From bd2623d9131d9521a2b7c924b647a9c1c8916732 Mon Sep 17 00:00:00 2001 From: "Edward M. Kagan" Date: Thu, 9 Apr 2020 12:15:21 +0300 Subject: [PATCH] Intial --- cayenne/deployment/pom.xml | 53 +++ .../quarkus/cayenne/CayenneProcessor.java | 36 ++ cayenne/pom.xml | 22 ++ cayenne/runtime/pom.xml | 67 ++++ .../pagan/quarkus/cayenne/CayenneConfig.java | 26 ++ .../quarkus/cayenne/CayenneRecorder.java | 16 + .../pagan/quarkus/cayenne/CayenneSupport.java | 50 +++ demo/.dockerignore | 4 + demo/.gitignore | 35 ++ demo/.mvn/wrapper/MavenWrapperDownloader.java | 117 +++++++ demo/.mvn/wrapper/maven-wrapper.jar | Bin 0 -> 50710 bytes demo/.mvn/wrapper/maven-wrapper.properties | 2 + demo/README.md | 30 ++ demo/mvnw | 310 ++++++++++++++++++ demo/mvnw.cmd | 182 ++++++++++ demo/pom.xml | 126 +++++++ demo/src/main/docker/Dockerfile.jvm | 47 +++ demo/src/main/docker/Dockerfile.native | 30 ++ .../java/org/pagan/janitor/LoginResource.java | 39 +++ .../pagan/janitor/TokenSecuredResource.java | 123 +++++++ .../org/pagan/janitor/session/DemoCache.java | 59 ++++ .../resources/META-INF/resources/index.html | 19 ++ .../src/main/resources/application.properties | 29 ++ .../jwt/NativeTokenSecuredResourceIT.java | 9 + .../jwt/TokenSecuredResourceTest.java | 21 ++ janitor/deployment/.classpath | 33 ++ janitor/deployment/.project | 23 ++ .../org.eclipse.core.resources.prefs | 5 + .../.settings/org.eclipse.jdt.core.prefs | 6 + .../.settings/org.eclipse.m2e.core.prefs | 4 + janitor/deployment/pom.xml | 63 ++++ .../java/pagan/janitor/JanitorProcessor.java | 54 +++ janitor/pom.xml | 22 ++ janitor/runtime/.classpath | 27 ++ janitor/runtime/.project | 23 ++ .../org.eclipse.core.resources.prefs | 3 + .../.settings/org.eclipse.jdt.core.prefs | 6 + .../.settings/org.eclipse.m2e.core.prefs | 4 + janitor/runtime/pom.xml | 97 ++++++ .../java/org/pagan/janitor/JanitorConfig.java | 79 +++++ .../org/pagan/janitor/JanitorRecorder.java | 35 ++ .../org/pagan/janitor/cache/SessionCache.java | 15 + .../janitor/cache/SessionCacheConfig.java | 25 ++ .../pagan/janitor/cache/SessionCacheImpl.java | 77 +++++ .../org/pagan/janitor/cache/SessionInfo.java | 79 +++++ .../security/JanitorAuthMechanism.java | 94 ++++++ .../JanitorAuthenticationRequest.java | 76 +++++ .../security/JanitorIdentityProvider.java | 112 +++++++ .../security/JanitorPrincipalProducer.java | 76 +++++ jedis/.gitignore | 124 +++++++ jedis/deployment/pom.xml | 58 ++++ .../pagan/quarkus/jedis/JedisProccessor.java | 58 ++++ jedis/pom.xml | 22 ++ jedis/runtime/pom.xml | 77 +++++ .../org/pagan/quarkus/jedis/JedisConfig.java | 38 +++ .../pagan/quarkus/jedis/JedisRecorder.java | 16 + .../org/pagan/quarkus/jedis/JedisSupport.java | 59 ++++ pom.xml | 47 +++ 58 files changed, 2989 insertions(+) create mode 100644 cayenne/deployment/pom.xml create mode 100644 cayenne/deployment/src/main/java/org/pagan/quarkus/cayenne/CayenneProcessor.java create mode 100644 cayenne/pom.xml create mode 100644 cayenne/runtime/pom.xml create mode 100644 cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneConfig.java create mode 100644 cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneRecorder.java create mode 100644 cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneSupport.java create mode 100644 demo/.dockerignore create mode 100644 demo/.gitignore create mode 100644 demo/.mvn/wrapper/MavenWrapperDownloader.java create mode 100644 demo/.mvn/wrapper/maven-wrapper.jar create mode 100644 demo/.mvn/wrapper/maven-wrapper.properties create mode 100644 demo/README.md create mode 100755 demo/mvnw create mode 100644 demo/mvnw.cmd create mode 100644 demo/pom.xml create mode 100644 demo/src/main/docker/Dockerfile.jvm create mode 100644 demo/src/main/docker/Dockerfile.native create mode 100644 demo/src/main/java/org/pagan/janitor/LoginResource.java create mode 100644 demo/src/main/java/org/pagan/janitor/TokenSecuredResource.java create mode 100644 demo/src/main/java/org/pagan/janitor/session/DemoCache.java create mode 100644 demo/src/main/resources/META-INF/resources/index.html create mode 100644 demo/src/main/resources/application.properties create mode 100644 demo/src/test/java/org/acme/security/jwt/NativeTokenSecuredResourceIT.java create mode 100644 