Project

General

Profile

1
/**
2
 *  '$RCSfile$'
3
 *    Purpose: A Class that implements a metadata catalog as a java Servlet
4
 *  Copyright: 2000 Regents of the University of California and the
5
 *             National Center for Ecological Analysis and Synthesis
6
 *    Authors: Matt Jones, Dan Higgins, Jivka Bojilova, Chad Berkley
7
 *    Release: @release@
8
 *
9
 *   '$Author: bojilova $'
10
 *     '$Date: 2001-05-04 14:30:51 -0700 (Fri, 04 May 2001) $'
11
 * '$Revision: 738 $'
12
 *
13
 * This program is free software; you can redistribute it and/or modify
14
 * it under the terms of the GNU General Public License as published by
15
 * the Free Software Foundation; either version 2 of the License, or
16
 * (at your option) any later version.
17
 *
18
 * This program is distributed in the hope that it will be useful,
19
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
21
 * GNU General Public License for more details.
22
 *
23
 * You should have received a copy of the GNU General Public License
24
 * along with this program; if not, write to the Free Software
25
 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
26
 */
27

    
28
package edu.ucsb.nceas.metacat;
29

    
30
import java.io.File;
31
import java.io.PrintWriter;
32
import java.io.IOException;
33
import java.io.StringReader;
34
import java.io.FileInputStream;
35
import java.io.BufferedInputStream;
36
import java.util.Enumeration;
37
import java.util.Hashtable;
38
import java.util.ResourceBundle; 
39
import java.util.Random;
40
import java.util.PropertyResourceBundle;
41
import java.net.URL;
42
import java.net.MalformedURLException;
43
import java.sql.PreparedStatement;
44
import java.sql.ResultSet;
45
import java.sql.Connection;
46
import java.sql.SQLException;
47
import java.lang.reflect.*;
48
import java.net.*;
49
import java.util.zip.*;
50

    
51
import javax.servlet.ServletConfig;
52
import javax.servlet.ServletContext;
53
import javax.servlet.ServletException;
54
import javax.servlet.ServletInputStream;
55
import javax.servlet.http.HttpServlet;
56
import javax.servlet.http.HttpServletRequest;
57
import javax.servlet.http.HttpServletResponse;
58
import javax.servlet.http.HttpSession;
59
import javax.servlet.http.HttpUtils;
60
import javax.servlet.ServletOutputStream;
61

    
62
import oracle.xml.parser.v2.XSLStylesheet;
63
import oracle.xml.parser.v2.XSLException;
64
import oracle.xml.parser.v2.XMLDocumentFragment;
65
import oracle.xml.parser.v2.XSLProcessor;
66

    
67
import org.xml.sax.SAXException;
68

    
69
/**
70
 * A metadata catalog server implemented as a Java Servlet
71
 *
72
 * <p>Valid parameters are:<br>
73
 * action=query -- query the values of all elements and attributes
74
 *                     and return a result set of nodes<br>
75
 * action=squery -- structured query (see pathquery.dtd)<br>
76
 * action=read -- read any metadata/data file from Metacat and from Internet<br>
77
 * action=insert -- insert an XML document into the database store<br>
78
 * action=update -- update an XML document that is in the database store<br>
79
 * action=delete --  delete an XML document from the database store<br>
80
 * action=validate -- vallidate the xml contained in valtext<br>
81
 * doctype -- document type list returned by the query (publicID)<br>
82
 * qformat=xml -- display resultset from query in XML<br>
83
 * qformat=html -- display resultset from query in HTML<br>
84
 * qformat=zip -- zip resultset from query<br>
85
 * docid=34 -- display the document with the document ID number 34<br>
86
 * doctext -- XML text of the document to load into the database<br>
87
 * acltext -- XML access text for a document to load into the database<br>
88
 * dtdtext -- XML DTD text for a new DTD to load into Metacat XML Catalog<br>
89
 * query -- actual query text (to go with 'action=query' or 'action=squery')<br>
90
 * valtext -- XML text to be validated<br>
91
 * abstractpath -- XPath in metadata document to read from<br>
92
 * action=getaccesscontrol -- retrieve acl info for Metacat document<br>
93
 * action=getdoctypes -- retrieve all doctypes (publicID)<br>
94
 * action=getdtdschema -- retrieve a DTD or Schema file<br>
95
 * action=getdataguide -- retrieve a Data Guide<br>
96
 * action=getprincipals -- retrieve a list of principals in XML<br>
97
 * datadoc -- data document name (id)<br>
98
 * <p>
99
 * The particular combination of parameters that are valid for each 
100
 * particular action value is quite specific.  This documentation
101
 * will be reorganized to reflect this information.
102
 */
103
public class MetaCatServlet extends HttpServlet {
104

    
105
  private ServletConfig config = null;
106
  private ServletContext context = null;
107
  private Hashtable connectionPool = new Hashtable();
108
  private String resultStyleURL = null;
109
  private String xmlcatalogfile = null;
110
  private String saxparser = null;
111
  private String defaultdatapath = null; 
112
  private String servletpath = null; 
113
  private PropertyResourceBundle options = null;
114
  private MetaCatUtil util = null;
115

    
116
  // path to directory where data files 
117
  // that can be downloaded will be stored
118
  private String htmlpath = null; 
119
  // script to get data file and put it 
120
  // in defaultdocpath dir
121
  private String executescript  = null;  
122

    
123
  /**
124
   * Initialize the servlet by creating appropriate database connections
125
   */
126
  public void init( ServletConfig config ) throws ServletException {
127
    try {
128
      super.init( config );
129
      this.config = config;
130
      this.context = config.getServletContext(); 
131
      System.out.println("MetaCatServlet Initialize");
132

    
133
      util = new MetaCatUtil();
134

    
135
      // Get the configuration file information
136
      resultStyleURL = util.getOption("resultStyleURL");
137
      xmlcatalogfile = util.getOption("xmlcatalogfile");
138
      saxparser = util.getOption("saxparser");
139
      defaultdatapath = util.getOption("defaultdatapath");
140
      executescript = util.getOption("executescript"); 
141
      servletpath = util.getOption("servletpath");
142
      htmlpath = util.getOption("htmlpath");
143

    
144
// MOVED IT TO doGet() & doPost()
145
//      try {
146
//        // Open a pool of db connections
147
//        connectionPool = util.getConnectionPool();
148
//      } catch (Exception e) {
149
//        System.err.println("Error creating pool of database connections");
150
//        System.err.println(e.getMessage());
151
//      }
152
    } catch ( ServletException ex ) {
153
      throw ex;
154
    }
155
  }
156

    
157
  /**
158
   * Close all db connections from the pool
159
   */
160
  public void destroy() {
161
    
162
    if (util != null) {
163
        util.closeConnections();
164
    }
165
  }
166

    
167
  /** Handle "GET" method requests from HTTP clients */
168
  public void doGet (HttpServletRequest request, HttpServletResponse response)
169
    throws ServletException, IOException {
170

