View Javadoc
1   /**
2    * This file Copyright (c) 2003-2018 Magnolia International
3    * Ltd.  (http://www.magnolia-cms.com). All rights reserved.
4    *
5    *
6    * This file is dual-licensed under both the Magnolia
7    * Network Agreement and the GNU General Public License.
8    * You may elect to use one or the other of these licenses.
9    *
10   * This file is distributed in the hope that it will be
11   * useful, but AS-IS and WITHOUT ANY WARRANTY; without even the
12   * implied warranty of MERCHANTABILITY or FITNESS FOR A
13   * PARTICULAR PURPOSE, TITLE, or NONINFRINGEMENT.
14   * Redistribution, except as permitted by whichever of the GPL
15   * or MNA you select, is prohibited.
16   *
17   * 1. For the GPL license (GPL), you can redistribute and/or
18   * modify this file under the terms of the GNU General
19   * Public License, Version 3, as published by the Free Software
20   * Foundation.  You should have received a copy of the GNU
21   * General Public License, Version 3 along with this program;
22   * if not, write to the Free Software Foundation, Inc., 51
23   * Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
24   *
25   * 2. For the Magnolia Network Agreement (MNA), this file
26   * and the accompanying materials are made available under the
27   * terms of the MNA which accompanies this distribution, and
28   * is available at http://www.magnolia-cms.com/mna.html
29   *
30   * Any modifications to this file must keep this entire header
31   * intact.
32   *
33   */
34  package info.magnolia.cms.security;
35  
36  import info.magnolia.context.MgnlContext;
37  
38  import java.util.Date;
39  
40  import javax.servlet.http.HttpServletRequest;
41  import javax.servlet.http.HttpSession;
42  
43  import org.slf4j.Logger;
44  import org.slf4j.LoggerFactory;
45  
46  
47  /**
48   * Used to lock a session or the system. Currently checked in the {@link URISecurityFilter}. Should
49   * only be used with care.
50   *
51   * @deprecated since 5.3.6 - no longer used, will be removed without replacement.
52   */
53  @Deprecated
54  public final class Lock {
55  
56      private static Logger log = LoggerFactory.getLogger(Lock.class);
57  
58      /**
59       * Session lock attribute.
60       */
61      private static final String SESSION_LOCK = "mgnlSessionLock";
62  
63      /**
64       * System wide lock.
65       */
66      private static boolean isSystemLocked;
67  
68      /**
69       * System wide lock creation time.
70       */
71      private static Date lockSetDate;
72  
73      /**
74       * Utility class, don't instantiate.
75       */
76      private Lock() {
77          // unused
78      }
79  
80      /**
81       * Set session based lock.
82       */
83      public static void setSessionLock(HttpServletRequest request) {
84          log.info("Session lock enabled for user ( {} ) on {}", MgnlContext.getUser().getName(), new Date());
85          // @todo IMPORTANT remove use of http session
86          HttpSession httpsession = request.getSession(true);
87          httpsession.setAttribute(SESSION_LOCK, (new Date()).toString());
88      }
89  
90      /**
91       * Returns true if this session is locked.
92       *
93       * @return a boolean
94       */
95      public static boolean isSessionLocked(HttpServletRequest request) {
96          // @todo IMPORTANT remove use of http session
97          if (request.getSession(true).getAttribute(Lock.SESSION_LOCK) != null) {
98              return true;
99          }
100         return false;
101     }
102 
103     /**
104      * Reset session lock.
105      */
106     public static void resetSessionLock(HttpServletRequest request) {
107         if (!Lock.isSessionLocked(request)) {
108             log.debug("No Lock found to reset");
109         } else {
110             log.debug("Resetting session lock");
111             Lock.isSystemLocked = false;
112         }
113         // @todo IMPORTANT remove use of http session
114         HttpSession httpsession = request.getSession(true);
115         httpsession.removeAttribute(Lock.SESSION_LOCK);
116     }
117 
118     /**
119      * Set system wide lock.
120      */
121     public static void setSystemLock() {
122         if (Lock.isSystemLocked()) {
123             log.debug("System lock exist, created on {}", Lock.lockSetDate);
124         } else {
125             Lock.isSystemLocked = true;
126             Lock.lockSetDate = new Date();
127             log.debug("New System lock created on {}", Lock.lockSetDate);
128         }
129     }
130 
131     /**
132      * Reset system wide lock.
133      */
134     public static void resetSystemLock() {
135         if (!Lock.isSystemLocked()) {
136             log.debug("No Lock found to reset");
137         } else {
138             log.debug("Resetting system lock created on {}", Lock.lockSetDate);
139             Lock.isSystemLocked = false;
140         }
141     }
142 
143     /**
144      * Return true if system is locked.
145      *
146      * @return a boolean
147      */
148     public static boolean isSystemLocked() {
149         return Lock.isSystemLocked;
150     }
151 }