJson.has(OAuth2Constants.KEY_REFRESH_TOKEN)) {
  145. mResultTokenMap.put(OAuth2Constants.KEY_REFRESH_TOKEN, tokenJson.getString(OAuth2Constants.KEY_REFRESH_TOKEN));
  146. }
  147. if (tokenJson.has(OAuth2Constants.KEY_SCOPE)) {
  148. mResultTokenMap.put(OAuth2Constants.KEY_SCOPE, tokenJson.getString(OAuth2Constants.KEY_SCOPE));
  149. }
  150. if (tokenJson.has(OAuth2Constants.KEY_ERROR)) {
  151. mResultTokenMap.put(OAuth2Constants.KEY_ERROR, tokenJson.getString(OAuth2Constants.KEY_ERROR));
  152. }
  153. if (tokenJson.has(OAuth2Constants.KEY_ERROR_DESCRIPTION)) {
  154. mResultTokenMap.put(OAuth2Constants.KEY_ERROR_DESCRIPTION, tokenJson.getString(OAuth2Constants.KEY_ERROR_DESCRIPTION));
  155. }
  156. if (tokenJson.has(OAuth2Constants.KEY_ERROR_URI)) {
  157. mResultTokenMap.put(OAuth2Constants.KEY_ERROR_URI, tokenJson.getString(OAuth2Constants.KEY_ERROR_URI));
  158. }
  159. }
  160. }