    
171
    // Process the data and send back the response
172
    handleGetOrPost(request, response);
173
  }
174

    
175
  /** Handle "POST" method requests from HTTP clients */
176
  public void doPost( HttpServletRequest request, HttpServletResponse response)
177
    throws ServletException, IOException {
178

    
179
    // Process the data and send back the response
180
    handleGetOrPost(request, response);
181
  }
182

    
183
  /**
184
   * Control servlet response depending on the action parameter specified
185
   */
186
  private void handleGetOrPost(HttpServletRequest request, 
187
    HttpServletResponse response) 
188
    throws ServletException, IOException 
189
 {
190

    
191
    if ( util == null ) {
192
        util = new MetaCatUtil(); 
193
    }
194
    if ( connectionPool.isEmpty() ) {
195
      try {
196
        // Open a pool of db connections
197
        connectionPool = util.getConnectionPool();
198
      } catch (Exception e) {
199
        System.err.println("Error creating pool of database connections in " +
200
                            " MetaCatServlet.handleGetOrPost");
201
        System.err.println(e.getMessage());
202
      }
203
    }    
204
    // Get a handle to the output stream back to the client
205
    //PrintWriter pwout = response.getWriter();
206
    //response.setContentType("text/html");
207
  
208
    String name = null;
209
    String[] value = null;
210
    String[] docid = new String[3];
211
    Hashtable params = new Hashtable();
212
    Enumeration paramlist = request.getParameterNames();
213
    while (paramlist.hasMoreElements()) {
214
      name = (String)paramlist.nextElement();
215
      value = request.getParameterValues(name);
216

    
217
      // Decode the docid and mouse click information
218
      if (name.endsWith(".y")) {
219
        docid[0] = name.substring(0,name.length()-2);
220
        params.put("docid", docid);
221
        name = "ypos";
222
      }
223
      if (name.endsWith(".x")) {
224
        name = "xpos";
225
      } 
226

    
227
      params.put(name,value); 
228
    }  
229
    
230
    //if the user clicked on the input images, decode which image
231
    //was clicked then set the action.
232
    String action = ((String[])params.get("action"))[0];  
233
    util.debugMessage("Line 213: Action is: " + action);
234

    
235
    // This block handles session management for the servlet
236
    // by looking up the current session information for all actions
237
    // other than "login" and "logout"
238
    String username = null;
239
    String password = null;
240
    String groupname = null;
241
    String sess_id = null;
242

    
243
    // handle login action
244
    if (action.equals("login")) {
245

    
246
      handleLoginAction(response.getWriter(), params, request, response);
247

    
248
    // handle logout action  
249
    } else if (action.equals("logout")) {
250

    
251
      handleLogoutAction(response.getWriter(), params, request, response);
252

    
253
    // aware of session expiration on every request  
254
    } else {   
255

    
256
      HttpSession sess = request.getSession(true);
257
      if (sess.isNew()) { 
258
        // session expired or has not been stored b/w user requests
259
        username = "public";
260
        sess.setAttribute("username", username);
261
      } else {
262
        username = (String)sess.getAttribute("username");
263
        password = (String)sess.getAttribute("password");
264
        groupname = (String)sess.getAttribute("groupname");
265
        try {
266
          sess_id = (String)sess.getId();
267
        } catch(IllegalStateException ise) {
268
          System.out.println("error in handleGetOrPost: this shouldn't " +
269
                             "happen: the session should be valid: " + 
270
                             ise.getMessage());
271
        }
272
      }  
273
    }    
274

    
275
    // Now that we know the session is valid, we can delegate the request
276
    // to a particular action handler
277
    if(action.equals("query")) {
278
      handleQuery(response.getWriter(), params, response, username, groupname); 
279
    } else if(action.equals("squery")) {
280
      if(params.containsKey("query")) {
281
        handleSQuery(response.getWriter(), params, response, username, groupname); 
282
      } else {
283
        PrintWriter out = response.getWriter();
284
        out.println("Illegal action squery without \"query\" parameter");
285
      }
286
    } else if (action.equals("read")) {
287
      handleReadAction(params, response, username, groupname);
288
    } else if (action.equals("insert") || action.equals("update")) {
289
      PrintWriter out = response.getWriter();
290
      if ( (username != null) &&  !username.equals("public") ) {
291
        handleInsertOrUpdateAction(out, params, response, username, groupname);
292
      } else {  
293
        out.println("Permission denied for " + action);
294
      }  
295
    } else if (action.equals("delete")) {
296
      PrintWriter out = response.getWriter();
297
      if ( (username != null) &&  !username.equals("public") ) {
298
        handleDeleteAction(out, params, response, username, groupname);
299
      } else {  
300
        out.println("Permission denied for " + action);
301
      }  
302
    } else if (action.equals("validate")) {
303
      PrintWriter out = response.getWriter();
304
      handleValidateAction(out, params, response); 
305
    } else if (action.equals("getdataport")) {
306
      PrintWriter out = response.getWriter();
307
      if ( (username != null) &&  !username.equals("public") ) {
308
      handleGetDataPortAction(out, params, response, username, groupname, 
309
                              sess_id);
310
      } else {
311
        out.println("You must be authenticated to perform the getdataport " +
312
                    "action!");
313
      }
314
    } else if (action.equals("getaccesscontrol")) {
315
      PrintWriter out = response.getWriter();
316
      handleGetAccessControlAction(out, params, response, username, groupname);
317
    } else if (action.equals("getprincipals")) {
318
      PrintWriter out = response.getWriter();
319
      handleGetPrincipalsAction(out, username, password);  
320
    } else if (action.equals("getdoctypes")) {
321
      PrintWriter out = response.getWriter();
322
      handleGetDoctypesAction(out, params, response);  
323
    } else if (action.equals("getdtdschema")) {
324
      PrintWriter out = response.getWriter();
325
      handleGetDTDSchemaAction(out, params, response);  
326
    } else if (action.equals("getdataguide")) {
327
      PrintWriter out = response.getWriter();
328
      handleGetDataGuideAction(out, params, response);  
329
    } else if (action.equals("login") || action.equals("logout")) {
330
    } else if (action.equals("protocoltest")) {
331
      String testURL = "metacat://dev.nceas.ucsb.edu/NCEAS.897766.9";
332
      try {
333
        testURL = ((String[])params.get("url"))[0];
334
      } catch (Throwable t) {
335
      }
336
      String phandler = System.getProperty("java.protocol.handler.pkgs");
337
      response.setContentType("text/html");
338
      PrintWriter out = response.getWriter();
339
      out.println("<body bgcolor=\"white\">");
340
      out.println("<p>Handler property: <code>" + phandler + "</code></p>");
341
      out.println("<p>Starting test for:<br>");
342
      out.println("    " + testURL + "</p>");
343
      try {
344
        URL u = new URL(testURL);
345
        out.println("<pre>");
346
        out.println("Protocol: " + u.getProtocol());
347
        out.println("    Host: " + u.getHost());
348
        out.println("    Port: " + u.getPort());
349
        out.println("    Path: " + u.getPath());
350
        out.println("     Ref: " + u.getRef());
351
        String pquery = u.getQuery();
352
        out.println("   Query: " + pquery);
353
        out.println("  Params: ");
354
        if (pquery != null) {
355
          Hashtable qparams = util.parseQuery(u.getQuery());
356
          for (Enumeration en = qparams.keys(); en.hasMoreElements(); ) {
357
            String pname = (String)en.nextElement();
358
            String pvalue = (String)qparams.get(pname);
359
            out.println("    " + pname + ": " + pvalue);
360
          }
361
        }
362
        out.println("</pre>");
363
        out.println("</body>");
364
        out.close();
365
      } catch (MalformedURLException mue) {
366
        System.out.println("bad url from MetacatServlet.handleGetOrPost");
367
        out.println(mue.getMessage());
368
        mue.printStackTrace(out);
369
        out.close();
370
      }
371
    } else {
372
      PrintWriter out = response.getWriter();
373
      out.println("Error: action not registered.  Please report this error.");
374
    }
375
    
