OAuth2GetAccessToken.java 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197
  1. /*
  2. * ownCloud Android client application
  3. *
  4. * Copyright (C) 2015 ownCloud Inc.
  5. *
  6. * This program is free software: you can redistribute it and/or modify
  7. * it under the terms of the GNU General Public License version 2,
  8. * as published by the Free Software Foundation.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. */
  19. package com.owncloud.android.operations;
  20. import com.owncloud.android.authentication.OAuth2Constants;
  21. import com.owncloud.android.lib.common.OwnCloudClient;
  22. import com.owncloud.android.lib.common.operations.RemoteOperation;
  23. import com.owncloud.android.lib.common.operations.RemoteOperationResult;
  24. import com.owncloud.android.lib.common.operations.RemoteOperationResult.ResultCode;
  25. import com.owncloud.android.lib.common.utils.Log_OC;
  26. import org.apache.commons.httpclient.NameValuePair;
  27. import org.apache.commons.httpclient.methods.PostMethod;
  28. import org.json.JSONException;
  29. import org.json.JSONObject;
  30. import java.util.ArrayList;
  31. import java.util.HashMap;
  32. import java.util.Map;
  33. public class OAuth2GetAccessToken extends RemoteOperation {
  34. private static final String TAG = OAuth2GetAccessToken.class.getSimpleName();
  35. private static final int KEY_INDEX = 0;
  36. private static final int VALUE_INDEX = 1;
  37. private String mClientId;
  38. private String mRedirectUri;
  39. private String mGrantType;
  40. private String mOAuth2AuthorizationResponse;
  41. private Map<String, String> mOAuth2ParsedAuthorizationResponse;
  42. private Map<String, String> mResultTokenMap;
  43. public OAuth2GetAccessToken(String clientId, String redirectUri, String grantType, String oAuth2AuthorizationResponse) {
  44. mClientId = clientId;
  45. mRedirectUri = redirectUri;
  46. mGrantType = grantType;
  47. mOAuth2AuthorizationResponse = oAuth2AuthorizationResponse;
  48. mOAuth2ParsedAuthorizationResponse = new HashMap<>();
  49. mResultTokenMap = null;
  50. }
  51. /*
  52. public Map<String, String> getResultTokenMap() {
  53. return mResultTokenMap;
  54. }
  55. */
  56. @Override
  57. @SuppressWarnings("PMD.AvoidDuplicateLiterals")
  58. protected RemoteOperationResult run(OwnCloudClient client) {
  59. RemoteOperationResult result = null;
  60. PostMethod postMethod = null;
  61. try {
  62. parseAuthorizationResponse();
  63. if (mOAuth2ParsedAuthorizationResponse.keySet().contains(OAuth2Constants.KEY_ERROR)) {
  64. if (OAuth2Constants.VALUE_ERROR_ACCESS_DENIED.equals(mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_ERROR))) {
  65. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR_ACCESS_DENIED);
  66. } else {
  67. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR);
  68. }
  69. }
  70. if (result == null) {
  71. NameValuePair[] nameValuePairs = new NameValuePair[4];
  72. nameValuePairs[0] = new NameValuePair(OAuth2Constants.KEY_GRANT_TYPE, mGrantType);
  73. nameValuePairs[1] = new NameValuePair(OAuth2Constants.KEY_CODE, mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_CODE));
  74. nameValuePairs[2] = new NameValuePair(OAuth2Constants.KEY_REDIRECT_URI, mRedirectUri);
  75. nameValuePairs[3] = new NameValuePair(OAuth2Constants.KEY_CLIENT_ID, mClientId);
  76. //nameValuePairs[4] = new NameValuePair(OAuth2Constants.KEY_SCOPE, mOAuth2ParsedAuthorizationResponse.get(OAuth2Constants.KEY_SCOPE));
  77. postMethod = new PostMethod(client.getWebdavUri().toString());
  78. postMethod.setRequestBody(nameValuePairs);
  79. client.executeMethod(postMethod);
  80. String response = postMethod.getResponseBodyAsString();
  81. if (response != null && response.length() > 0) {
  82. JSONObject tokenJson = new JSONObject(response);
  83. parseAccessTokenResult(tokenJson);
  84. if (mResultTokenMap.get(OAuth2Constants.KEY_ERROR) != null || mResultTokenMap.get(OAuth2Constants.KEY_ACCESS_TOKEN) == null) {