demo/src/test/java/org/acme/security/jwt/TokenSecuredResourceTest.java create mode 100644 janitor/deployment/.classpath create mode 100644 janitor/deployment/.project create mode 100644 janitor/deployment/.settings/org.eclipse.core.resources.prefs create mode 100644 janitor/deployment/.settings/org.eclipse.jdt.core.prefs create mode 100644 janitor/deployment/.settings/org.eclipse.m2e.core.prefs create mode 100644 janitor/deployment/pom.xml create mode 100644 janitor/deployment/src/main/java/pagan/janitor/JanitorProcessor.java create mode 100644 janitor/pom.xml create mode 100644 janitor/runtime/.classpath create mode 100644 janitor/runtime/.project create mode 100644 janitor/runtime/.settings/org.eclipse.core.resources.prefs create mode 100644 janitor/runtime/.settings/org.eclipse.jdt.core.prefs create mode 100644 janitor/runtime/.settings/org.eclipse.m2e.core.prefs create mode 100644 janitor/runtime/pom.xml create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/JanitorConfig.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/JanitorRecorder.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCache.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheConfig.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheImpl.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionInfo.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthMechanism.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthenticationRequest.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorIdentityProvider.java create mode 100644 janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorPrincipalProducer.java create mode 100644 jedis/.gitignore create mode 100644 jedis/deployment/pom.xml create mode 100644 jedis/deployment/src/main/java/org/pagan/quarkus/jedis/JedisProccessor.java create mode 100644 jedis/pom.xml create mode 100644 jedis/runtime/pom.xml create mode 100644 jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisConfig.java create mode 100644 jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisRecorder.java create mode 100644 jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisSupport.java create mode 100644 pom.xml diff --git a/cayenne/deployment/pom.xml b/cayenne/deployment/pom.xml new file mode 100644 index 0000000..bce3719 --- /dev/null +++ b/cayenne/deployment/pom.xml @@ -0,0 +1,53 @@ + + + 4.0.0 + + + org.pagan.quarkus + cayenne-parent + 1.0-SNAPSHOT + + + cayenne-deployment + ${project.artifactId} + + + + io.quarkus + quarkus-core-deployment + ${quarkus.platform.version} + + + io.quarkus + quarkus-agroal-deployment + ${quarkus.platform.version} + + + org.pagan.quarkus + cayenne + 1.0-SNAPSHOT + + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + \ No newline at end of file diff --git a/cayenne/deployment/src/main/java/org/pagan/quarkus/cayenne/CayenneProcessor.java b/cayenne/deployment/src/main/java/org/pagan/quarkus/cayenne/CayenneProcessor.java new file mode 100644 index 0000000..c8b3004 --- /dev/null +++ b/cayenne/deployment/src/main/java/org/pagan/quarkus/cayenne/CayenneProcessor.java @@ -0,0 +1,36 @@ +package org.pagan.quarkus.cayenne; + +import io.quarkus.arc.deployment.AdditionalBeanBuildItem; +import io.quarkus.arc.deployment.BeanContainerBuildItem; +import io.quarkus.deployment.annotations.BuildProducer; +import io.quarkus.deployment.annotations.BuildStep; +import io.quarkus.deployment.annotations.ExecutionTime; +import io.quarkus.deployment.annotations.Record; +import io.quarkus.deployment.builditem.FeatureBuildItem; +import io.quarkus.deployment.builditem.ServiceStartBuildItem; +import io.quarkus.deployment.builditem.ShutdownContextBuildItem; + +public class CayenneProcessor { + + private CayenneConfig config; + + @BuildStep + FeatureBuildItem feature() { + System.out.println("CayenneProcessor - feature"); + return new FeatureBuildItem("cayenne"); + } + + @BuildStep + AdditionalBeanBuildItem beans() { + System.out.println("CayenneProcessor - beans"); + return AdditionalBeanBuildItem.unremovableOf(CayenneSupport.class); + } + + @Record(ExecutionTime.RUNTIME_INIT) + @BuildStep + void build(CayenneRecorder recorder, BuildProducer serviceStart, BeanContainerBuildItem beanContainer, ShutdownContextBuildItem shutdownContext) { + System.out.println("CayenneProcessor - build"); + recorder.initialize(config, beanContainer.getValue(), shutdownContext); + serviceStart.produce(new ServiceStartBuildItem("cayenne")); + } +} diff --git a/cayenne/pom.xml b/cayenne/pom.xml new file mode 100644 index 0000000..094decd --- /dev/null +++ b/cayenne/pom.xml @@ -0,0 +1,22 @@ + + + 4.0.0 + + + org.pagan.quarkus + extensions + 1.0-SNAPSHOT + + + cayenne-parent + ${project.artifactId} + pom + + + deployment + runtime + + + diff --git a/cayenne/runtime/pom.xml b/cayenne/runtime/pom.xml new file mode 100644 index 0000000..3db21cb --- /dev/null +++ b/cayenne/runtime/pom.xml @@ -0,0 +1,67 @@ + + + 4.0.0 + + + org.pagan.quarkus + cayenne-parent + 1.0-SNAPSHOT + + + cayenne + ${project.artifactId} + + + + io.quarkus + quarkus-core + ${quarkus.platform.version} + + + io.quarkus + quarkus-agroal + ${quarkus.platform.version} + + + org.apache.cayenne + cayenne-server + ${cayenne.version} + + + + + + + io.quarkus + quarkus-bootstrap-maven-plugin + ${quarkus.platform.version} + + + + extension-descriptor + + + ${project.groupId}:${project.artifactId}-deployment:${project.version} + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + \ No newline at end of file diff --git a/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneConfig.java b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneConfig.java new file mode 100644 index 0000000..47a1d92 --- /dev/null +++ b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneConfig.java @@ -0,0 +1,26 @@ +package org.pagan.quarkus.cayenne; + +import io.quarkus.runtime.annotations.ConfigItem; +import io.quarkus.runtime.annotations.ConfigPhase; +import io.quarkus.runtime.annotations.ConfigRoot; + +/** + * Quarkus Apache Cayenne configuration holder + * @author Edward M. Kagan + */ +@ConfigRoot(name = "cayenne", phase = ConfigPhase.BUILD_AND_RUN_TIME_FIXED) +public final class CayenneConfig { + + /** + * Cayenne configuration file location + */ + @ConfigItem + public String config; + + /** + * Will Cayenne log SQL requests or not + */ + @ConfigItem(defaultValue = "false") + public boolean log; + +} \ No newline at end of file diff --git a/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneRecorder.java b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneRecorder.java new file mode 100644 index 0000000..f5f911c --- /dev/null +++ b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneRecorder.java @@ -0,0 +1,16 @@ +package org.pagan.quarkus.cayenne; + +import io.quarkus.arc.runtime.BeanContainer; +import io.quarkus.runtime.ShutdownContext; +import io.quarkus.runtime.annotations.Recorder; + +@Recorder +public class CayenneRecorder { + + public void initialize(CayenneConfig config, BeanContainer container, ShutdownContext shutdownContext) { + CayenneSupport support = container.instance(CayenneSupport.class); + support.initialize(config); + shutdownContext.addShutdownTask(() -> support.shutdown()); + } + +} diff --git a/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneSupport.java b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneSupport.java new file mode 100644 index 0000000..493f2da --- /dev/null +++ b/cayenne/runtime/src/main/java/org/pagan/quarkus/cayenne/CayenneSupport.java @@ -0,0 +1,50 @@ +package org.pagan.quarkus.cayenne; + +import io.agroal.api.AgroalDataSource; +import javax.inject.Inject; +import javax.inject.Singleton; +import org.apache.cayenne.ObjectContext; +import org.apache.cayenne.configuration.server.ServerRuntime; +import org.apache.cayenne.configuration.server.ServerRuntimeBuilder; +import org.apache.cayenne.log.JdbcEventLogger; +import org.apache.cayenne.log.NoopJdbcEventLogger; + +/** + * + * @author Edward M. Kagan + */ +@Singleton +public class CayenneSupport { + + @Inject + AgroalDataSource dataSource; + + ServerRuntime cayenneRuntime; + + public CayenneSupport() { + System.out.println("Cayenne support now"); + } + + void initialize(CayenneConfig config) { + ServerRuntimeBuilder builder = ServerRuntime.builder() + .addConfig(config.config) + .dataSource(dataSource); + + if (!config.log) { + builder = builder.addModule(binder -> binder + .bind(JdbcEventLogger.class) + .to(NoopJdbcEventLogger.class)); + } + + cayenneRuntime = builder.build(); + } + + public void shutdown() { + cayenneRuntime.shutdown(); + } + + public ObjectContext context() { + return cayenneRuntime.newContext(); + } + +} diff --git a/demo/.dockerignore b/demo/.dockerignore new file mode 100644 index 0000000..b86c7ac --- /dev/null +++ b/demo/.dockerignore @@ -0,0 +1,4 @@ +* +!target/*-runner +!target/*-runner.jar +!target/lib/* \ No newline at end of file diff --git a/demo/.gitignore b/demo/.gitignore new file mode 100644 index 0000000..087a183 --- /dev/null +++ b/demo/.gitignore @@ -0,0 +1,35 @@ +# Eclipse +.project +.classpath +.settings/ +bin/ + +# IntelliJ +.idea +*.ipr +*.iml +*.iws + +# NetBeans +nb-configuration.xml + +# Visual Studio Code +.vscode + +# OSX +.DS_Store + +# Vim +*.swp +*.swo + +# patch +*.orig +*.rej + +# Maven +target/ +pom.xml.tag +pom.xml.releaseBackup +pom.xml.versionsBackup +release.properties \ No newline at end of file diff --git a/demo/.mvn/wrapper/MavenWrapperDownloader.java b/demo/.mvn/wrapper/MavenWrapperDownloader.java new file mode 100644 index 0000000..b901097 --- /dev/null +++ b/demo/.mvn/wrapper/MavenWrapperDownloader.java @@ -0,0 +1,117 @@ +/* + * Copyright 2007-present the original author or authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +import java.net.*; +import java.io.*; +import java.nio.channels.*; +import java.util.Properties; + +public class MavenWrapperDownloader { + + private static final String WRAPPER_VERSION = "0.5.6"; + /** + * Default URL to download the maven-wrapper.jar from, if no 'downloadUrl' is provided. + */ + private static final String DEFAULT_DOWNLOAD_URL = "https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/" + + WRAPPER_VERSION + "/maven-wrapper-" + WRAPPER_VERSION + ".jar"; + + /** + * Path to the maven-wrapper.properties file, which might contain a downloadUrl property to + * use instead of the default one. + */ + private static final String MAVEN_WRAPPER_PROPERTIES_PATH = + ".mvn/wrapper/maven-wrapper.properties"; + + /** + * Path where the maven-wrapper.jar will be saved to. + */ + private static final String MAVEN_WRAPPER_JAR_PATH = + ".mvn/wrapper/maven-wrapper.jar"; + + /** + * Name of the property which should be used to override the default download url for the wrapper. + */ + private static final String PROPERTY_NAME_WRAPPER_URL = "wrapperUrl"; + + public static void main(String args[]) { + System.out.println("- Downloader started"); + File baseDirectory = new File(args[0]); + System.out.println("- Using base directory: " + baseDirectory.getAbsolutePath()); + + // If the maven-wrapper.properties exists, read it and check if it contains a custom + // wrapperUrl parameter. + File mavenWrapperPropertyFile = new File(baseDirectory, MAVEN_WRAPPER_PROPERTIES_PATH); + String url = DEFAULT_DOWNLOAD_URL; + if(mavenWrapperPropertyFile.exists()) { + FileInputStream mavenWrapperPropertyFileInputStream = null; + try { + mavenWrapperPropertyFileInputStream = new FileInputStream(mavenWrapperPropertyFile); + Properties mavenWrapperProperties = new Properties(); + mavenWrapperProperties.load(mavenWrapperPropertyFileInputStream); + url = mavenWrapperProperties.getProperty(PROPERTY_NAME_WRAPPER_URL, url); + } catch (IOException e) { + System.out.println("- ERROR loading '" + MAVEN_WRAPPER_PROPERTIES_PATH + "'"); + } finally { + try { + if(mavenWrapperPropertyFileInputStream != null) { + mavenWrapperPropertyFileInputStream.close(); + } + } catch (IOException e) { + // Ignore ... + } + } + } + System.out.println("- Downloading from: " + url); + + File outputFile = new File(baseDirectory.getAbsolutePath(), MAVEN_WRAPPER_JAR_PATH); + if(!outputFile.getParentFile().exists()) { + if(!outputFile.getParentFile().mkdirs()) { + System.out.println( + "- ERROR creating output directory '" + outputFile.getParentFile().getAbsolutePath() + "'"); + } + } + System.out.println("- Downloading to: " + outputFile.getAbsolutePath()); + try { + downloadFileFromURL(url, outputFile); + System.out.println("Done"); + System.exit(0); + } catch (Throwable e) { + System.out.println("- Error downloading"); + e.printStackTrace(); + System.exit(1); + } + } + + private static void downloadFileFromURL(String urlString, File destination) throws Exception { + if (System.getenv("MVNW_USERNAME") != null && System.getenv("MVNW_PASSWORD") != null) { + String username = System.getenv("MVNW_USERNAME"); + char[] password = System.getenv("MVNW_PASSWORD").toCharArray(); + Authenticator.setDefault(new Authenticator() { + @Override + protected PasswordAuthentication getPasswordAuthentication() { + return new PasswordAuthentication(username, password); + } + }); + } + URL website = new URL(urlString); + ReadableByteChannel rbc; + rbc = Channels.newChannel(website.openStream()); + FileOutputStream fos = new FileOutputStream(destination); + fos.getChannel().transferFrom(rbc, 0, Long.MAX_VALUE); + fos.close(); + rbc.close(); + } + +} diff --git a/demo/.mvn/wrapper/maven-wrapper.jar b/demo/.mvn/wrapper/maven-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..2cc7d4a55c0cd0092912bf49ae38b3a9e3fd0054 GIT binary patch literal 50710 zcmbTd1CVCTmM+|7+wQV$+qP}n>auOywyU~q+qUhh+uxis_~*a##hm*_WW?9E7Pb7N%LRFiwbEGCJ0XP=%-6oeT$XZcYgtzC2~q zk(K08IQL8oTl}>>+hE5YRgXTB@fZ4TH9>7=79e`%%tw*SQUa9~$xKD5rS!;ZG@ocK zQdcH}JX?W|0_Afv?y`-NgLum62B&WSD$-w;O6G0Sm;SMX65z)l%m1e-g8Q$QTI;(Q z+x$xth4KFvH@Bs6(zn!iF#nenk^Y^ce;XIItAoCsow38eq?Y-Auh!1in#Rt-_D>H^ z=EjbclGGGa6VnaMGmMLj`x3NcwA43Jb(0gzl;RUIRAUDcR1~99l2SAPkVhoRMMtN} zXvC<tOmX83grD8GSo_Lo?%lNfhD#EBgPo z*nf@ppMC#B!T)Ae0RG$mlJWmGl7CkuU~B8-==5i;rS;8i6rJ=PoQxf446XDX9g|c> zU64ePyMlsI^V5Jq5A+BPe#e73+kpc_r1tv#B)~EZ;7^67F0*QiYfrk0uVW;Qb=NsG zN>gsuCwvb?s-KQIppEaeXtEMdc9dy6Dfduz-tMTms+i01{eD9JE&h?Kht*$eOl#&L zJdM_-vXs(V#$Ed;5wyNWJdPNh+Z$+;$|%qR(t`4W@kDhd*{(7-33BOS6L$UPDeE_53j${QfKN-0v-HG z(QfyvFNbwPK%^!eIo4ac1;b>c0vyf9}Xby@YY!lkz-UvNp zwj#Gg|4B~?n?G^{;(W;|{SNoJbHTMpQJ*Wq5b{l9c8(%?Kd^1?H1om1de0Da9M;Q=n zUfn{f87iVb^>Exl*nZ0hs(Yt>&V9$Pg`zX`AI%`+0SWQ4Zc(8lUDcTluS z5a_KerZWe}a-MF9#Cd^fi!y3%@RFmg&~YnYZ6<=L`UJ0v={zr)>$A;x#MCHZy1st7 ztT+N07NR+vOwSV2pvWuN1%lO!K#Pj0Fr>Q~R40{bwdL%u9i`DSM4RdtEH#cW)6}+I-eE< z&tZs+(Ogu(H_;$a$!7w`MH0r%h&@KM+<>gJL@O~2K2?VrSYUBbhCn#yy?P)uF3qWU z0o09mIik+kvzV6w>vEZy@&Mr)SgxPzUiDA&%07m17udz9usD82afQEps3$pe!7fUf z0eiidkJ)m3qhOjVHC_M(RYCBO%CZKZXFb8}s0-+}@CIn&EF(rRWUX2g^yZCvl0bI} zbP;1S)iXnRC&}5-Tl(hASKqdSnO?ASGJ*MIhOXIblmEudj(M|W!+I3eDc}7t`^mtg z)PKlaXe(OH+q-)qcQ8a@!llRrpGI8DsjhoKvw9T;TEH&?s=LH0w$EzI>%u;oD@x83 zJL7+ncjI9nn!TlS_KYu5vn%f*@qa5F;| zEFxY&B?g=IVlaF3XNm_03PA)=3|{n-UCgJoTr;|;1AU9|kPE_if8!Zvb}0q$5okF$ zHaJdmO&gg!9oN|M{!qGE=tb|3pVQ8PbL$}e;NgXz<6ZEggI}wO@aBP**2Wo=yN#ZC z4G$m^yaM9g=|&!^ft8jOLuzc3Psca*;7`;gnHm}tS0%f4{|VGEwu45KptfNmwxlE~ z^=r30gi@?cOm8kAz!EylA4G~7kbEiRlRIzwrb~{_2(x^$-?|#e6Bi_**(vyr_~9Of z!n>Gqf+Qwiu!xhi9f53=PM3`3tNF}pCOiPU|H4;pzjcsqbwg*{{kyrTxk<;mx~(;; z1NMrpaQ`57yn34>Jo3b|HROE(UNcQash!0p2-!Cz;{IRv#Vp5!3o$P8!%SgV~k&Hnqhp`5eLjTcy93cK!3Hm-$`@yGnaE=?;*2uSpiZTs_dDd51U%i z{|Zd9ou-;laGS_x=O}a+ zB||za<795A?_~Q=r=coQ+ZK@@ zId~hWQL<%)fI_WDIX#=(WNl!Dm$a&ROfLTd&B$vatq!M-2Jcs;N2vps$b6P1(N}=oI3<3luMTmC|0*{ zm1w8bt7vgX($!0@V0A}XIK)w!AzUn7vH=pZEp0RU0p?}ch2XC-7r#LK&vyc2=-#Q2 z^L%8)JbbcZ%g0Du;|8=q8B>X=mIQirpE=&Ox{TiuNDnOPd-FLI^KfEF729!!0x#Es z@>3ursjFSpu%C-8WL^Zw!7a0O-#cnf`HjI+AjVCFitK}GXO`ME&on|^=~Zc}^LBp9 zj=-vlN;Uc;IDjtK38l7}5xxQF&sRtfn4^TNtnzXv4M{r&ek*(eNbIu!u$>Ed%` z5x7+&)2P&4>0J`N&ZP8$vcR+@FS0126s6+Jx_{{`3ZrIMwaJo6jdrRwE$>IU_JTZ} z(||hyyQ)4Z1@wSlT94(-QKqkAatMmkT7pCycEB1U8KQbFX&?%|4$yyxCtm3=W`$4fiG0WU3yI@c zx{wfmkZAYE_5M%4{J-ygbpH|(|GD$2f$3o_Vti#&zfSGZMQ5_f3xt6~+{RX=$H8at z?GFG1Tmp}}lmm-R->ve*Iv+XJ@58p|1_jRvfEgz$XozU8#iJS})UM6VNI!3RUU!{5 zXB(+Eqd-E;cHQ>)`h0(HO_zLmzR3Tu-UGp;08YntWwMY-9i^w_u#wR?JxR2bky5j9 z3Sl-dQQU$xrO0xa&>vsiK`QN<$Yd%YXXM7*WOhnRdSFt5$aJux8QceC?lA0_if|s> ze{ad*opH_kb%M&~(~&UcX0nFGq^MqjxW?HJIP462v9XG>j(5Gat_)#SiNfahq2Mz2 zU`4uV8m$S~o9(W>mu*=h%Gs(Wz+%>h;R9Sg)jZ$q8vT1HxX3iQnh6&2rJ1u|j>^Qf`A76K%_ubL`Zu?h4`b=IyL>1!=*%!_K)=XC z6d}4R5L+sI50Q4P3upXQ3Z!~1ZXLlh!^UNcK6#QpYt-YC=^H=EPg3)z*wXo*024Q4b2sBCG4I# zlTFFY=kQ>xvR+LsuDUAk)q%5pEcqr(O_|^spjhtpb1#aC& zghXzGkGDC_XDa%t(X`E+kvKQ4zrQ*uuQoj>7@@ykWvF332)RO?%AA&Fsn&MNzmFa$ zWk&&^=NNjxLjrli_8ESU)}U|N{%j&TQmvY~lk!~Jh}*=^INA~&QB9em!in_X%Rl1&Kd~Z(u z9mra#<@vZQlOY+JYUwCrgoea4C8^(xv4ceCXcejq84TQ#sF~IU2V}LKc~Xlr_P=ry zl&Hh0exdCbVd^NPCqNNlxM3vA13EI8XvZ1H9#bT7y*U8Y{H8nwGpOR!e!!}*g;mJ#}T{ekSb}5zIPmye*If(}}_=PcuAW#yidAa^9-`<8Gr0 z)Fz=NiZ{)HAvw{Pl5uu)?)