376
    util.closeConnections();
377
    // Close the stream to the client
378
    // out.close();
379
  }
380
  
381
  // LOGIN & LOGOUT SECTION
382
  /** 
383
   * Handle the login request. Create a new session object.
384
   * Do user authentication through the session.
385
   */
386
  private void handleLoginAction(PrintWriter out, Hashtable params, 
387
               HttpServletRequest request, HttpServletResponse response) {
388

    
389
    AuthSession sess = null;
390
    String un = ((String[])params.get("username"))[0];
391
    String pw = ((String[])params.get("password"))[0];
392
    String action = ((String[])params.get("action"))[0];
393
    String qformat = ((String[])params.get("qformat"))[0];
394
    
395
    try {
396
      sess = new AuthSession();
397
    } catch (Exception e) {
398
      System.out.println("error in MetacatServlet.handleLoginAction: " +
399
                          e.getMessage());
400
      out.println(e.getMessage());
401
      return;
402
    }
403
    
404
    boolean isValid = sess.authenticate(request, un, pw);
405

    
406
    // format and transform the output
407
    if (qformat.equals("html")) {
408
      Connection conn = null;
409
      try {
410
        conn = util.getConnection();
411
        DBTransform trans = new DBTransform(conn);
412
        response.setContentType("text/html");
413
        trans.transformXMLDocument(sess.getMessage(), "-//NCEAS//login//EN",
414
                                   "-//W3C//HTML//EN", out);
415
        util.returnConnection(conn); 
416
      } catch(Exception e) {
417
        util.returnConnection(conn); 
418
      } 
419
      
420
    // any output is returned  
421
    } else {
422
      response.setContentType("text/xml");
423
      out.println(sess.getMessage()); 
424
    }
425
  }    
426

    
427
  /** 
428
   * Handle the logout request. Close the connection.
429
   */
430
  private void handleLogoutAction(PrintWriter out, Hashtable params, 
431
               HttpServletRequest request, HttpServletResponse response) {
432

    
433
    String qformat = ((String[])params.get("qformat"))[0];
434

    
435
    // close the connection
436
    HttpSession sess = request.getSession(false);
437
    if (sess != null) { sess.invalidate();  }    
438

    
439
    // produce output
440
    StringBuffer output = new StringBuffer();
441
    output.append("<?xml version=\"1.0\"?>");
442
    output.append("<logout>");
443
    output.append("User logged out");
444
    output.append("</logout>");
445

    
446
    //format and transform the output
447
    if (qformat.equals("html")) {
448
      Connection conn = null;
449
      try {
450
        conn = util.getConnection();
451
        DBTransform trans = new DBTransform(conn);
452
        response.setContentType("text/html");
453
        trans.transformXMLDocument(output.toString(), "-//NCEAS//login//EN", 
454
                                   "-//W3C//HTML//EN", out);
455
        util.returnConnection(conn); 
456
      } catch(Exception e) {
457
        util.returnConnection(conn); 
458
      } 
459
    // any output is returned  
460
    } else {
461
      response.setContentType("text/xml");
462
      out.println(output.toString()); 
463
    }
464
  }
465
  // END OF LOGIN & LOGOUT SECTION
466
  
467
  // SQUERY & QUERY SECTION
468
  /**      
469
   * Retreive the squery xml, execute it and display it
470
   *
471
   * @param out the output stream to the client
472
   * @param params the Hashtable of parameters that should be included
473
   * in the squery.
474
   * @param response the response object linked to the client
475
   * @param conn the database connection 
476
   */
477
  protected void handleSQuery(PrintWriter out, Hashtable params, 
478
                 HttpServletResponse response, String user, String group)
479
  { 
480
    String xmlquery = ((String[])params.get("query"))[0];
481
    String qformat = ((String[])params.get("qformat"))[0];
482
    String resultdoc = null;
483
    String[] returndoc = null;
484
    if(params.contains("returndoc"))
485
    {
486
      returndoc = (String[])params.get("returndoc");
487
    }
488
    
489
    Hashtable doclist = runQuery(xmlquery, user, group, returndoc);
490
    //String resultdoc = createResultDocument(doclist, transformQuery(xmlquery));
491

    
492
    resultdoc = createResultDocument(doclist, transformQuery(xmlquery));
493
    
494
    //format and transform the results                                        
495
    if(qformat.equals("html")) {
496
      transformResultset(resultdoc, response, out);
497
    } else if(qformat.equals("xml")) {
498
      response.setContentType("text/xml");
499
      out.println(resultdoc);
500
    } else {
501
      out.println("invalid qformat: " + qformat); 
502
    }
503
  }
504
  
505
   /**
506
    * Create the xml query, execute it and display the results.
507
    *
508
    * @param out the output stream to the client
509
    * @param params the Hashtable of parameters that should be included
510
    * in the squery.
511
    * @param response the response object linked to the client
512
    */ 
513
  protected void handleQuery(PrintWriter out, Hashtable params, 
514
                 HttpServletResponse response, String user, String group)
515
  {
516
    //create the query and run it
517
    String[] returndoc = null;
518
    if(params.containsKey("returndoc"))
519
    {
520
      returndoc = (String[])params.get("returndoc");
521
    }
522
    String xmlquery = DBQuery.createSQuery(params);
523
    Hashtable doclist = runQuery(xmlquery, user, group, returndoc);
524
    String qformat = ((String[])params.get("qformat"))[0];
525
    String resultdoc = null;
526
    
