001/*
002 * (C) Copyright 2012-2014 Nuxeo SA (http://nuxeo.com/) and others.
003 *
004 * Licensed under the Apache License, Version 2.0 (the "License");
005 * you may not use this file except in compliance with the License.
006 * You may obtain a copy of the License at
007 *
008 *     http://www.apache.org/licenses/LICENSE-2.0
009 *
010 * Unless required by applicable law or agreed to in writing, software
011 * distributed under the License is distributed on an "AS IS" BASIS,
012 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
013 * See the License for the specific language governing permissions and
014 * limitations under the License.
015 *
016 * Contributors:
017 *      Vladimir Pasquier <vpasquier@nuxeo.com>
018 *      Mickael Vachette <mv@nuxeo.com>
019 *      Estelle Giuly <egiuly@nuxeo.com>
020 */
021package org.nuxeo.ecm.platform.signature.core.operations;
022
023import org.nuxeo.ecm.automation.OperationContext;
024import org.nuxeo.ecm.automation.OperationException;
025import org.nuxeo.ecm.automation.core.Constants;
026import org.nuxeo.ecm.automation.core.annotations.Context;
027import org.nuxeo.ecm.automation.core.annotations.Operation;
028import org.nuxeo.ecm.automation.core.annotations.OperationMethod;
029import org.nuxeo.ecm.automation.core.annotations.Param;
030import org.nuxeo.ecm.core.api.Blob;
031import org.nuxeo.ecm.core.api.DocumentModel;
032import org.nuxeo.ecm.core.api.NuxeoPrincipal;
033import org.nuxeo.ecm.core.api.blobholder.BlobHolder;
034import org.nuxeo.ecm.platform.signature.api.sign.SignatureService;
035import org.nuxeo.ecm.platform.signature.api.sign.SignatureService.SigningDisposition;
036import org.nuxeo.ecm.platform.signature.core.sign.SignatureHelper;
037import org.nuxeo.ecm.platform.usermanager.UserManager;
038
039@Operation(id = SignPDFDocument.ID, category = Constants.CAT_SERVICES, label = "Sign PDF", description = "Applies a digital signature to the"
040        + " PDF blob of the input document.")
041public class SignPDFDocument {
042
043    public static final String ID = "Services.SignPDFDocument";
044
045    private static final String MIME_TYPE_PDF = "application/pdf";
046
047    @Context
048    protected OperationContext ctx;
049
050    @Context
051    protected UserManager userManager;
052
053    @Context
054    protected SignatureService signatureService;
055
056    @Param(name = "username", required = true, description = "The user ID for" + " signing PDF document.")
057    protected String username;
058
059    @Param(name = "password", required = true, description = "Certificate " + "password.")
060    protected String password;
061
062    @Param(name = "reason", required = true, description = "Signature reason.")
063    protected String reason;
064
065    @OperationMethod
066    public Blob run(DocumentModel doc) throws OperationException {
067        if (!(ctx.getPrincipal() instanceof NuxeoPrincipal)
068                || !((NuxeoPrincipal) ctx.getPrincipal()).isAdministrator()) {
069            throw new OperationException("Not allowed. You must be administrator to use this operation");
070        }
071        DocumentModel user = userManager.getUserModel(username);
072        Blob originalBlob = doc.getAdapter(BlobHolder.class).getBlob();
073        boolean originalIsPdf = MIME_TYPE_PDF.equals(originalBlob.getMimeType());
074        // decide if we want PDF/A
075        boolean pdfa = SignatureHelper.getPDFA();
076        // decide disposition
077        SigningDisposition disposition = SignatureHelper.getDisposition(originalIsPdf);
078        // decide archive filename
079        String filename = originalBlob.getFilename();
080        String archiveFilename = SignatureHelper.getArchiveFilename(filename);
081        return signatureService.signDocument(doc, user, password, reason, pdfa, disposition, archiveFilename);
082    }
083}