&i&Us$Cx4gE}cIJ}B4Xz~-q7)R_%owbP!z_V2=Aq%Rj z{V;7#kV1dNT9-6R+H}}(ED*_!F=~uz>&nR3gb^Ce%+0s#u|vWl<~JD3MvS0T9thdF zioIG3c#Sdsv;LdtRv3ml7%o$6LTVL>(H`^@TNg`2KPIk*8-IB}X!MT0`hN9Ddf7yN z?J=GxPL!uJ7lqwowsl?iRrh@#5C$%E&h~Z>XQcvFC*5%0RN-Opq|=IwX(dq(*sjs+ zqy99+v~m|6T#zR*e1AVxZ8djd5>eIeCi(b8sUk)OGjAsKSOg^-ugwl2WSL@d#?mdl zib0v*{u-?cq}dDGyZ%$XRY=UkQwt2oGu`zQneZh$=^! zj;!pCBWQNtvAcwcWIBM2y9!*W|8LmQy$H~5BEx)78J`4Z0(FJO2P^!YyQU{*Al+fs z){!4JvT1iLrJ8aU3k0t|P}{RN)_^v%$$r;+p0DY7N8CXzmS*HB*=?qaaF9D@#_$SN zSz{moAK<*RH->%r7xX~9gVW$l7?b|_SYI)gcjf0VAUJ%FcQP(TpBs; zg$25D!Ry_`8xpS_OJdeo$qh#7U+cepZ??TII7_%AXsT$B z=e)Bx#v%J0j``00Zk5hsvv6%T^*xGNx%KN-=pocSoqE5_R)OK%-Pbu^1MNzfds)mL zxz^F4lDKV9D&lEY;I+A)ui{TznB*CE$=9(wgE{m}`^<--OzV-5V4X2w9j(_!+jpTr zJvD*y6;39&T+==$F&tsRKM_lqa1HC}aGL0o`%c9mO=fts?36@8MGm7Vi{Y z^<7m$(EtdSr#22<(rm_(l_(`j!*Pu~Y>>xc>I9M#DJYDJNHO&4=HM%YLIp?;iR&$m z#_$ZWYLfGLt5FJZhr3jpYb`*%9S!zCG6ivNHYzNHcI%khtgHBliM^Ou}ZVD7ehU9 zS+W@AV=?Ro!=%AJ>Kcy9aU3%VX3|XM_K0A+ZaknKDyIS3S-Hw1C7&BSW5)sqj5Ye_ z4OSW7Yu-;bCyYKHFUk}<*<(@TH?YZPHr~~Iy%9@GR2Yd}J2!N9K&CN7Eq{Ka!jdu; zQNB*Y;i(7)OxZK%IHGt#Rt?z`I|A{q_BmoF!f^G}XVeTbe1Wnzh%1g>j}>DqFf;Rp zz7>xIs12@Ke0gr+4-!pmFP84vCIaTjqFNg{V`5}Rdt~xE^I;Bxp4)|cs8=f)1YwHz zqI`G~s2~qqDV+h02b`PQpUE#^^Aq8l%y2|ByQeXSADg5*qMprEAE3WFg0Q39`O+i1 z!J@iV!`Y~C$wJ!5Z+j5$i<1`+@)tBG$JL=!*uk=2k;T<@{|s1$YL079FvK%mPhyHV zP8^KGZnp`(hVMZ;s=n~3r2y;LTwcJwoBW-(ndU-$03{RD zh+Qn$ja_Z^OuMf3Ub|JTY74s&Am*(n{J3~@#OJNYuEVVJd9*H%)oFoRBkySGm`hx! zT3tG|+aAkXcx-2Apy)h^BkOyFTWQVeZ%e2@;*0DtlG9I3Et=PKaPt&K zw?WI7S;P)TWED7aSH$3hL@Qde?H#tzo^<(o_sv_2ci<7M?F$|oCFWc?7@KBj-;N$P zB;q!8@bW-WJY9do&y|6~mEruZAVe$!?{)N9rZZxD-|oltkhW9~nR8bLBGXw<632!l z*TYQn^NnUy%Ds}$f^=yQ+BM-a5X4^GHF=%PDrRfm_uqC zh{sKwIu|O0&jWb27;wzg4w5uA@TO_j(1X?8E>5Zfma|Ly7Bklq|s z9)H`zoAGY3n-+&JPrT!>u^qg9Evx4y@GI4$n-Uk_5wttU1_t?6><>}cZ-U+&+~JE) zPlDbO_j;MoxdLzMd~Ew|1o^a5q_1R*JZ=#XXMzg?6Zy!^hop}qoLQlJ{(%!KYt`MK z8umEN@Z4w!2=q_oe=;QttPCQy3Nm4F@x>@v4sz_jo{4m*0r%J(w1cSo;D_hQtJs7W z><$QrmG^+<$4{d2bgGo&3-FV}avg9zI|Rr(k{wTyl3!M1q+a zD9W{pCd%il*j&Ft z5H$nENf>>k$;SONGW`qo6`&qKs*T z2^RS)pXk9b@(_Fw1bkb)-oqK|v}r$L!W&aXA>IpcdNZ_vWE#XO8X`#Yp1+?RshVcd zknG%rPd*4ECEI0wD#@d+3NbHKxl}n^Sgkx==Iu%}HvNliOqVBqG?P2va zQ;kRJ$J6j;+wP9cS za#m;#GUT!qAV%+rdWolk+)6kkz4@Yh5LXP+LSvo9_T+MmiaP-eq6_k;)i6_@WSJ zlT@wK$zqHu<83U2V*yJ|XJU4farT#pAA&@qu)(PO^8PxEmPD4;Txpio+2)#!9 z>&=i7*#tc0`?!==vk>s7V+PL#S1;PwSY?NIXN2=Gu89x(cToFm))7L;< z+bhAbVD*bD=}iU`+PU+SBobTQ%S!=VL!>q$rfWsaaV}Smz>lO9JXT#`CcH_mRCSf4%YQAw`$^yY z3Y*^Nzk_g$xn7a_NO(2Eb*I=^;4f!Ra#Oo~LLjlcjke*k*o$~U#0ZXOQ5@HQ&T46l z7504MUgZkz2gNP1QFN8Y?nSEnEai^Rgyvl}xZfMUV6QrJcXp;jKGqB=D*tj{8(_pV zqyB*DK$2lgYGejmJUW)*s_Cv65sFf&pb(Yz8oWgDtQ0~k^0-wdF|tj}MOXaN@ydF8 zNr={U?=;&Z?wr^VC+`)S2xl}QFagy;$mG=TUs7Vi2wws5zEke4hTa2)>O0U?$WYsZ z<8bN2bB_N4AWd%+kncgknZ&}bM~eDtj#C5uRkp21hWW5gxWvc6b*4+dn<{c?w9Rmf zIVZKsPl{W2vQAlYO3yh}-{Os=YBnL8?uN5(RqfQ=-1cOiUnJu>KcLA*tQK3FU`_bM zM^T28w;nAj5EdAXFi&Kk1Nnl2)D!M{@+D-}bIEe+Lc4{s;YJc-{F#``iS2uk;2!Zp zF9#myUmO!wCeJIoi^A+T^e~20c+c2C}XltaR!|U-HfDA=^xF97ev}$l6#oY z&-&T{egB)&aV$3_aVA51XGiU07$s9vubh_kQG?F$FycvS6|IO!6q zq^>9|3U^*!X_C~SxX&pqUkUjz%!j=VlXDo$!2VLH!rKj@61mDpSr~7B2yy{>X~_nc zRI+7g2V&k zd**H++P9dg!-AOs3;GM`(g<+GRV$+&DdMVpUxY9I1@uK28$az=6oaa+PutlO9?6#? zf-OsgT>^@8KK>ggkUQRPPgC7zjKFR5spqQb3ojCHzj^(UH~v+!y*`Smv)VpVoPwa6 zWG18WJaPKMi*F6Zdk*kU^`i~NNTfn3BkJniC`yN98L-Awd)Z&mY? zprBW$!qL-OL7h@O#kvYnLsfff@kDIegt~?{-*5A7JrA;#TmTe?jICJqhub-G@e??D zqiV#g{)M!kW1-4SDel7TO{;@*h2=_76g3NUD@|c*WO#>MfYq6_YVUP+&8e4|%4T`w zXzhmVNziAHazWO2qXcaOu@R1MrPP{t)`N)}-1&~mq=ZH=w=;-E$IOk=y$dOls{6sRR`I5>|X zpq~XYW4sd;J^6OwOf**J>a7u$S>WTFPRkjY;BfVgQst)u4aMLR1|6%)CB^18XCz+r ztkYQ}G43j~Q&1em(_EkMv0|WEiKu;z2zhb(L%$F&xWwzOmk;VLBYAZ8lOCziNoPw1 zv2BOyXA`A8z^WH!nXhKXM`t0;6D*-uGds3TYGrm8SPnJJOQ^fJU#}@aIy@MYWz**H zvkp?7I5PE{$$|~{-ZaFxr6ZolP^nL##mHOErB^AqJqn^hFA=)HWj!m3WDaHW$C)i^ z9@6G$SzB=>jbe>4kqr#sF7#K}W*Cg-5y6kun3u&0L7BpXF9=#7IN8FOjWrWwUBZiU zT_se3ih-GBKx+Uw0N|CwP3D@-C=5(9T#BH@M`F2!Goiqx+Js5xC92|Sy0%WWWp={$(am!#l~f^W_oz78HX<0X#7 zp)p1u~M*o9W@O8P{0Qkg@Wa# z2{Heb&oX^CQSZWSFBXKOfE|tsAm#^U-WkDnU;IowZ`Ok4!mwHwH=s|AqZ^YD4!5!@ zPxJj+Bd-q6w_YG`z_+r;S86zwXb+EO&qogOq8h-Ect5(M2+>(O7n7)^dP*ws_3U6v zVsh)sk^@*c>)3EML|0<-YROho{lz@Nd4;R9gL{9|64xVL`n!m$-Jjrx?-Bacp!=^5 z1^T^eB{_)Y<9)y{-4Rz@9_>;_7h;5D+@QcbF4Wv7hu)s0&==&6u)33 zHRj+&Woq-vDvjwJCYES@$C4{$?f$Ibi4G()UeN11rgjF+^;YE^5nYprYoJNoudNj= zm1pXSeG64dcWHObUetodRn1Fw|1nI$D9z}dVEYT0lQnsf_E1x2vBLql7NrHH!n&Sq z6lc*mvU=WS6=v9Lrl}&zRiu_6u;6g%_DU{9b+R z#YHqX7`m9eydf?KlKu6Sb%j$%_jmydig`B*TN`cZL-g!R)iE?