527
    resultdoc = createResultDocument(doclist, transformQuery(params));
528

    
529
    //format and transform the results                                        
530
    if(qformat.equals("html")) {
531
      transformResultset(resultdoc, response, out);
532
    } else if(qformat.equals("xml")) {
533
      response.setContentType("text/xml");
534
      out.println(resultdoc);
535
    } else { 
536
      out.println("invalid qformat: " + qformat); 
537
    }
538
  }
539
  
540
  /**
541
   * Removes the <?xml version="x"?> tag from the beginning of xmlquery
542
   * so it can properly be placed in the <query> tag of the resultset.
543
   * This method is overwritable so that other applications can customize
544
   * the structure of what is in the <query> tag.
545
   * 
546
   * @param xmlquery is the query to remove the <?xml version="x"?> tag from.
547
   */
548
  protected String transformQuery(Hashtable params)
549
  {
550
    //DBQuery.createSQuery is a re-calling of a previously called 
551
    //function but it is necessary
552
    //so that overriding methods have access to the params hashtable
553
    String xmlquery = DBQuery.createSQuery(params);
554
    //the <?xml version="1.0"?> tag is the first 22 characters of the
555
    xmlquery = xmlquery.trim();
556
    int index = xmlquery.indexOf("?>");
557
    return xmlquery.substring(index + 2, xmlquery.length());
558
  }
559
  
560
  /**
561
   * removes the <?xml version="1.0"?> tag from the beginning.  This takes a
562
   * string as a param instead of a hashtable.
563
   * 
564
   * @param xmlquery a string representing a query.
565
   */
566
  protected String transformQuery(String xmlquery)
567
  {
568
    xmlquery = xmlquery.trim();
569
    int index = xmlquery.indexOf("?>");
570
    return xmlquery.substring(index + 2, xmlquery.length());
571
  }
572
  
573
  /**
574
   * Run the query and return a hashtable of results.
575
   *
576
   * @param xmlquery the query to run
577
   */
578
  private Hashtable runQuery(String xmlquery, String user, String group, 
579
                             String[] returndoc)
580
  {
581
    Hashtable doclist=null;
582
    Connection conn = null;
583
    try
584
    {
585
      conn = util.getConnection();
586
      DBQuery queryobj = new DBQuery(conn, saxparser);
587
      doclist = queryobj.findDocuments(new StringReader(xmlquery),user,group,
588
                                       returndoc);
589
      util.returnConnection(conn);
590
      return doclist;
591
    } 
592
    catch (Exception e) 
593
    {
594
      util.returnConnection(conn); 
595
      util.debugMessage("Error in MetacatServlet.runQuery: " + e.getMessage());
596
      doclist = null;
597
      return doclist;
598
    }    
599
  }
600
  
601
  /**
602
   * Transorms an xml resultset document to html and sends it to the browser
603
   *
604
   * @param resultdoc the string representation of the document that needs
605
   * to be transformed.
606
   * @param response the HttpServletResponse object bound to the client.
607
   * @param out the output stream to the client
608
   */ 
609
  protected void transformResultset(String resultdoc, 
610
                                    HttpServletResponse response,
611
                                    PrintWriter out)
612
  {
613
    Connection conn = null;
614
    try {
615
      conn = util.getConnection();
616
      DBTransform trans = new DBTransform(conn);
617
      response.setContentType("text/html");
618
      trans.transformXMLDocument(resultdoc, "-//NCEAS//resultset//EN", 
619
                                 "-//W3C//HTML//EN", out);
620
      util.returnConnection(conn); 
621
    }
622
    catch(Exception e)
623
    {
624
      util.returnConnection(conn); 
625
    } 
626
  }
627
  
628
  /**
629
   * Transforms a hashtable of documents to an xml or html result.
630
   * If there is a returndoc, then it only displays documents of
631
   * whatever type returndoc represents.  If a result is found in a document
632
   * that is not of type returndoc then this attempts to find a relation 
633
   * between this document and one that satifies the returndoc doctype.
634
   *
635
   * @param doclist- the hashtable to transform
636
   * @param xmlquery- the query that returned the dolist result
637
   * @param resultdoc- the document type to backtrack to.
638
   */
639
  protected String createResultDocument(Hashtable doclist, String xmlquery)
640
  {
641
    // Create a buffer to hold the xml result
642
    StringBuffer resultset = new StringBuffer();
643
 
644
    // Print the resulting root nodes 
645
    String docid = null;
646
    String document = null;
647
    resultset.append("<?xml version=\"1.0\"?>\n");
648
    resultset.append("<resultset>\n");
649
      
650
    resultset.append("  <query>" + xmlquery + "</query>");   
651

    
652
    if(doclist != null)
653
    {
654
      Enumeration doclistkeys = doclist.keys(); 
655
      while (doclistkeys.hasMoreElements()) 
656
      {
657
        docid = (String)doclistkeys.nextElement();
658
        document = (String)doclist.get(docid);
659
        resultset.append("  <document>" + document + "</document>");
660
      }
661
    }
662

    
663
    resultset.append("</resultset>");
664
    //System.out.println(resultset.toString());
665
    return resultset.toString();
666
  }
667
  // END OF SQUERY & QUERY SECTION
668
  
669
  // READ SECTION
670
  /** 
671
   * Handle the "read" request of metadata/data files from Metacat
672
   * or any files from Internet;
673
   * transformed metadata XML document into HTML presentation if requested;
674
   * zip files when more than one were requested.
675
   *
676
   * @param params the Hashtable of HTTP request parameters
677
   * @param response the HTTP response object linked to the client
678
   * @param user the username sent the request
679
   * @param group the user's groupname
680
   */
681
  private void handleReadAction(Hashtable params, HttpServletResponse response,
682
                                String user, String group) 
683
  {
684
    ServletOutputStream out = null;
685
    ZipOutputStream zout = null;
686
    
687
    try {
688
      String[] docs = new String[0];
689
      String docid = "";
690
      String qformat = "";
691
      String abstrpath = null;
692
      boolean zip = false;
693
      // read the params
694
      if (params.containsKey("docid")) {
695
        docs = (String[])params.get("docid");
696
      }
697
      if (params.containsKey("qformat")) {
698
        qformat = ((String[])params.get("qformat"))[0];
699
      }
700
      if (params.containsKey("abstractpath")) {
701
        abstrpath = ((String[])params.get("abstractpath"))[0];
702
        if ( !abstrpath.equals("") && (abstrpath != null) ) {
703
          viewAbstract(response, abstrpath, docs[0]);
704
          return;
705
        }
706
      }
707
      if ( (docs.length > 1) || qformat.equals("zip") ) {
708
        zip = true;
709
        out = response.getOutputStream();
710
        response.setContentType("application/zip"); //MIME type
711
        zout = new ZipOutputStream(out);
712
      }
713
      // go through the list of docs to read
714
      for (int i=0; i < docs.length; i++ ) {
715
        try {
716

