Ether Framework
Unified API docs for Ether modules
Loading...
Searching...
No Matches
JettyCorsHandler.java
Go to the documentation of this file.
1package dev.rafex.ether.http.jetty12;
2
3/*-
4 * #%L
5 * ether-http-jetty12
6 * %%
7 * Copyright (C) 2025 - 2026 Raúl Eduardo González Argote
8 * %%
9 * Permission is hereby granted, free of charge, to any person obtaining a copy
10 * of this software and associated documentation files (the "Software"), to deal
11 * in the Software without restriction, including without limitation the rights
12 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
13 * copies of the Software, and to permit persons to whom the Software is
14 * furnished to do so, subject to the following conditions:
15 *
16 * The above copyright notice and this permission notice shall be included in
17 * all copies or substantial portions of the Software.
18 *
19 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
20 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
21 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
22 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
23 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
24 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
25 * THE SOFTWARE.
26 * #L%
27 */
28
29import java.util.Map;
30
31import org.eclipse.jetty.server.Handler;
32import org.eclipse.jetty.server.Request;
33import org.eclipse.jetty.server.Response;
34import org.eclipse.jetty.util.Callback;
35
36import dev.rafex.ether.http.jetty12.response.JettyApiResponses;
37import dev.rafex.ether.http.security.cors.CorsPolicy;
38
39final class JettyCorsHandler extends Handler.Wrapper {
40
41 private final CorsPolicy policy;
42 private final JettyApiResponses responses;
43
44 JettyCorsHandler(final Handler next, final CorsPolicy policy, final JettyApiResponses responses) {
45 super(next);
46 this.policy = policy;
47 this.responses = responses;
48 }
49
50 @Override
51 public boolean handle(final Request request, final Response response, final Callback callback) throws Exception {
52 final var origin = request.getHeaders().get("Origin");
53 if (isPreflight(request)) {
54 if (origin == null || !policy.isOriginAllowed(origin)) {
55 responses.text(response, callback, 403, "forbidden");
56 return true;
57 }
58 applyHeaders(response, policy.responseHeaders(origin));
59 responses.noContent(response, callback, 204);
60 return true;
61 }
62
63 final boolean handled = super.handle(request, response, callback);
64 if (origin != null && policy.isOriginAllowed(origin)) {
65 applyHeaders(response, policy.responseHeaders(origin));
66 }
67 return handled;
68 }
69
70 private static boolean isPreflight(final Request request) {
71 return "OPTIONS".equalsIgnoreCase(request.getMethod())
72 && request.getHeaders().get("Access-Control-Request-Method") != null;
73 }
74
75 private static void applyHeaders(final Response response, final Map<String, String> headers) {
76 for (final var entry : headers.entrySet()) {
77 response.getHeaders().put(entry.getKey(), entry.getValue());
78 }
79 }
80}
record CorsPolicy(boolean allowAnyOrigin, List< String > allowedOrigins, List< String > allowedMethods, List< String > allowedHeaders, List< String > exposedHeaders, boolean allowCredentials, int maxAgeSeconds, boolean varyOrigin)
Política de seguridad CORS para controlar el acceso entre orígenes.