Class DigestScheme
java.lang.Object
org.apache.hc.client5.http.impl.auth.DigestScheme
- All Implemented Interfaces:
Serializable,AuthScheme
Digest authentication scheme.
Both MD5 (default) and MD5-sess are supported.
Currently only qop=auth or no qop is supported. qop=auth-int
is unsupported. If auth and auth-int are provided, auth is
used.
Since the digest username is included as clear text in the generated Authentication header, the charset of the username must be compatible with the HTTP element charset used by the connection.
- Since:
- 4.0
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionprivate static enumRepresent the possible values of quality of protection. -
Field Summary
FieldsModifier and TypeFieldDescriptionprivate byte[]private byte[]private ByteArrayBuilderprivate Stringprivate booleanprivate UsernamePasswordCredentialsprivate Charsetprivate static final char[]Hexa values used when creating 32 character long digest in HTTP DigestScheme in case of authentication.private Stringprivate static final org.slf4j.Loggerprivate longprivate static final long -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescription(package private) static byte[]Creates a random cnonce value based on the current time.private StringcreateDigestResponse(org.apache.hc.core5.http.HttpRequest request) private static MessageDigestcreateMessageDigest(String digAlg) (package private) static StringformatHex(byte[] binaryData) Encodes the 128 bit (16 bytes) MD5 digest into a 32 characters long string.generateAuthResponse(org.apache.hc.core5.http.HttpHost host, org.apache.hc.core5.http.HttpRequest request, org.apache.hc.core5.http.protocol.HttpContext context) Generates an authorization response based on the current state.(package private) StringgetA1()(package private) StringgetA2()getName()Returns textual designation of the given authentication scheme.getNonce()longReturnsPrincipalwhose credentials are used to generate an authentication response.getRealm()Returns authentication realm.voidinitPreemptive(Credentials credentials, String cnonce, String realm) booleanAuthentication process may involve a series of challenge-response exchanges.booleanDetermines if the authentication scheme is expected to provide an authorization response on a per connection basis instead of the standard per request basisbooleanisResponseReady(org.apache.hc.core5.http.HttpHost host, CredentialsProvider credentialsProvider, org.apache.hc.core5.http.protocol.HttpContext context) Determines whether or not an authorization response can be generated based on the actual authentication state.voidprocessChallenge(AuthChallenge authChallenge, org.apache.hc.core5.http.protocol.HttpContext context) Processes the given auth challenge.private voidtoString()private void
-
Field Details
-
serialVersionUID
private static final long serialVersionUID- See Also:
-
LOG
private static final org.slf4j.Logger LOG -
HEXADECIMAL
private static final char[] HEXADECIMALHexa values used when creating 32 character long digest in HTTP DigestScheme in case of authentication.- See Also:
-
defaultCharset
-
paramMap
-
complete
private boolean complete -
buffer
-
lastNonce
-
nounceCount
private long nounceCount -
cnonce
-
a1
private byte[] a1 -
a2
private byte[] a2 -
credentials
-
-
Constructor Details
-
DigestScheme
public DigestScheme() -
DigestScheme
-
-
Method Details
-
initPreemptive
-
getName
Description copied from interface:AuthSchemeReturns textual designation of the given authentication scheme.- Specified by:
getNamein interfaceAuthScheme- Returns:
- the name of the given authentication scheme
-
isConnectionBased
public boolean isConnectionBased()Description copied from interface:AuthSchemeDetermines if the authentication scheme is expected to provide an authorization response on a per connection basis instead of the standard per request basis- Specified by:
isConnectionBasedin interfaceAuthScheme- Returns:
trueif the scheme is connection based,falseif the scheme is request based.
-
getRealm
Description copied from interface:AuthSchemeReturns authentication realm. If the concept of an authentication realm is not applicable to the given authentication scheme, returnsnull.- Specified by:
getRealmin interfaceAuthScheme- Returns:
- the authentication realm
-
processChallenge
public void processChallenge(AuthChallenge authChallenge, org.apache.hc.core5.http.protocol.HttpContext context) throws MalformedChallengeException Description copied from interface:AuthSchemeProcesses the given auth challenge. Some authentication schemes may involve multiple challenge-response exchanges. Such schemes must be able to maintain internal state when dealing with sequential challenges- Specified by:
processChallengein interfaceAuthScheme- Parameters:
authChallenge- the auth challengecontext- HTTP context- Throws:
MalformedChallengeException- in case the auth challenge is incomplete, malformed or otherwise invalid.
-
isChallengeComplete
public boolean isChallengeComplete()Description copied from interface:AuthSchemeAuthentication process may involve a series of challenge-response exchanges. This method tests if the authorization process has been fully completed (either successfully or unsuccessfully), that is, all the required authorization challenges have been processed in their entirety.- Specified by:
isChallengeCompletein interfaceAuthScheme- Returns:
trueif the authentication process has been completed,falseotherwise.
-
isResponseReady
public boolean isResponseReady(org.apache.hc.core5.http.HttpHost host, CredentialsProvider credentialsProvider, org.apache.hc.core5.http.protocol.HttpContext context) throws AuthenticationException Description copied from interface:AuthSchemeDetermines whether or not an authorization response can be generated based on the actual authentication state. Generally the outcome of this method will depend upon availability of user credentials necessary to produce an authorization response.- Specified by:
isResponseReadyin interfaceAuthScheme- Parameters:
credentialsProvider- The credentials to be used for authenticationcontext- HTTP context- Returns:
trueif an authorization response can be generated and the authentication handshake can proceed,falseotherwise.- Throws:
AuthenticationException- if authorization string cannot be generated due to an authentication failure
-
getPrincipal
Description copied from interface:AuthSchemeReturnsPrincipalwhose credentials are used to generate an authentication response. Connection based schemes are required to return a userPrincipalif authorization applies to for the entire life span of connection.- Specified by:
getPrincipalin interfaceAuthScheme- Returns:
- user principal
- See Also:
-
generateAuthResponse
public String generateAuthResponse(org.apache.hc.core5.http.HttpHost host, org.apache.hc.core5.http.HttpRequest request, org.apache.hc.core5.http.protocol.HttpContext context) throws AuthenticationException Description copied from interface:AuthSchemeGenerates an authorization response based on the current state. Some authentication schemes may need to load user credentials required to generate an authorization response from aCredentialsProviderprior to this method call.- Specified by:
generateAuthResponsein interfaceAuthScheme- Parameters:
request- The request being authenticatedcontext- HTTP context- Returns:
- authorization header
- Throws:
AuthenticationException- if authorization string cannot be generated due to an authentication failure- See Also:
-
createMessageDigest
private static MessageDigest createMessageDigest(String digAlg) throws UnsupportedDigestAlgorithmException -
createDigestResponse
private String createDigestResponse(org.apache.hc.core5.http.HttpRequest request) throws AuthenticationException - Throws:
AuthenticationException
-
getNonce
-
getNounceCount
@Internal public long getNounceCount() -
getCnonce
-
getA1
String getA1() -
getA2
String getA2() -
formatHex
Encodes the 128 bit (16 bytes) MD5 digest into a 32 characters long string.- Parameters:
binaryData- array containing the digest- Returns:
- encoded MD5, or
nullif encoding failed
-
createCnonce
static byte[] createCnonce()Creates a random cnonce value based on the current time.- Returns:
- The cnonce value as String.
-
writeObject
- Throws:
IOException
-
readObject
- Throws:
IOExceptionClassNotFoundException
-
toString
-