001/**
002 * Licensed to the Apache Software Foundation (ASF) under one
003 * or more contributor license agreements.  See the NOTICE file
004 * distributed with this work for additional information
005 * regarding copyright ownership.  The ASF licenses this file
006 * to you under the Apache License, Version 2.0 (the
007 * "License"); you may not use this file except in compliance
008 * with the License.  You may obtain a copy of the License at
009 *
010 *     http://www.apache.org/licenses/LICENSE-2.0
011 *
012 * Unless required by applicable law or agreed to in writing, software
013 * distributed under the License is distributed on an "AS IS" BASIS,
014 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
015 * See the License for the specific language governing permissions and
016 * limitations under the License.
017 */
018package org.apache.hadoop.hbase.http;
019
020import java.io.IOException;
021import java.util.HashMap;
022import java.util.Map;
023
024import javax.servlet.Filter;
025import javax.servlet.FilterChain;
026import javax.servlet.FilterConfig;
027import javax.servlet.ServletException;
028import javax.servlet.ServletRequest;
029import javax.servlet.ServletResponse;
030import javax.servlet.http.HttpServletResponse;
031
032import org.apache.hadoop.conf.Configuration;
033import org.apache.hadoop.hbase.HBaseInterfaceAudience;
034import org.apache.yetus.audience.InterfaceAudience;
035
036@InterfaceAudience.LimitedPrivate(HBaseInterfaceAudience.CONFIG)
037public class ClickjackingPreventionFilter implements Filter {
038  private FilterConfig filterConfig;
039  private static final String DEFAULT_XFRAMEOPTIONS = "DENY";
040
041  @Override
042  public void init(FilterConfig filterConfig) throws ServletException {
043    this.filterConfig = filterConfig;
044  }
045
046  @Override
047  public void doFilter(ServletRequest req, ServletResponse res, FilterChain chain)
048        throws IOException, ServletException {
049    HttpServletResponse httpRes = (HttpServletResponse) res;
050    httpRes.addHeader("X-Frame-Options", filterConfig.getInitParameter("xframeoptions"));
051    chain.doFilter(req, res);
052  }
053
054  @Override
055  public void destroy() {
056  }
057
058  public static Map<String, String> getDefaultParameters(Configuration conf) {
059    Map<String, String> params = new HashMap<>();
060    params.put("xframeoptions", conf.get("hbase.http.filter.xframeoptions.mode",
061        DEFAULT_XFRAMEOPTIONS));
062    return params;
063  }
064}