    
717
          URL murl = new URL(docs[i]);
718
          Hashtable murlQueryStr = util.parseQuery(murl.getQuery());
719
          // case docid="http://.../?docid=aaa" 
720
          // or docid="metacat://.../?docid=bbb"
721
          if (murlQueryStr.containsKey("docid")) {
722
            // get only docid, eliminate the rest
723
            docid = (String)murlQueryStr.get("docid");
724
            if ( zip ) {
725
              addDocToZip(docid, zout);
726
            } else {
727
              readFromMetacat(response, docid, qformat, abstrpath,
728
                              user, group, zip, zout);
729
            }
730

    
731
          // case docid="http://.../filename"
732
          } else {
733
            docid = docs[i];
734
            if ( zip ) {
735
              addDocToZip(docid, zout);
736
            } else {
737
              readFromURLConnection(response, docid);
738
            }
739
          }
740

    
741
        // case docid="ccc"
742
        } catch (MalformedURLException mue) {
743
          docid = docs[i];
744
          if ( zip ) {
745
            addDocToZip(docid, zout);
746
          } else {
747
            readFromMetacat(response, docid, qformat, abstrpath,
748
                            user, group, zip, zout);
749
          }
750
        }
751
        
752
      } /* end for */
753
      
754
      if ( zip ) {
755
        zout.finish(); //terminate the zip file
756
        zout.close();  //close the zip stream
757
      }
758
      
759
    } catch (Exception e) {
760
      try {
761
        if ( out != null ) { out.close(); }
762
        if ( zout != null ) { zout.close(); }
763
        response.setContentType("text/xml"); //MIME type
764
        PrintWriter pw = response.getWriter();
765
        pw.println(e.getMessage());
766
      } catch (IOException ioe) {
767
        System.out.println("Problem with the servlet output " +
768
                           "in MetacatServlet.handleReadAction: " +
769
                           ioe.getMessage());
770
        ioe.printStackTrace(System.out);
771
        
772
      }
773

    
774
      System.out.println("Error in MetacatServlet.handleReadAction: " +
775
                         e.getMessage());
776
      e.printStackTrace(System.out);
777
    }
778
    
779
  }
780
  
781
  // read metadata or data from Metacat
782
  private void readFromMetacat(HttpServletResponse response, String docid,
783
                               String qformat, String abstrpath, String user,
784
                               String group, boolean zip, ZipOutputStream zout)
785
               throws ClassNotFoundException, IOException, SQLException, 
786
                      McdbException, Exception
787
  {
788
    Connection conn = null;
789
    try {
790
      conn = util.getConnection();
791
      DocumentImpl doc = new DocumentImpl(conn, docid);
792
      
793
      if ( doc.getRootNodeID() == 0 ) {
794
        // this is data file
795
        ServletOutputStream out = response.getOutputStream(); 
796
        String filepath = util.getOption("datafilepath");
797
        if(!filepath.endsWith("/")) {
798
          filepath += "/";
799
        }
800
        String filename = filepath + doc.getDocname();      //MIME type
801
        String contentType = getServletContext().getMimeType(filename);
802
        if (contentType == null) {
803
          if (filename.endsWith(".xml")) {
804
            contentType="text/xml";
805
          } else if (filename.endsWith(".css")) {
806
            contentType="text/css";
807
          } else if (filename.endsWith(".dtd")) {
808
            contentType="text/plain";
809
          } else if (filename.endsWith(".xsd")) {
810
            contentType="text/xml";
811
          } else if (filename.endsWith("/")) {
812
            contentType="text/html";
813
          } else {
814
            File f = new File(filename);
815
            if ( f.isDirectory() ) {
816
              contentType="text/html";
817
            } else {
818
              contentType="application/octet-stream";
819
            }
820
          }
821
        }
822
        response.setContentType(contentType);
823
        // if we decide to use "application/octet-stream" for all data returns
824
        // response.setContentType("application/octet-stream");
825
        FileInputStream fin = null;
826
        try {
827
          fin = new FileInputStream(filename);
828
          byte[] buf = new byte[4 * 1024]; // 4K buffer
829
          int b = fin.read(buf);
830
          while (b != -1) {
831
            out.write(buf, 0, b);
832
            b = fin.read(buf);
833
          }
834
        } finally {
835
          if (fin != null) fin.close();
836
        }
837

    
838
      } else {
839
        // this is metadata doc
840
        if ( qformat.equals("html") ) { 
841
          response.setContentType("text/html");  //MIME type
842
          PrintWriter out = response.getWriter();
843
    
844
          // Look up the document type
845
          String doctype = doc.getDoctype();
846
          // Transform the document to the new doctype
847
          DBTransform dbt = new DBTransform(conn);
848
          dbt.transformXMLDocument(doc.toString(),
849
                                   doctype,"-//W3C//HTML//EN",out);
850
        } else {
851
          // set content type first
852
          response.setContentType("text/xml");   //MIME type
853
          PrintWriter out = response.getWriter();
854
          doc.toXml(out);
855
        }
856
      
857
      }
858
    } finally {
859
      util.returnConnection(conn);
860
    }
861
    
862
  }
863
  
864
  // read data from URLConnection
865
  private void readFromURLConnection(HttpServletResponse response, String docid)
866
               throws IOException, MalformedURLException
867
  {
868
    ServletOutputStream out = response.getOutputStream(); 
869
    String contentType = getServletContext().getMimeType(docid); //MIME type
870
    if (contentType == null) {
871
      if (docid.endsWith(".xml")) {
872
        contentType="text/xml";
873
      } else if (docid.endsWith(".css")) {
874
        contentType="text/css";
875
      } else if (docid.endsWith(".dtd")) {
876
        contentType="text/plain";
877
      } else if (docid.endsWith(".xsd")) {
878
        contentType="text/xml";
879
      } else if (docid.endsWith("/")) {
880
        contentType="text/html";
881
      } else {
882
        File f = new File(docid);
883
        if ( f.isDirectory() ) {
884
          contentType="text/html";
885
        } else {
886
          contentType="application/octet-stream";
887
        }
888
      }
889
    }
890
    response.setContentType(contentType);
891
    // if we decide to use "application/octet-stream" for all data returns
892
    // response.setContentType("application/octet-stream");
893

    
894
    // this is http url
895
    URL url = new URL(docid);
896
    BufferedInputStream bis = null;
897
    try {
898
      bis = new BufferedInputStream(url.openStream());
899
      byte[] buf = new byte[4 * 1024]; // 4K buffer
900
      int b = bis.read(buf);
901
      while (b != -1) {
902
        out.write(buf, 0, b);
903
        b = bis.read(buf);
904
      }
905
    } finally {
906
      if (bis != null) bis.close();
907
    }
908
    
909
  }
910
  
911
  // read file/doc and write to ZipOutputStream
912
  private void addDocToZip(String docid, ZipOutputStream zout)
913
               throws ClassNotFoundException, IOException, SQLException, 
914
                      McdbException, Exception
915
  {
916
    byte[] bytestring = null;
917
    ZipEntry zentry = null;
918