+Q5oOqBFKhx z%MW>BC^(F_JuG(ayE(MT{S3eI{cKiwOtPwLc0XO*{*|(JOx;uQOfq@lp_^cZo=FZj z4#}@e@dJ>Bn%2`2_WPeSN7si^{U#H=7N4o%Dq3NdGybrZgEU$oSm$hC)uNDC_M9xc zGzwh5Sg?mpBIE8lT2XsqTt3j3?We8}3bzLBTQd639vyg^$0#1epq8snlDJP2(BF)K zSx30RM+{f+b$g{9usIL8H!hCO117Xgv}ttPJm9wVRjPk;ePH@zxv%j9k5`TzdXLeT zFgFX`V7cYIcBls5WN0Pf6SMBN+;CrQ(|EsFd*xtwr#$R{Z9FP`OWtyNsq#mCgZ7+P z^Yn$haBJ)r96{ZJd8vlMl?IBxrgh=fdq_NF!1{jARCVz>jNdC)H^wfy?R94#MPdUjcYX>#wEx+LB#P-#4S-%YH>t-j+w zOFTI8gX$ard6fAh&g=u&56%3^-6E2tpk*wx3HSCQ+t7+*iOs zPk5ysqE}i*cQocFvA68xHfL|iX(C4h*67@3|5Qwle(8wT&!&{8*{f%0(5gH+m>$tq zp;AqrP7?XTEooYG1Dzfxc>W%*CyL16q|fQ0_jp%%Bk^k!i#Nbi(N9&T>#M{gez_Ws zYK=l}adalV(nH}I_!hNeb;tQFk3BHX7N}}R8%pek^E`X}%ou=cx8InPU1EE0|Hen- zyw8MoJqB5=)Z%JXlrdTXAE)eqLAdVE-=>wGHrkRet}>3Yu^lt$Kzu%$3#(ioY}@Gu zjk3BZuQH&~7H+C*uX^4}F*|P89JX;Hg2U!pt>rDi(n(Qe-c}tzb0#6_ItoR0->LSt zR~UT<-|@TO%O`M+_e_J4wx7^)5_%%u+J=yF_S#2Xd?C;Ss3N7KY^#-vx+|;bJX&8r zD?|MetfhdC;^2WG`7MCgs>TKKN=^=!x&Q~BzmQio_^l~LboTNT=I zC5pme^P@ER``p$2md9>4!K#vV-Fc1an7pl>_|&>aqP}+zqR?+~Z;f2^`a+-!Te%V? z;H2SbF>jP^GE(R1@%C==XQ@J=G9lKX+Z<@5}PO(EYkJh=GCv#)Nj{DkWJM2}F&oAZ6xu8&g7pn1ps2U5srwQ7CAK zN&*~@t{`31lUf`O;2w^)M3B@o)_mbRu{-`PrfNpF!R^q>yTR&ETS7^-b2*{-tZAZz zw@q5x9B5V8Qd7dZ!Ai$9hk%Q!wqbE1F1c96&zwBBaRW}(^axoPpN^4Aw}&a5dMe+*Gomky_l^54*rzXro$ z>LL)U5Ry>~FJi=*{JDc)_**c)-&faPz`6v`YU3HQa}pLtb5K)u%K+BOqXP0)rj5Au$zB zW1?vr?mDv7Fsxtsr+S6ucp2l#(4dnr9sD*v+@*>g#M4b|U?~s93>Pg{{a5|rm2xfI z`>E}?9S@|IoUX{Q1zjm5YJT|3S>&09D}|2~BiMo=z4YEjXlWh)V&qs;*C{`UMxp$9 zX)QB?G$fPD6z5_pNs>Jeh{^&U^)Wbr?2D6-q?)`*1k@!UvwQgl8eG$r+)NnFoT)L6 zg7lEh+E6J17krfYJCSjWzm67hEth24pomhz71|Qodn#oAILN)*Vwu2qpJirG)4Wnv}9GWOFrQg%Je+gNrPl8mw7ykE8{ z=|B4+uwC&bpp%eFcRU6{mxRV32VeH8XxX>v$du<$(DfinaaWxP<+Y97Z#n#U~V zVEu-GoPD=9$}P;xv+S~Ob#mmi$JQmE;Iz4(){y*9pFyW-jjgdk#oG$fl4o9E8bo|L zWjo4l%n51@Kz-n%zeSCD`uB?T%FVk+KBI}=ve zvlcS#wt`U6wrJo}6I6Rwb=1GzZfwE=I&Ne@p7*pH84XShXYJRgvK)UjQL%R9Zbm(m zxzTQsLTON$WO7vM)*vl%Pc0JH7WhP;$z@j=y#avW4X8iqy6mEYr@-}PW?H)xfP6fQ z&tI$F{NNct4rRMSHhaelo<5kTYq+(?pY)Ieh8*sa83EQfMrFupMM@nfEV@EmdHUv9 z35uzIrIuo4#WnF^_jcpC@uNNaYTQ~uZWOE6P@LFT^1@$o&q+9Qr8YR+ObBkpP9=F+$s5+B!mX2~T zAuQ6RenX?O{IlLMl1%)OK{S7oL}X%;!XUxU~xJN8xk z`xywS*naF(J#?vOpB(K=o~lE;m$zhgPWDB@=p#dQIW>xe_p1OLoWInJRKbEuoncf; zmS1!u-ycc1qWnDg5Nk2D)BY%jmOwCLC+Ny>`f&UxFowIsHnOXfR^S;&F(KXd{ODlm z$6#1ccqt-HIH9)|@fHnrKudu!6B$_R{fbCIkSIb#aUN|3RM>zuO>dpMbROZ`^hvS@ z$FU-;e4W}!ubzKrU@R*dW*($tFZ>}dd*4_mv)#O>X{U@zSzQt*83l9mI zI$8O<5AIDx`wo0}f2fsPC_l>ONx_`E7kdXu{YIZbp1$(^oBAH({T~&oQ&1{X951QW zmhHUxd)t%GQ9#ak5fTjk-cahWC;>^Rg7(`TVlvy0W@Y!Jc%QL3Ozu# zDPIqBCy&T2PWBj+d-JA-pxZlM=9ja2ce|3B(^VCF+a*MMp`(rH>Rt6W1$;r{n1(VK zLs>UtkT43LR2G$AOYHVailiqk7naz2yZGLo*xQs!T9VN5Q>eE(w zw$4&)&6xIV$IO^>1N-jrEUg>O8G4^@y+-hQv6@OmF@gy^nL_n1P1-Rtyy$Bl;|VcV zF=p*&41-qI5gG9UhKmmnjs932!6hceXa#-qfK;3d*a{)BrwNFeKU|ge?N!;zk+kB! zMD_uHJR#%b54c2tr~uGPLTRLg$`fupo}cRJeTwK;~}A>(Acy4k-Xk&Aa1&eWYS1ULWUj@fhBiWY$pdfy+F z@G{OG{*v*mYtH3OdUjwEr6%_ZPZ3P{@rfbNPQG!BZ7lRyC^xlMpWH`@YRar`tr}d> z#wz87t?#2FsH-jM6m{U=gp6WPrZ%*w0bFm(T#7m#v^;f%Z!kCeB5oiF`W33W5Srdt zdU?YeOdPG@98H7NpI{(uN{FJdu14r(URPH^F6tOpXuhU7T9a{3G3_#Ldfx_nT(Hec zo<1dyhsVsTw;ZkVcJ_0-h-T3G1W@q)_Q30LNv)W?FbMH+XJ* zy=$@39Op|kZv`Rt>X`zg&at(?PO^I=X8d9&myFEx#S`dYTg1W+iE?vt#b47QwoHI9 zNP+|3WjtXo{u}VG(lLUaW0&@yD|O?4TS4dfJI`HC-^q;M(b3r2;7|FONXphw-%7~* z&;2!X17|05+kZOpQ3~3!Nb>O94b&ZSs%p)TK)n3m=4eiblVtSx@KNFgBY_xV6ts;NF;GcGxMP8OKV^h6LmSb2E#Qnw ze!6Mnz7>lE9u{AgQ~8u2zM8CYD5US8dMDX-5iMlgpE9m*s+Lh~A#P1er*rF}GHV3h z=`STo?kIXw8I<`W0^*@mB1$}pj60R{aJ7>C2m=oghKyxMbFNq#EVLgP0cH3q7H z%0?L93-z6|+jiN|@v>ix?tRBU(v-4RV`}cQH*fp|)vd3)8i9hJ3hkuh^8dz{F5-~_ zUUr1T3cP%cCaTooM8dj|4*M=e6flH0&8ve32Q)0dyisl))XkZ7Wg~N}6y`+Qi2l+e zUd#F!nJp{#KIjbQdI`%oZ`?h=5G^kZ_uN`<(`3;a!~EMsWV|j-o>c?x#;zR2ktiB! z);5rrHl?GPtr6-o!tYd|uK;Vbsp4P{v_4??=^a>>U4_aUXPWQ$FPLE4PK$T^3Gkf$ zHo&9$U&G`d(Os6xt1r?sg14n)G8HNyWa^q8#nf0lbr4A-Fi;q6t-`pAx1T*$eKM*$ z|CX|gDrk#&1}>5H+`EjV$9Bm)Njw&7-ZR{1!CJTaXuP!$Pcg69`{w5BRHysB$(tWUes@@6aM69kb|Lx$%BRY^-o6bjH#0!7b;5~{6J+jKxU!Kmi# zndh@+?}WKSRY2gZ?Q`{(Uj|kb1%VWmRryOH0T)f3cKtG4oIF=F7RaRnH0Rc_&372={_3lRNsr95%ZO{IX{p@YJ^EI%+gvvKes5cY+PE@unghjdY5#9A!G z70u6}?zmd?v+{`vCu-53_v5@z)X{oPC@P)iA3jK$`r zSA2a7&!^zmUiZ82R2=1cumBQwOJUPz5Ay`RLfY(EiwKkrx%@YN^^XuET;tE zmr-6~I7j!R!KrHu5CWGSChO6deaLWa*9LLJbcAJsFd%Dy>a!