/* * #%L * GarethHealy :: JBoss Fuse Examples :: WS Playground :: WS Security HTTPS CXF * %% * Copyright (C) 2013 - 2017 Gareth Healy * %% * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. * #L% */ package com.garethahealy.wssecurity.https.cxf.impl; import java.util.Collections; import java.util.HashMap; import java.util.Map; import javax.servlet.http.HttpServletRequest; import org.apache.cxf.binding.soap.SoapMessage; import org.apache.cxf.binding.soap.interceptor.AbstractSoapInterceptor; import org.apache.cxf.interceptor.Fault; import org.apache.cxf.phase.Phase; import org.apache.cxf.transport.http.AbstractHTTPDestination; public class HTTPMethodInterceptor extends AbstractSoapInterceptor { private static final Map<String, Boolean> HTTP_METHODS; static { Map<String, Boolean> httpMap = new HashMap<String, Boolean>(); httpMap.put("PUT", false); httpMap.put("GET", true); HTTP_METHODS = Collections.unmodifiableMap(httpMap); } public HTTPMethodInterceptor() { super(Phase.RECEIVE); } @Override public void handleMessage(SoapMessage message) throws Fault { HttpServletRequest request = (HttpServletRequest)message.get(AbstractHTTPDestination.HTTP_REQUEST); if (request != null) { if (!HTTP_METHODS.get(request.getMethod())) { throw new Fault(new IllegalArgumentException("Invalid HTTPMethod of " + request.getMethod())); } } } }