001/*
002 * Licensed to the Apache Software Foundation (ASF) under one
003 * or more contributor license agreements.  See the NOTICE file
004 * distributed with this work for additional information
005 * regarding copyright ownership.  The ASF licenses this file
006 * to you under the Apache License, Version 2.0 (the
007 * "License"); you may not use this file except in compliance
008 * with the License.  You may obtain a copy of the License at
009 *
010 *     http://www.apache.org/licenses/LICENSE-2.0
011 *
012 * Unless required by applicable law or agreed to in writing, software
013 * distributed under the License is distributed on an "AS IS" BASIS,
014 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
015 * See the License for the specific language governing permissions and
016 * limitations under the License.
017 */
018package org.apache.hadoop.hbase.http;
019
020import java.io.IOException;
021import javax.servlet.Filter;
022import javax.servlet.FilterChain;
023import javax.servlet.FilterConfig;
024import javax.servlet.ServletException;
025import javax.servlet.ServletRequest;
026import javax.servlet.ServletResponse;
027import javax.servlet.http.HttpServletRequest;
028import javax.servlet.http.HttpServletResponse;
029import org.apache.hadoop.conf.Configuration;
030import org.apache.hadoop.security.authorize.AccessControlList;
031import org.apache.yetus.audience.InterfaceAudience;
032
033@InterfaceAudience.Private
034public class AdminAuthorizedFilter implements Filter {
035
036  private Configuration conf;
037  private AccessControlList adminsAcl;
038
039  @Override
040  public void init(FilterConfig filterConfig) throws ServletException {
041    adminsAcl =
042      (AccessControlList) filterConfig.getServletContext().getAttribute(HttpServer.ADMINS_ACL);
043    conf = (Configuration) filterConfig.getServletContext()
044      .getAttribute(HttpServer.CONF_CONTEXT_ATTRIBUTE);
045  }
046
047  @Override
048  public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
049    throws IOException, ServletException {
050    if (!(request instanceof HttpServletRequest) || !(response instanceof HttpServletResponse)) {
051      throw new UnsupportedOperationException("Only accepts HTTP");
052    }
053    HttpServletRequest httpReq = (HttpServletRequest) request;
054    HttpServletResponse httpResp = (HttpServletResponse) response;
055
056    if (!HttpServer.hasAdministratorAccess(conf, adminsAcl, httpReq, httpResp)) {
057      return;
058    }
059
060    chain.doFilter(request, response);
061  }
062
063  @Override
064  public void destroy() {
065  }
066}