  85. result = new RemoteOperationResult(ResultCode.OAUTH2_ERROR);
  86. } else {
  87. result = new RemoteOperationResult(true, postMethod);
  88. ArrayList<Object> data = new ArrayList<>();
  89. data.add(mResultTokenMap);
  90. result.setData(data);
  91. }
  92. } else {
  93. result = new RemoteOperationResult(false, postMethod);
  94. client.exhaustResponse(postMethod.getResponseBodyAsStream());
  95. }
  96. }
  97. } catch (Exception e) {
  98. result = new RemoteOperationResult(e);
  99. } finally {
  100. if (postMethod != null) {
  101. postMethod.releaseConnection(); // let the connection available for other methods
  102. }
  103. final String code = "code";
  104. final String oauth_token_request = "OAuth2 TOKEN REQUEST with auth code ";
  105. if (result != null) {
  106. if (result.isSuccess()) {
  107. Log_OC.i(TAG, oauth_token_request + mOAuth2ParsedAuthorizationResponse.get(code) + " to " + client.getWebdavUri() + ": " + result.getLogMessage());
  108. } else if (result.getException() != null) {
  109. Log_OC.e(TAG, oauth_token_request + mOAuth2ParsedAuthorizationResponse.get(code) + " to " + client.getWebdavUri() + ": " + result.getLogMessage(), result.getException());
  110. } else if (result.getCode() == ResultCode.OAUTH2_ERROR) {
  111. Log_OC.e(TAG, oauth_token_request + mOAuth2ParsedAuthorizationResponse.get(code) + " to " + client.getWebdavUri() + ": " + ((mResultTokenMap != null) ? mResultTokenMap.get(OAuth2Constants.KEY_ERROR) : "NULL"));
  112. } else {
  113. Log_OC.e(TAG, oauth_token_request + mOAuth2ParsedAuthorizationResponse.get(code) + " to " + client.getWebdavUri() + ": " + result.getLogMessage());
  114. }
  115. }
  116. }
  117. return result;
  118. }
  119. private void parseAuthorizationResponse() {
  120. String[] pairs = mOAuth2AuthorizationResponse.split("&");
  121. int i = 0;
  122. String key = "";
  123. String value;
  124. while (pairs.length > i) {
  125. int j = 0;
  126. String[] part = pairs[i].split("=");
  127. while (part.length > j) {
  128. String p = part[j];
  129. if (j == KEY_INDEX) {
  130. key = p;
  131. } else if (j == VALUE_INDEX) {
  132. value = p;
  133. mOAuth2ParsedAuthorizationResponse.put(key, value);
  134. }
  135. Log_OC.v(TAG, "[" + i + "," + j + "] = " + p);
  136. j++;
  137. }
  138. i++;
  139. }
  140. }
  141. private void parseAccessTokenResult (JSONObject tokenJson) throws JSONException {
  142. mResultTokenMap = new HashMap<>();
  143. if (tokenJson.has(OAuth2Constants.KEY_ACCESS_TOKEN)) {
  144. mResultTokenMap.put(OAuth2Constants.KEY_ACCESS_TOKEN, tokenJson.getString(OAuth2Constants.KEY_ACCESS_TOKEN));
  145. }
  146. if (tokenJson.has(OAuth2Constants.KEY_TOKEN_TYPE)) {
  147. mResultTokenMap.put(OAuth2Constants.KEY_TOKEN_TYPE, tokenJson.getString(OAuth2Constants.KEY_TOKEN_TYPE));
  148. }
  149. if (tokenJson.has(OAuth2Constants.KEY_EXPIRES_IN)) {
  150. mResultTokenMap.put(OAuth2Constants.KEY_EXPIRES_IN, tokenJson.getString(OAuth2Constants.KEY_EXPIRES_IN));
  151. }
  152. if (tokenJson.has(OAuth2Constants.KEY_REFRESH_TOKEN)) {
  153. mResultTokenMap.put(OAuth2Constants.KEY_REFRESH_TOKEN, tokenJson.getString(OAuth2Constants.KEY_REFRESH_TOKEN));
  154. }
  155. if (tokenJson.has(OAuth2Constants.KEY_SCOPE)) {
  156. mResultTokenMap.put(OAuth2Constants.KEY_SCOPE, tokenJson.getString(OAuth2Constants.KEY_SCOPE));
  157. }
  158. if (tokenJson.has(OAuth2Constants.KEY_ERROR)) {
  159. mResultTokenMap.put(OAuth2Constants.KEY_ERROR, tokenJson.getString(OAuth2Constants.KEY_ERROR));
  160. }
  161. if (tokenJson.has(OAuth2Constants.KEY_ERROR_DESCRIPTION)) {
  162. mResultTokenMap.put(OAuth2Constants.KEY_ERROR_DESCRIPTION, tokenJson.getString(OAuth2Constants.KEY_ERROR_DESCRIPTION));
  163. }
  164. if (tokenJson.has(OAuth2Constants.KEY_ERROR_URI)) {
  165. mResultTokenMap.put(OAuth2Constants.KEY_ERROR_URI, tokenJson.getString(OAuth2Constants.KEY_ERROR_URI));
  166. }
  167. }
  168. }