aboutsummaryrefslogtreecommitdiffstats
path: root/security-utils/src/main/java/com/yahoo/security/tls
diff options
context:
space:
mode:
authorBjørn Christian Seime <bjorncs@verizonmedia.com>2021-12-02 16:46:27 +0100
committerBjørn Christian Seime <bjorncs@verizonmedia.com>2021-12-02 16:46:27 +0100
commit482a30d82ab06a8f8ddfbc1d3e1222daa0b3389f (patch)
treea6729f4666159a997749dda56604157c3a9fae18 /security-utils/src/main/java/com/yahoo/security/tls
parent7050f71b6d40c59fb68315b0c72dc3dcf84f0f0c (diff)
Add glob pattern helper that handles multiple alternative boundaries
Diffstat (limited to 'security-utils/src/main/java/com/yahoo/security/tls')
-rw-r--r--security-utils/src/main/java/com/yahoo/security/tls/policy/GlobPattern.java82
-rw-r--r--security-utils/src/main/java/com/yahoo/security/tls/policy/HostGlobPattern.java42
2 files changed, 89 insertions, 35 deletions
diff --git a/security-utils/src/main/java/com/yahoo/security/tls/policy/GlobPattern.java b/security-utils/src/main/java/com/yahoo/security/tls/policy/GlobPattern.java
new file mode 100644
index 00000000000..30d4186f8a5
--- /dev/null
+++ b/security-utils/src/main/java/com/yahoo/security/tls/policy/GlobPattern.java
@@ -0,0 +1,82 @@
+// Copyright Yahoo. Licensed under the terms of the Apache 2.0 license. See LICENSE in the project root.
+package com.yahoo.security.tls.policy;
+
+import java.util.Arrays;
+import java.util.Objects;
+import java.util.regex.Pattern;
+
+/**
+ * Matching engine for glob patterns having where one ore more alternative characters acts a boundary for wildcard matching.
+ *
+ * @author bjorncs
+ */
+class GlobPattern {
+ private final String pattern;
+ private final char[] boundaries;
+ private final Pattern regexPattern;
+
+ GlobPattern(String pattern, char[] boundaries) {
+ this.pattern = pattern;
+ this.boundaries = boundaries;
+ this.regexPattern = toRegexPattern(pattern, boundaries);
+ }
+
+ boolean matches(String value) { return regexPattern.matcher(value).matches(); }
+
+ String asString() { return pattern; }
+ Pattern regexPattern() { return regexPattern; }
+ char[] boundaries() { return boundaries; }
+
+ private static Pattern toRegexPattern(String pattern, char[] boundaries) {
+ StringBuilder builder = new StringBuilder("^");
+ StringBuilder precedingCharactersToQuote = new StringBuilder();
+ char[] chars = pattern.toCharArray();
+ for (char c : chars) {
+ if (c == '?' || c == '*') {
+ builder.append(quotePrecedingLiteralsAndReset(precedingCharactersToQuote));
+ // Note: we explicitly stop matching at a separator boundary.
+ // This is to make matching less vulnerable to dirty tricks (e.g dot as boundary for hostnames).
+ // Same applies for single chars; they should only match _within_ a boundary.
+ builder.append("[^").append(Pattern.quote(new String(boundaries))).append("]");
+ if (c == '*') builder.append('*');
+ } else {
+ precedingCharactersToQuote.append(c);
+ }
+ }
+ return Pattern.compile(builder.append(quotePrecedingLiteralsAndReset(precedingCharactersToQuote)).append('$').toString());
+ }
+
+ // Combines multiple subsequent literals inside a single quote to simplify produced regex patterns
+ private static String quotePrecedingLiteralsAndReset(StringBuilder literals) {
+ if (literals.length() > 0) {
+ String quoted = literals.toString();
+ literals.setLength(0);
+ return Pattern.quote(quoted);
+ }
+ return "";
+ }
+
+ @Override
+ public boolean equals(Object o) {
+ if (this == o) return true;
+ if (o == null || getClass() != o.getClass()) return false;
+ GlobPattern that = (GlobPattern) o;
+ return Objects.equals(pattern, that.pattern) && Arrays.equals(boundaries, that.boundaries);
+ }
+
+ @Override
+ public int hashCode() {
+ int result = Objects.hash(pattern);
+ result = 31 * result + Arrays.hashCode(boundaries);
+ return result;
+ }
+
+ @Override
+ public String toString() {
+ return "GlobPattern{" +
+ "pattern='" + pattern + '\'' +
+ ", boundaries=" + Arrays.toString(boundaries) +
+ ", regexPattern=" + regexPattern +
+ '}';
+ }
+}
diff --git a/security-utils/src/main/java/com/yahoo/security/tls/policy/HostGlobPattern.java b/security-utils/src/main/java/com/yahoo/security/tls/policy/HostGlobPattern.java
index fd9a233d609..d59052a48ef 100644
--- a/security-utils/src/main/java/com/yahoo/security/tls/policy/HostGlobPattern.java
+++ b/security-utils/src/main/java/com/yahoo/security/tls/policy/HostGlobPattern.java
@@ -2,60 +2,32 @@
package com.yahoo.security.tls.policy;
import java.util.Objects;
-import java.util.regex.Pattern;
/**
* @author bjorncs
*/
class HostGlobPattern implements RequiredPeerCredential.Pattern {
- private final String pattern;
- private final Pattern regexPattern;
+ private final GlobPattern globPattern;
HostGlobPattern(String pattern) {
- this.pattern = pattern;
- this.regexPattern = toRegexPattern(pattern);
+ this.globPattern = new GlobPattern(pattern, new char[] {'.'});
}
@Override
public String asString() {
- return pattern;
+ return globPattern.asString();
}
@Override
public boolean matches(String hostString) {
- return regexPattern.matcher(hostString).matches();
- }
-
- private static Pattern toRegexPattern(String pattern) {
- StringBuilder builder = new StringBuilder("^");
- for (char c : pattern.toCharArray()) {
- if (c == '*') {
- // Note: we explicitly stop matching at a dot separator boundary.
- // This is to make host name matching less vulnerable to dirty tricks.
- builder.append("[^.]*");
- } else if (c == '?') {
- // Same applies for single chars; they should only match _within_ a dot boundary.
- builder.append("[^.]");
- } else if (isRegexMetaCharacter(c)){
- builder.append("\\");
- builder.append(c);
- } else {
- builder.append(c);
- }
- }
- builder.append('$');
- return Pattern.compile(builder.toString());
- }
-
- private static boolean isRegexMetaCharacter(char c) {
- return "<([{\\^-=$!|]})?*+.>".indexOf(c) != -1; // note: includes '?' and '*'
+ return globPattern.matches(hostString);
}
@Override
public String toString() {
return "HostGlobPattern{" +
- "pattern='" + pattern + '\'' +
+ "pattern='" + globPattern + '\'' +
'}';
}
@@ -64,11 +36,11 @@ class HostGlobPattern implements RequiredPeerCredential.Pattern {
if (this == o) return true;
if (o == null || getClass() != o.getClass()) return false;
HostGlobPattern that = (HostGlobPattern) o;
- return Objects.equals(pattern, that.pattern);
+ return Objects.equals(globPattern, that.globPattern);
}
@Override
public int hashCode() {
- return Objects.hash(pattern);
+ return Objects.hash(globPattern);
}
}