Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 1.

Slides:



Advertisements
Similar presentations
Hypertext Transfer PROTOCOL ----HTTP Sen Wang CSE5232 Network Programming.
Advertisements

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12 of the corporate.
Copyright © 2014 Oracle and/or its affiliates. All rights reserved. | Your customer as a segment of one That changes every second! Hein Van Der Merwe Chief.
MVC in JavaEE 8 Manfred Riem Principal Member of Technical Staff September, 2014 Copyright © 2014, Oracle and/or its affiliates. All rights reserved.
Internet of Things Security Architecture
Copyright © 2012, Oracle and/or its affiliates. All rights reserved.Public 1 JavaScript/HTML5 Rich Clients Using Java EE 7 Reza Rahman Java EE/GlassFish.
BASIC CRYPTOGRAPHY CONCEPT. Secure Socket Layer (SSL)  SSL was first used by Netscape.  To ensure security of data sent through HTTP, LDAP or POP3.
Rensselaer Polytechnic Institute CSCI-4220 – Network Programming David Goldschmidt, Ph.D.
HTTP Cookies. CPSC Application Layer 2 User-server state: cookies Many major Web sites use cookies Four components: 1) cookie header line of HTTP.
Securing web applications using Java EE Dr Jim Briggs 1.
A Java Architecture for the Internet of Things Noel Poore, Architect Pete St. Pierre, Product Manager Java Platform Group, Internet of Things September.
Martin Kruliš by Martin Kruliš (v1.0)1.
Copyright © 2014, Oracle and/or its affiliates. All rights reserved. | Advanced Metadata Modeling Modeling for the Oracle Business Intelligence Cloud.
The Safe Harbor The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated.
Best Practices for Upgrading Oracle PeopleSoft Environments
Copyright © 2015, Oracle and/or its affiliates. All rights reserved. | Title Slide without Picture Subtitle Presenter’s Name Presenter’s Title Organization,
Android and iOS Development with JAX-RS, WebSocket , and Java EE 7
Copyright © 2015, Oracle and/or its affiliates. All rights reserved. JD Edwards Summit The Newest JDE Module – Rental Management Joel Sandberg Sales Consultant.
Copyright © 2012, Oracle and/or its affiliates. All rights reserved. 1.
Copyright © 2015, Oracle and/or its affiliates. All rights reserved. JD Edwards Summit PaaS from an Applications Perspective Charles McGuinness Director,
1 WebSocket & JSON Java APIs Hackday By Somay David
WebSockets [intro].
Rensselaer Polytechnic Institute CSCI-4220 – Network Programming David Goldschmidt, Ph.D.
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12 1.
1Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 8 Reporting from Contract.
1 What Can HTML5 WebSocket Do For You? Sidda Eraiah Director of Management Services Kaazing Corporation.
Oracle E-Business Suite Order Management: Presenting the HTML and Mobile User Experience Durgaprasad Bodapati Director, Product Management Bhavana Sharma.
Oracle Application Express 3.0 Joel R. Kallman Software Development Manager.
What Is New and Noteworthy in Jersey Miroslav Fuksa, Jakub Podlešák Software Developers Oracle, Application Server Group October 1, 2014 Copyright ©
Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 1.
Copyright © 2014, Oracle and/or its affiliates. All rights reserved. An Auto-Join Network of Things Wong, H. and Wesson, B. Oracle Confidential – Internal/Restricted/Highly.
1Copyright © 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 8 Contract Management.
Web Security : Secure Socket Layer Secure Electronic Transaction.
CSCE 815 Network Security Lecture 26 SSH and SSH Implementation April 24, 2003.
Copyright © 2015, Oracle and/or its affiliates. All rights reserved. JD Edwards Summit Really Cool Demo Stuff – 2015 Edition!!!!! For demo content, please.
1 82 nd IETF meeting NETCONF over WebSocket ( ) Tomoyuki Iijima, (Hitachi) Hiroyasu Kimura,
HTML5 Websockets Norman White Websockets The HTTP protocol is not designed for a continuous connection between the client and the server, but rather.
1 ObjectRiver Metadata Compilers Programmatic WebSockets JavaOne 2014 – Steven Lemmo.
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12 1.
RIA and Web2.0 Development with no Coding Juan Camilo Ruiz Senior Product Manager Development Tools.
RESTful Microservices In Java With Jersey Jakub Podlešák Software Engineer Oracle, Application Server Group September 29, 2014 Copyright © 2014, Oracle.
Copyright © 2014, Oracle and/or its affiliates. All rights reserved. | Planning & Budgeting Cloud Service (PBCS) Overview Business Analytics Product Group.
Using WebSockets in Web apps Presenter: Shahzad Badar.
HTTP protocol Java Servlets. HTTP protocol Web system communicates with end-user via HTTP protocol HTTP protocol methods: GET, POST, HEAD, PUT, OPTIONS,
Java Programming: Advanced Topics 1 Building Web Applications Chapter 13.
Copyright © 2014, Oracle and/or its affiliates. All rights reserved. | Think Async Masoud Kalali, Software Engineer, Embrace and.
Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12 1.
© 2010 IBM Corporation RESTFul Service Modelling in Rational Software Architect April, 2011.
Copyright © 2016, Oracle and/or its affiliates. All rights reserved. | What You Need to Know About User Defined Objects (UDOs) With Tools Release 9.2.
Copyright © 2012, Oracle and/or its affiliates. All rights reserved.Insert Information Protection Policy Classification from Slide 13 1.
Research of Web Real-Time Communication Based on WebSocket
CS5220 Advanced Topics in Web Programming Introduction to WebSocket
Advanced Communication in Web Technologies
Websocket Application
Web Programming Developing Web Applications including Servlets, and Web Services using NetBeans 6.5 with GlassFish.V3.
Node.js Express Web Services
Visit for more Learning Resources
Building real-time web apps with WebSockets using IIS, ASP.NET and WCF
WebSocket: Full-Duplex Solution for the Web
Build a Web App with Oracle REST Data Services &
OpenWorld 2018 How to Combine Data from Source Sites
Transport Protocols Relates to Lab 5. An overview of the transport protocols of the TCP/IP protocol suite. Also, a short discussion of UDP.
WEB API.
Project Helidon Deep Dive
Building real-time web apps with HTML5 WebSockets
OpenWorld 2018 Oracle API Platform: How to Manage Typical Workflows
Web Socket Protocol.
Part II Application Layer.
Presentation transcript:

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 1

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 2 Building WebSocket Apps in Java using JSR 356 Arun Gupta To fill a shape with an image. 1.Use existing picture box, DO NOT delete and create new picture box. 2.Right click on the shape. 3.At the bottom of the submenu select “Format Shape” 4.Select “Fill” at the top of the “Format Shape” dialog box. 5.Select “Picture or Texture fill” from the options. 6.And select “File” under the “Insert from” option. 7.Navigate to the file you want to use and select “Insert” 8.On the “Format” tab, in the Size group, click on “Crop to Fill” in the Crop tool and drag the image bounding box to the desired size 9.DELETE THIS INSTRUCTION NOTE WHEN NOT IN USE

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 3 The preceding is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle.

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 4 Agenda  Primer on WebSocket  JSR 356: Java API for WebSocket

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 5 Interactive Web Sites  HTTP is half-duplex  HTTP is verbose  Hacks for Server Push – Polling – Long Polling – Comet/Ajax  Complex, Inefficient, Wasteful

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 6 WebSocket to the Rescue  TCP based, bi-directional, full-duplex messaging  Originally proposed as part of HTML5  IETF-defined Protocol: RFC 6455 – Handshake – Data Transfer  W3C defined JavaScript API – Candidate Recommendation

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 7 What’s the basic idea ?  Upgrade HTTP to upgrade to WebSocket – Single TCP connection – Transparent to proxies, firewalls, and routers  Send data frames in both direction (Bi-directional) – No headers, cookies, authentication – No security overhead – “ping”/”pong” frames for keep-alive  Send message independent of each other (Full Duplex)  End the connection

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 8 Establish a connection Client Handshake Request Handshake Response Server

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 9 Handshake Request GET /chat HTTP/1.1 Host: server.example.com Upgrade: websocket Connection: Upgrade Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ== Origin: Sec-WebSocket-Protocol: chat, superchat Sec-WebSocket-Version: 13

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Handshake Response HTTP/ Switching Protocols Upgrade: websocket Connection: Upgrade Sec-WebSocket-Accept: s3pPLMBiTxaQ9kYGzzhZRbK+xOo= Sec-WebSocket-Protocol: chat

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Server Client Handshake Request Handshake Response Connected ! Establishing a Connection

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Peer (server) Peer (client) Connected ! open close message error message Disconnected WebSocket Lifecycle

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide WebSocket API

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Browser Support

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide JSR 356 Specification  Standard Java API for creating WebSocket Applications  Transparent Expert Group – jcp.org/en/jsr/detail?id=356 jcp.org/en/jsr/detail?id=356 – java.net/projects/websocket-spec java.net/projects/websocket-spec  FINAL: Part of Java EE 7

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide JSR 356: Reference Implementation  Tyrus: java.net/projects/tyrusjava.net/projects/tyrus  Open source and transparent  Integrated in GlassFish 4

