[ Web Proxy ]
URL:
Viewing: https://raw.githubusercontent.com/OWASP/SecurityShepherd/dev/src/main/java/utils/Validate.java [Back]  [Original]

package utils; import java.math.BigInteger; import javax.mail.internet.AddressException; import javax.mail.internet.InternetAddress; import javax.servlet.http.Cookie; import javax.servlet.http.HttpSession; import org.apache.logging.log4j.LogManager; import org.apache.logging.log4j.Logger; /** * Class is used to validate various inputs
*
* This file is part of the Security Shepherd Project. * *

The Security Shepherd project is free software: you can redistribute it and/or modify it under * the terms of the GNU General Public License as published by the Free Software Foundation, either * version 3 of the License, or (at your option) any later version.
* *

The Security Shepherd project is distributed in the hope that it will be useful, but WITHOUT * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR * PURPOSE. See the GNU General Public License for more details.
* *

You should have received a copy of the GNU General Public License along with the Security * Shepherd project. If not, see . * * @author Mark Denihan */ public class Validate { private static final Logger log = LogManager.getLogger(Validate.class); /** * Finds JSession token from user's cookies[], validates and returns. * * @param userCookies Cookies from users browser * @return JSession Id */ public static Cookie getSessionId(Cookie[] userCookies) { int i = 0; Cookie theSessionId = null; for (i = 0; i < userCookies.length; i++) { if (userCookies[i].getName().compareTo("JSESSIONID") == 0) { theSessionId = userCookies[i]; break; // End Loop, because we found the theSessionId } } return theSessionId; } /** * Finds CSRF token from user's cookies[], validates. * * @param userCookies All of the user's cookies from their browser * @return csrfCookie */ public static Cookie getToken(Cookie[] userCookies) { int i = 0; Cookie theToken = null; for (i = 0; i < userCookies.length; i++) { if (userCookies[i].getName().compareTo("token") == 0) { theToken = userCookies[i]; break; // End Loop, because we found the token } } if (theToken != null) { // log.debug("Found Cookie " + theToken.getName() + " with value " + // theToken.getValue()); // The Token is currently designed to be a random Big Integer. If the Big // Integer Case does not work, the token has been modified. Potentially in a // malicious manner try { BigInteger theTokenCasted = new BigInteger(theToken.getValue()); BigInteger tenGrand = new BigInteger("10000"); BigInteger tenGrandNeg = new BigInteger("-10000"); if (!(theTokenCasted.compareTo(tenGrand) > 0 || theTokenCasted.compareTo(tenGrandNeg) < 0)) { log.error("CSRF Cookie Token was modified in some manor!"); theToken = null; } } catch (Exception e) { log.error("CSRF Cookie Token was modified in some manor: " + e.toString()); theToken = null; } } return theToken; } /** * Validates class year when creating classes. Class year should be YY/YY, e.g. 11/12. So the * first year must be less than the second. * * @param classYear Class Year in YY/YY format, e.g. 11/12. * @return Boolean value stating weather or not these supplied attributes make a valid class year */ public static boolean isValidClassYear(String classYear) { boolean result = false; result = classYear.length() == 4; if (result) { try { result = Integer.parseInt(classYear) > 2010; } catch (NumberFormatException e) { log.error("Could not parse classYear " + classYear); result = false; throw new RuntimeException(e); } } return result; } /** * Email validation * * @param email * @return Boolean reflect email validity */ public static boolean isValidEmailAddress(String email) { boolean result = true; try { log.debug("Validating email"); InternetAddress emailAddr = new InternetAddress(email); log.debug("Did we crash"); emailAddr.validate(); log.debug("Didn't crash"); } catch (AddressException ex) { result = false; } return result; } /** * Invalid password detecter * * @param passWord * @return */ public static boolean isValidPassword(String passWord) { boolean result = false; result = passWord.length() > 7 && passWord.length() 2 && userLength 7 && passLength 2 && passWord.length() >= 8 && userName.length()


Web Proxy Viewer  |  New URL  |  Original Page