Ether Framework
Unified API docs for Ether modules
Loading...
Searching...
No Matches
JettyIpPolicyHandler.java
Go to the documentation of this file.
1package dev.rafex.ether.http.jetty12;
2
3/*-
4 * #%L
5 * ether-http-jetty12
6 * %%
7 * Copyright (C) 2025 - 2026 Raúl Eduardo González Argote
8 * %%
9 * Permission is hereby granted, free of charge, to any person obtaining a copy
10 * of this software and associated documentation files (the "Software"), to deal
11 * in the Software without restriction, including without limitation the rights
12 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
13 * copies of the Software, and to permit persons to whom the Software is
14 * furnished to do so, subject to the following conditions:
15 *
16 * The above copyright notice and this permission notice shall be included in
17 * all copies or substantial portions of the Software.
18 *
19 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
20 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
21 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
22 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
23 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
24 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
25 * THE SOFTWARE.
26 * #L%
27 */
28
29import org.eclipse.jetty.server.Handler;
30import org.eclipse.jetty.server.Request;
31import org.eclipse.jetty.server.Response;
32import org.eclipse.jetty.util.Callback;
33
34import dev.rafex.ether.http.jetty12.response.JettyApiErrorResponses;
35import dev.rafex.ether.http.security.ip.IpPolicy;
36import dev.rafex.ether.http.security.proxy.TrustedProxyPolicy;
37
38final class JettyIpPolicyHandler extends Handler.Wrapper {
39
40 private final IpPolicy ipPolicy;
41 private final TrustedProxyPolicy trustedProxyPolicy;
42 private final JettyApiErrorResponses errorResponses;
43
44 JettyIpPolicyHandler(final Handler next, final IpPolicy ipPolicy, final TrustedProxyPolicy trustedProxyPolicy,
45 final JettyApiErrorResponses errorResponses) {
46 super(next);
47 this.ipPolicy = ipPolicy;
48 this.trustedProxyPolicy = trustedProxyPolicy;
49 this.errorResponses = errorResponses;
50 }
51
52 @Override
53 public boolean handle(final Request request, final Response response, final Callback callback) throws Exception {
54 final var clientIp = JettyRequestIpResolver.resolve(request, trustedProxyPolicy);
55 if (!ipPolicy.isAllowed(clientIp)) {
56 errorResponses.forbidden(response, callback, "ip_not_allowed");
57 return true;
58 }
59 return super.handle(request, response, callback);
60 }
61}
record IpPolicy(List< String > allowList, List< String > denyList)
Política de control de acceso basada en direcciones IP.
Definition IpPolicy.java:38
record TrustedProxyPolicy(List< String > trustedSources, boolean trustForwardedHeader, boolean forwardedOnly, boolean preferRightMostForwardedFor)
Política para configurar proxy de confianza en servidores.