    
919
    try {
920
      URL url = new URL(docid);
921

    
922
      // this http url; read from URLConnection; add to zip
923
      zentry = new ZipEntry(docid);
924
      zout.putNextEntry(zentry);
925
      BufferedInputStream bis = null;
926
      try {
927
        bis = new BufferedInputStream(url.openStream());
928
        byte[] buf = new byte[4 * 1024]; // 4K buffer
929
        int b = bis.read(buf);
930
        while(b != -1) {
931
          zout.write(buf, 0, b);
932
          b = bis.read(buf);
933
        }
934
      } finally {
935
        if (bis != null) bis.close();
936
      }
937
      zout.closeEntry();
938

    
939
    } catch (MalformedURLException mue) {
940
      
941
      // this is metacat doc (data file or metadata doc)
942
      Connection conn = null;
943
      try {
944
        conn = util.getConnection();
945
        DocumentImpl doc = new DocumentImpl(conn, docid);
946
      
947
        if ( doc.getRootNodeID() == 0 ) {
948
          // this is data file; add file to zip
949
          String filepath = util.getOption("datafilepath");
950
          if(!filepath.endsWith("/")) {
951
            filepath += "/";
952
          }
953
          String filename = filepath + doc.getDocname();
954
          zentry = new ZipEntry(filename);
955
          zout.putNextEntry(zentry);
956
          FileInputStream fin = null;
957
          try {
958
            fin = new FileInputStream(filename);
959
            byte[] buf = new byte[4 * 1024]; // 4K buffer
960
            int b = fin.read(buf);
961
            while (b != -1) {
962
              zout.write(buf, 0, b);
963
              b = fin.read(buf);
964
            }
965
          } finally {
966
            if (fin != null) fin.close();
967
          }
968
          zout.closeEntry();
969

    
970
        } else {
971
          // this is metadata doc; add doc to zip
972
          bytestring = doc.toString().getBytes();
973
          zentry = new ZipEntry(docid + ".xml");
974
          zentry.setSize(bytestring.length);
975
          zout.putNextEntry(zentry);
976
          zout.write(bytestring, 0, bytestring.length);
977
          zout.closeEntry();
978
        }
979
      } finally {
980
        util.returnConnection(conn);
981
      }
982
      
983
    }
984
      
985
  }
986
  
987
  // view abstract within document
988
  private void viewAbstract(HttpServletResponse response,
989
                            String abstractpath, String docid)
990
               throws ClassNotFoundException, IOException, SQLException,
991
                      McdbException, Exception
992
  {
993
    Connection conn = null;
994
    try {
995
      conn = util.getConnection();
996
    
997
      Object[] abstracts = DBQuery.getNodeContent(abstractpath, docid, conn);
998
    
999
      response.setContentType("text/html");  //MIME type
1000
      PrintWriter out = response.getWriter();
1001
      out.println("<html><head><title>Abstract</title></head>");
1002
      out.println("<body bgcolor=\"white\"><h1>Abstract</h1>");
1003
      for (int i=0; i<abstracts.length; i++) {
1004
        out.println("<p>" + (String)abstracts[i] + "</p>");
1005
      }
1006
      out.println("</body></html>");
1007

    
1008
    } finally {
1009
      util.returnConnection(conn);
1010
    }
1011
  }
1012
  // END OF READ SECTION
1013
    
1014
  // INSERT/UPDATE SECTION
1015
  /** 
1016
   * Handle the database putdocument request and write an XML document 
1017
   * to the database connection
1018
   */
1019
  private void handleInsertOrUpdateAction(PrintWriter out, Hashtable params, 
1020
               HttpServletResponse response, String user, String group) {
1021

    
1022
    Connection conn = null;
1023

    
1024
    try {
1025
      // Get the document indicated
1026
      String[] doctext = (String[])params.get("doctext");
1027

    
1028
      String pub = null;
1029
      if (params.containsKey("public")) {
1030
        pub = ((String[])params.get("public"))[0];
1031
      }
1032

    
1033
      StringReader dtd = null;
1034
      if (params.containsKey("dtdtext")) {
1035
        String[] dtdtext = (String[])params.get("dtdtext");
1036
        try {
1037
          if ( !dtdtext[0].equals("") ) {
1038
            dtd = new StringReader(dtdtext[0]);
1039
          }
1040
        } catch (NullPointerException npe) {}
1041
      }
1042
      
1043
      StringReader xml = null;
1044
      boolean validate = false;
1045
      try {
1046
        // look inside XML Document for <!DOCTYPE ... PUBLIC/SYSTEM ... > 
1047
        // in order to decide whether to use validation parser
1048
        validate = validateXML(doctext[0]);
1049
        xml = new StringReader(doctext[0]);
1050

    
1051
        String[] action = (String[])params.get("action");
1052
        String[] docid = (String[])params.get("docid");
1053
        String newdocid = null;
1054

    
1055
        String doAction = null;
1056
        if (action[0].equals("insert")) {
1057
          doAction = "INSERT";
1058
        } else if (action[0].equals("update")) {
1059
          doAction = "UPDATE";
1060
        }
1061

    
1062
        try {
1063
          // get a connection from the pool
1064
          conn = util.getConnection();
1065

    
1066
          // write the document to the database
1067
          try {
1068
            String accNumber = docid[0];
1069
            if (accNumber.equals("")) {
1070
              accNumber = null;
1071
            }
1072
            newdocid = DocumentImpl.write(conn, xml, pub, dtd, doAction,
1073
                                          accNumber, user, group, validate);
1074
          } catch (NullPointerException npe) {
1075
            newdocid = DocumentImpl.write(conn, xml, pub, dtd, doAction,
1076
                                          null, user, group, validate);
1077
          }
1078
        } finally {
1079
          util.returnConnection(conn);
1080
        }    
1081

    
1082
        // set content type and other response header fields first
1083
        response.setContentType("text/xml");
1084
        out.println("<?xml version=\"1.0\"?>");
1085
        out.println("<success>");
1086
        out.println("<docid>" + newdocid + "</docid>"); 
1087
        out.println("</success>");
1088

    
1089
      } catch (NullPointerException npe) {
1090
        response.setContentType("text/xml");
1091
        out.println("<?xml version=\"1.0\"?>");
1092
        out.println("<error>");
1093
        out.println(npe.getMessage()); 
1094
        out.println("</error>");
1095
      }
1096
    } catch (Exception e) {
1097
      response.setContentType("text/xml");
1098
      out.println("<?xml version=\"1.0\"?>");
1099
      out.println("<error>");
1100
      out.println(e.getMessage()); 
1101
      if (e instanceof SAXException) {
1102
        Exception e2 = ((SAXException)e).getException();
1103
        out.println("<error>");
1104
        out.println(e2.getMessage()); 
1105
        out.println("</error>");
1106
      }
1107
      //e.printStackTrace(out);
1108
      out.println("</error>");
1109
    }
1110
  }
1111