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Java API for WebSocket Features  API for WebSocket Server and Client Endpoint – Programmatic: Endpoint  WebSocket opening handshake negotiation  Lifecycle callback methods  Integration with Java EE technologies

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Hello World and Basics POJO

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Hello World Annotated Endpoint import public class HelloBean public String sayHello(String name) { return “Hello “ + name; } }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Annotations classTurns a POJO into a Server classTurns a POJO into a Client methodIntercepts WebSocket Message method parameter Flags a matched path segment of a methodIntercepts WebSocket Open methodIntercepts WebSocket Close methodIntercepts errors during a conversation

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 attributes value Relative URI or URI template e.g. “/hello” or “/chat/{subscriber-level}” decoders list of message decoder classnames encoders list of message encoder classnames subprotocols list of the names of the supported subprotocols

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Custom value="/hello", decoders={MyMessageDecoder.class}, encoders={MyMessageEncoder.class} ) public class MyEndpoint {... }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Custom Payloads – Text Decoder public class MyMessageDecoder implements Decoder.Text { public MyMessage decode(String s) { JsonObject jsonObject = Json.createReader(…).readObject(); return new MyMessage(jsonObject); } public boolean willDecode(String string) {... return true; // Only if can process the payload }... }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Custom Payloads – Text Encoder public class MyMessageEncoder implements Encoder.Text { public String encode(MyMessage myMessage) { return myMessage.jsonObject.toString(); }... }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Custom Payloads – Binary Decoder public class MyMessageDecoder implements Decoder.Binary { public MyMessage decode(byte[] bytes) {... return myMessage; } public boolean willDecode(byte[] bytes) {... return true; // Only if can process the payload }... }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Which methods can ?  Exactly one of the following – Text: String, Java primitive or equivalent class, String and boolean, Reader, any type for which there is a decoder – Binary: byte[], ByteBuffer, byte[] and boolean, ByteBuffer and boolean, InptuStream, any type for which there is a decoder – Pong messages: PongMessage  An optional Session parameter  0..n String parameters annotated  Return type: String, byte[], ByteBuffer, Java primitive or class equivalent or any type for which there is a encoder

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Sample Messages  void m(String s);  void m(Float id);  Product m(Reader reader, Session s);  void m(byte[] b); or void m(ByteBuffer b);  Book m(int i, Session store);

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Chat public class ChatBean { static Set peers = public void onOpen(Session peer) { peers.add(peer); public void onClose(Session peer) { peers.remove(peer); }...

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Chat public void message(String message, Session client) { for (Session peer : peers) { peer.getBasicRemote().sendObject(message); } } }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide URI Template Matching  Level 1 public class MyEndpoint public void orderId) {... } }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide WebSocket public class HelloClient public void message(String message, Session session) { // process message from server } } WebSocketContainer c = ContainerProvider.getWebSocketContainer(); c.connectToServer(HelloClient.class, “hello”);

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Hello World and Basics Non-POJO

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Programmatic Endpoint public class MyEndpoint extends Endpoint public void onOpen(Session session) { session.addMessageHandler(new MessageHandler.Text() { public void onMessage(String name) { try { session.getBasicRemote().sendText(“Hello “ + name); } catch (IOException ex) { } } }); } }

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Interface-driven Endpoint ServerEndpointConfiguration config = ServerEndpointConfigurationBuilder.create(MyEndpoint.class, “/foo”).build(); Server Packaging

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Server and Client Configuration  Server – URI matching algorithm – Subprotocol and extension negotiation – Message encoders and decoders – Origin check – Handshake response  Client – Requested subprotocols and extensions – Message encoders and decoders – Request URI

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Relationship with Dependency Injection  Full Dependency Injection support required in endpoints – Field, method, constructor injection  Interceptors permitted too

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Relationship with Servlet 3.1  Allows a portable way to upgrade HTTP request  New API – HttpServletRequest.upgrade(ProtocolHandler handler)

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Security  Authenticates using Servlet security mechanism during opening handshake – Endpoint mapped by ws:// is protected using security model defined using the corresponding URI  Authorization defined using – TBD: Add/reuse security annotations  Transport Confidentiality using wss:// – Access allowed over encrypted connection only

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide How to view WebSocket messages ? Capture traffic on loopback

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide How to view WebSocket messages ? chrome://net-internals -> Sockets -> View live sockets

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Resources  Specification – JSR: jcp.org/en/jsr/detail?id=356jcp.org/en/jsr/detail?id=356 – Mailing Lists, JIRA, Archive: java.net/projects/websocket-specjava.net/projects/websocket-spec – FINAL: Part of Java EE 7  Reference Implementation – Tyrus: java.net/projects/tyrusjava.net/projects/tyrus – Integrated in GlassFish 4

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide Q & A

Copyright © 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 13 43