    
1112
  /** 
1113
   * Parse XML Document to look for <!DOCTYPE ... PUBLIC/SYSTEM ... > 
1114
   * in order to decide whether to use validation parser
1115
   */
1116
  private static boolean validateXML(String xmltext) throws IOException {
1117
    
1118
    StringReader xmlreader = new StringReader(xmltext);
1119
    StringBuffer cbuff = new StringBuffer();
1120
    java.util.Stack st = new java.util.Stack();
1121
    boolean validate = false;
1122
    int c;
1123
    int inx;
1124
    
1125
    // read from the stream until find the keywords
1126
    while ( (st.empty() || st.size()<4) && ((c = xmlreader.read()) != -1) ) {
1127
      cbuff.append((char)c);
1128

    
1129
      // "<!DOCTYPE" keyword is found; put it in the stack
1130
      if ( (inx = cbuff.toString().indexOf("<!DOCTYPE")) != -1 ) {
1131
        cbuff = new StringBuffer();
1132
        st.push("<!DOCTYPE");
1133
      }
1134
      // "PUBLIC" keyword is found; put it in the stack
1135
      if ( (inx = cbuff.toString().indexOf("PUBLIC")) != -1 ) {
1136
        cbuff = new StringBuffer();
1137
        st.push("PUBLIC");
1138
      }
1139
      // "SYSTEM" keyword is found; put it in the stack
1140
      if ( (inx = cbuff.toString().indexOf("SYSTEM")) != -1 ) {
1141
        cbuff = new StringBuffer();
1142
        st.push("SYSTEM");
1143
      }
1144
      // ">" character is found; put it in the stack
1145
      // ">" is found twice: fisrt from <?xml ...?> 
1146
      // and second from <!DOCTYPE ... >
1147
      if ( (inx = cbuff.toString().indexOf(">")) != -1 ) {
1148
        cbuff = new StringBuffer();
1149
        st.push(">");
1150
      }
1151
    }
1152

    
1153
    // close the stream
1154
    xmlreader.close();
1155

    
1156
    // check the stack whether it contains the keywords:
1157
    // "<!DOCTYPE", "PUBLIC" or "SYSTEM", and ">" in this order
1158
    if ( st.size() == 4 ) {
1159
      if ( ((String)st.pop()).equals(">") &&
1160
           ( ((String)st.peek()).equals("PUBLIC") |
1161
             ((String)st.pop()).equals("SYSTEM") ) &&
1162
           ((String)st.pop()).equals("<!DOCTYPE") )  {
1163
        validate = true;
1164
      }
1165
    }
1166

    
1167
System.out.println("Validation is " + validate);
1168
    return validate;
1169
  }
1170
  // END OF INSERT/UPDATE SECTION
1171

    
1172
  // DELETE SECTION
1173
  /** 
1174
   * Handle the database delete request and delete an XML document 
1175
   * from the database connection
1176
   */
1177
  private void handleDeleteAction(PrintWriter out, Hashtable params, 
1178
               HttpServletResponse response, String user, String group) {
1179

    
1180
    String[] docid = (String[])params.get("docid");
1181
    Connection conn = null;
1182

    
1183
    // delete the document from the database
1184
    try {
1185
      // get a connection from the pool
1186
      conn = util.getConnection();
1187
                                      // NOTE -- NEED TO TEST HERE
1188
                                      // FOR EXISTENCE OF DOCID PARAM
1189
                                      // BEFORE ACCESSING ARRAY
1190
      try { 
1191
        DocumentImpl.delete(conn, docid[0], user, group);
1192
        response.setContentType("text/xml");
1193
        out.println("<?xml version=\"1.0\"?>");
1194
        out.println("<success>");
1195
        out.println("Document deleted."); 
1196
        out.println("</success>");
1197
      } catch (AccessionNumberException ane) {
1198
        response.setContentType("text/xml");
1199
        out.println("<?xml version=\"1.0\"?>");
1200
        out.println("<error>");
1201
        out.println("Error deleting document!!!");
1202
        out.println(ane.getMessage()); 
1203
        out.println("</error>");
1204
      }
1205
    } catch (Exception e) {
1206
      response.setContentType("text/xml");
1207
      out.println("<?xml version=\"1.0\"?>");
1208
      out.println("<error>");
1209
      out.println(e.getMessage()); 
1210
      out.println("</error>");
1211
    } finally {
1212
      util.returnConnection(conn);
1213
    }  
1214
  }
1215
  // END OF DELETE SECTION
1216
  
1217
  // VALIDATE SECTION
1218
  /** 
1219
   * Handle the validation request and return the results to the requestor
1220
   */
1221
  private void handleValidateAction(PrintWriter out, Hashtable params, 
1222
               HttpServletResponse response) {
1223

    
1224
    // Get the document indicated
1225
    String valtext = null;
1226
    
1227
    try {
1228
      valtext = ((String[])params.get("valtext"))[0];
1229
    } catch (Exception nullpe) {
1230

    
1231
      Connection conn = null;
1232
      String docid = null;
1233
      try {
1234
        // Find the document id number
1235
        docid = ((String[])params.get("docid"))[0]; 
1236

    
1237
        // get a connection from the pool
1238
        conn = util.getConnection();
1239

    
1240
        // Get the document indicated from the db
1241
        DocumentImpl xmldoc = new DocumentImpl(conn, docid);
1242
        valtext = xmldoc.toString();
1243

    
1244
      } catch (NullPointerException npe) {
1245
        response.setContentType("text/xml");
1246
        out.println("<error>Error getting document ID: " + docid + "</error>");
1247
        if ( conn != null ) { util.returnConnection(conn); }
1248
        return;
1249
      } catch (Exception e) {
1250
        response.setContentType("text/html");
1251
        out.println(e.getMessage()); 
1252
      } finally {
1253
        util.returnConnection(conn);
1254
      }  
1255
    }
1256

    
1257
    Connection conn = null;
1258
    try {
1259
      // get a connection from the pool
1260
      conn = util.getConnection();
1261
      DBValidate valobj = new DBValidate(saxparser,conn);
1262
      boolean valid = valobj.validateString(valtext);
1263

    
1264
      // set content type and other response header fields first
1265
      response.setContentType("text/xml");
1266
      out.println(valobj.returnErrors());
1267

    
1268
    } catch (NullPointerException npe2) {
1269
      // set content type and other response header fields first
1270
      response.setContentType("text/xml");
1271
      out.println("<error>Error validating document.</error>"); 
1272
    } catch (Exception e) {
1273
      response.setContentType("text/html");
1274
      out.println(e.getMessage()); 
1275
    } finally {
1276
      util.returnConnection(conn);
1277
    }  
1278
  }
1279
  // END OF VALIDATE SECTION
1280
 
1281
  // OTHER ACTION HANDLERS
1282
  /**
1283
   * sends the port number that the data socket is running on.
1284
   * This is a parameter set in the metacat.properties file.
1285
   */
1286
  private void handleGetDataPortAction(PrintWriter out, Hashtable params, 
1287
                                       HttpServletResponse response, 
1288
                                       String username, String groupname,
1289
                                       String sess_id)
1290
  {
1291
    int port;
1292
    String filedir = null;
1293
    try
1294
    {
1295
      filedir = util.getOption("datafilepath");
1296
      
1297
      Random r = new Random();
1298
      port = r.nextInt(65000);  //pick a random port between 0-65000
1299
      //System.out.println("random port is: " + port);
1300
      while(!DataFileServer.portIsAvailable(port))
1301
      {
1302
        port = r.nextInt(65000);
1303
        //System.out.println("next port used: " + port);
1304
      }
1305
      DataFileServer dfs = new DataFileServer(port, username, sess_id);
1306
      dfs.start();
1307
      
1308
      //System.out.println("filedir: " + filedir);
1309
      //System.out.println("port: " + port);
1310
      response.setContentType("text/xml");
1311
      out.println("<?xml version=\"1.0\"?>");
1312
      out.println("<port>");
1313
      out.print(port);
1314
      out.print("</port>");
1315
      
1316
    }
1317
	  catch (Exception e) 
1318
    {
1319
      System.out.println("error in MetacatServlet.handleGetDataPortAction: " + 
1320
                          e.getMessage());
1321
    }
1322
  }
1323
  
1324
  /** 
1325
   * Handle "getaccesscontrol" action.
1326
   * Read Access Control List from db connection in XML format
1327
   */
1328
  private void handleGetAccessControlAction(PrintWriter out, Hashtable params, 
1329
                                       HttpServletResponse response, 
1330
                                       String username, String groupname) {
1331

    
1332
    Connection conn = null;
1333
    String docid = ((String[])params.get("docid"))[0];
1334
    
1335
    try {
1336

    
1337
        // get connection from the pool
1338
        conn = util.getConnection();
1339
        AccessControlList aclobj = new AccessControlList(conn);
1340
        String acltext = aclobj.getACL(docid, username, groupname);
1341
        out.println(acltext);
1342

    
1343
    } catch (Exception e) {
1344
      out.println("<?xml version=\"1.0\"?>");
1345
      out.println("<error>");
1346
      out.println(e.getMessage());
1347
      out.println("</error>");
1348
    } finally {
1349
      util.returnConnection(conn);
1350
    }  
1351
    
1352
  }
1353

    
1354
  /** 
1355
   * Handle the "getprincipals" action.
1356
   * Read all principals from authentication scheme in XML format
1357
   */
1358
  private void handleGetPrincipalsAction(PrintWriter out, String user,
1359
                                         String password) {
1360

    
1361
    Connection conn = null;
1362

    
1363
    try {
1364

    
1365
        // get connection from the pool
1366
        AuthSession auth = new AuthSession();
1367
        String principals = auth.getPrincipals(user, password);
1368
        out.println(principals);
1369

    
1370
    } catch (Exception e) {
1371
      out.println("<?xml version=\"1.0\"?>");
1372
      out.println("<error>");
1373
      out.println(e.getMessage());
1374
      out.println("</error>");
1375
    } finally {
1376
      util.returnConnection(conn);
1377
    }  
1378
    
1379
  }
1380

    
1381
  /** 
1382
   * Handle "getdoctypes" action.
1383
   * Read all doctypes from db connection in XML format
1384
   */
1385
  private void handleGetDoctypesAction(PrintWriter out, Hashtable params, 
1386
                                       HttpServletResponse response) {
1387

    
1388
    Connection conn = null;
1389
    
1390
    try {
1391

    
1392
        // get connection from the pool
1393
        conn = util.getConnection();
1394
        DBUtil dbutil = new DBUtil(conn);
1395
        String doctypes = dbutil.readDoctypes();
1396
        out.println(doctypes);
1397

    
1398
    } catch (Exception e) {
1399
      out.println("<?xml version=\"1.0\"?>");
1400
      out.println("<error>");
1401
      out.println(e.getMessage());
1402
      out.println("</error>");
1403
    } finally {
1404
      util.returnConnection(conn);
1405
    }  
1406
    
1407
  }
1408

    
1409
  /** 
1410
   * Handle the "getdtdschema" action.
1411
   * Read DTD or Schema file for a given doctype from Metacat catalog system
1412
   */
1413
  private void handleGetDTDSchemaAction(PrintWriter out, Hashtable params,
1414
                                        HttpServletResponse response) {
1415

    
1416
    Connection conn = null;
1417
    String doctype = null;
1418
    String[] doctypeArr = (String[])params.get("doctype");
1419

    
1420
    // get only the first doctype specified in the list of doctypes
1421
    // it could be done for all doctypes in that list
1422
    if (doctypeArr != null) {
1423
        doctype = ((String[])params.get("doctype"))[0]; 
1424
    }
1425

    
1426
    try {
1427

    
1428
        // get connection from the pool
1429
        conn = util.getConnection();
1430
        DBUtil dbutil = new DBUtil(conn);
1431
        String dtdschema = dbutil.readDTDSchema(doctype);
1432
        out.println(dtdschema);
1433

    
1434
    } catch (Exception e) {
1435
      out.println("<?xml version=\"1.0\"?>");
1436
      out.println("<error>");
1437
      out.println(e.getMessage());
1438
      out.println("</error>");
1439
    } finally {
1440
      util.returnConnection(conn);
1441
    }  
1442
    
1443
  }
1444

    
1445
  /** 
1446
   * Handle the "getdataguide" action.
1447
   * Read Data Guide for a given doctype from db connection in XML format
1448
   */
1449
  private void handleGetDataGuideAction(PrintWriter out, Hashtable params, 
1450
                                        HttpServletResponse response) {
1451

    
1452
    Connection conn = null;
1453
    String doctype = null;
1454
    String[] doctypeArr = (String[])params.get("doctype");
1455

    
1456
    // get only the first doctype specified in the list of doctypes
1457
    // it could be done for all doctypes in that list
1458
    if (doctypeArr != null) {
1459
        doctype = ((String[])params.get("doctype"))[0]; 
1460
    }
1461

    
1462
    try {
1463

    
1464
        // get connection from the pool
1465
        conn = util.getConnection();
1466
        DBUtil dbutil = new DBUtil(conn);
1467
        String dataguide = dbutil.readDataGuide(doctype);
1468
        out.println(dataguide);
1469

    
1470
    } catch (Exception e) {
1471
      out.println("<?xml version=\"1.0\"?>");
1472
      out.println("<error>");
1473
      out.println(e.getMessage());
1474
      out.println("</error>");
1475
    } finally {
1476
      util.returnConnection(conn);
1477
    }  
1478
    
1479
  }
1480

    
1481
}
(32-32/43)