>J`N)Z&oiU4OEP-!Ti^_!p}O?7`}i7Lsf$-gBkuY*`Zb z7=!nTT;5z$_5$=J=Ko+Cp|Q0J=%oFr>hBgnL3!tvFoLNhf#D0O=X^h+x08iB;@8pXdRHxX}6R4k@i6%vmsQwu^5z zk1ip`#^N)^#Lg#HOW3sPI33xqFB4#bOPVnY%d6prwxf;Y-w9{ky4{O6&94Ra8VN@K zb-lY;&`HtxW@sF!doT5T$2&lIvJpbKGMuDAFM#!QPXW87>}=Q4J3JeXlwHys?!1^#37q_k?N@+u&Ns20pEoBeZC*np;i;M{2C0Z4_br2gsh6eL z#8`#sn41+$iD?^GL%5?cbRcaa-Nx0vE(D=*WY%rXy3B%gNz0l?#noGJGP728RMY#q z=2&aJf@DcR?QbMmN)ItUe+VM_U!ryqA@1VVt$^*xYt~-qvW!J4Tp<-3>jT=7Zow5M z8mSKp0v4b%a8bxFr>3MwZHSWD73D@+$5?nZAqGM#>H@`)mIeC#->B)P8T$zh-Pxnc z8)~Zx?TWF4(YfKuF3WN_ckpCe5;x4V4AA3(i$pm|78{%!q?|~*eH0f=?j6i)n~Hso zmTo>vqEtB)`%hP55INf7HM@taH)v`Fw40Ayc*R!T?O{ziUpYmP)AH`euTK!zg9*6Z z!>M=$3pd0!&TzU=hc_@@^Yd3eUQpX4-33}b{?~5t5lgW=ldJ@dUAH%`l5US1y_`40 zs(X`Qk}vvMDYYq+@Rm+~IyCX;iD~pMgq^KY)T*aBz@DYEB={PxA>)mI6tM*sx-DmGQHEaHwRrAmNjO!ZLHO4b;;5mf@zzlPhkP($JeZGE7 z?^XN}Gf_feGoG~BjUgVa*)O`>lX=$BSR2)uD<9 z>o^|nb1^oVDhQbfW>>!;8-7<}nL6L^V*4pB=>wwW+RXAeRvKED(n1;R`A6v$6gy0I(;Vf?!4;&sgn7F%LpM}6PQ?0%2Z@b{It<(G1CZ|>913E0nR2r^Pa*Bp z@tFGi*CQ~@Yc-?{cwu1 zsilf=k^+Qs>&WZG(3WDixisHpR>`+ihiRwkL(3T|=xsoNP*@XX3BU8hr57l3k;pni zI``=3Nl4xh4oDj<%>Q1zYXHr%Xg_xrK3Nq?vKX3|^Hb(Bj+lONTz>4yhU-UdXt2>j z<>S4NB&!iE+ao{0Tx^N*^|EZU;0kJkx@zh}S^P{ieQjGl468CbC`SWnwLRYYiStXm zOxt~Rb3D{dz=nHMcY)#r^kF8|q8KZHVb9FCX2m^X*(|L9FZg!5a7((!J8%MjT$#Fs)M1Pb zq6hBGp%O1A+&%2>l0mpaIzbo&jc^!oN^3zxap3V2dNj3x<=TwZ&0eKX5PIso9j1;e zwUg+C&}FJ`k(M|%%}p=6RPUq4sT3-Y;k-<68ciZ~_j|bt>&9ZLHNVrp#+pk}XvM{8 z`?k}o-!if>hVlCP9j%&WI2V`5SW)BCeR5>MQhF)po=p~AYN%cNa_BbV6EEh_kk^@a zD>4&>uCGCUmyA-c)%DIcF4R6!>?6T~Mj_m{Hpq`*(wj>foHL;;%;?(((YOxGt)Bhx zuS+K{{CUsaC++%}S6~CJ=|vr(iIs-je)e9uJEU8ZJAz)w166q)R^2XI?@E2vUQ!R% zn@dxS!JcOimXkWJBz8Y?2JKQr>`~SmE2F2SL38$SyR1^yqj8_mkBp)o$@+3BQ~Mid z9U$XVqxX3P=XCKj0*W>}L0~Em`(vG<>srF8+*kPrw z20{z(=^w+ybdGe~Oo_i|hYJ@kZl*(9sHw#Chi&OIc?w`nBODp?ia$uF%Hs(X>xm?j zqZQ`Ybf@g#wli`!-al~3GWiE$K+LCe=Ndi!#CVjzUZ z!sD2O*;d28zkl))m)YN7HDi^z5IuNo3^w(zy8 zszJG#mp#Cj)Q@E@r-=NP2FVxxEAeOI2e=|KshybNB6HgE^(r>HD{*}S}mO>LuRGJT{*tfTzw_#+er-0${}%YPe@CMJ1Ng#j#)i)SnY@ss3gL;g zg2D~#Kpdfu#G;q1qz_TwSz1VJT(b3zby$Vk&;Y#1(A)|xj`_?i5YQ;TR%jice5E;0 zYHg;`zS5{S*9xI6o^j>rE8Ua*XhIw{_-*&@(R|C(am8__>+Ws&Q^ymy*X4~hR2b5r zm^p3sw}yv=tdyncy_Ui7{BQS732et~Z_@{-IhHDXAV`(Wlay<#hb>%H%WDi+K$862nA@BDtM#UCKMu+kM`!JHyWSi?&)A7_ z3{cyNG%a~nnH_!+;g&JxEMAmh-Z}rC!o7>OVzW&PoMyTA_g{hqXG)SLraA^OP**<7 zjWbr7z!o2n3hnx7A=2O=WL;`@9N{vQIM@&|G-ljrPvIuJHYtss0Er0fT5cMXNUf1B z7FAwBDixt0X7C3S)mPe5g`YtME23wAnbU)+AtV}z+e8G;0BP=bI;?(#|Ep!vVfDbK zvx+|CKF>yt0hWQ3drchU#XBU+HiuG*V^snFAPUp-5<#R&BUAzoB!aZ+e*KIxa26V}s6?nBK(U-7REa573wg-jqCg>H8~>O{ z*C0JL-?X-k_y%hpUFL?I>0WV{oV`Nb)nZbJG01R~AG>flIJf)3O*oB2i8~;!P?Wo_ z0|QEB*fifiL6E6%>tlAYHm2cjTFE@*<);#>689Z6S#BySQ@VTMhf9vYQyLeDg1*F} zjq>i1*x>5|CGKN{l9br3kB0EHY|k4{%^t7-uhjd#NVipUZa=EUuE5kS1_~qYX?>hJ z$}!jc9$O$>J&wnu0SgfYods^z?J4X;X7c77Me0kS-dO_VUQ39T(Kv(Y#s}Qqz-0AH z^?WRL(4RzpkD+T5FG_0NyPq-a-B7A5LHOCqwObRJi&oRi(<;OuIN7SV5PeHU$<@Zh zPozEV`dYmu0Z&Tqd>t>8JVde9#Pt+l95iHe$4Xwfy1AhI zDM4XJ;bBTTvRFtW>E+GzkN)9k!hA5z;xUOL2 zq4}zn-DP{qc^i|Y%rvi|^5k-*8;JZ~9a;>-+q_EOX+p1Wz;>i7c}M6Nv`^NY&{J-> z`(mzDJDM}QPu5i44**2Qbo(XzZ-ZDu%6vm8w@DUarqXj41VqP~ zs&4Y8F^Waik3y1fQo`bVUH;b=!^QrWb)3Gl=QVKr+6sxc=ygauUG|cm?|X=;Q)kQ8 zM(xrICifa2p``I7>g2R~?a{hmw@{!NS5`VhH8+;cV(F>B94M*S;5#O`YzZH1Z%yD? zZ61w(M`#aS-*~Fj;x|J!KM|^o;MI#Xkh0ULJcA?o4u~f%Z^16ViA27FxU5GM*rKq( z7cS~MrZ=f>_OWx8j#-Q3%!aEU2hVuTu(7`TQk-Bi6*!<}0WQi;_FpO;fhpL4`DcWp zGOw9vx0N~6#}lz(r+dxIGZM3ah-8qrqMmeRh%{z@dbUD2w15*_4P?I~UZr^anP}DB zU9CCrNiy9I3~d#&!$DX9e?A});BjBtQ7oGAyoI$8YQrkLBIH@2;lt4E^)|d6Jwj}z z&2_E}Y;H#6I4<10d_&P0{4|EUacwFHauvrjAnAm6yeR#}f}Rk27CN)vhgRqEyPMMS7zvunj2?`f;%?alsJ+-K+IzjJx>h8 zu~m_y$!J5RWAh|C<6+uiCNsOKu)E72M3xKK(a9Okw3e_*O&}7llNV!=P87VM2DkAk zci!YXS2&=P0}Hx|wwSc9JP%m8dMJA*q&VFB0yMI@5vWoAGraygwn){R+Cj6B1a2Px z5)u(K5{+;z2n*_XD!+Auv#LJEM)(~Hx{$Yb^ldQmcYF2zNH1V30*)CN_|1$v2|`LnFUT$%-tO0Eg|c5$BB~yDfzS zcOXJ$wpzVK0MfTjBJ0b$r#_OvAJ3WRt+YOLlJPYMx~qp>^$$$h#bc|`g0pF-Ao43? z>*A+8lx>}L{p(Tni2Vvk)dtzg$hUKjSjXRagj)$h#8=KV>5s)J4vGtRn5kP|AXIz! zPgbbVxW{2o4s-UM;c#We8P&mPN|DW7_uLF!a|^0S=wr6Esx9Z$2|c1?GaupU6$tb| zY_KU`(_29O_%k(;>^|6*pZURH3`@%EuKS;Ns z1lujmf;r{qAN&Q0&m{wJSZ8MeE7RM5+Sq;ul_ z`+ADrd_Um+G37js6tKsArNB}n{p*zTUxQr>3@wA;{EUbjNjlNd6$Mx zg0|MyU)v`sa~tEY5$en7^PkC=S<2@!nEdG6L=h(vT__0F=S8Y&eM=hal#7eM(o^Lu z2?^;05&|CNliYrq6gUv;|i!(W{0N)LWd*@{2q*u)}u*> z7MQgk6t9OqqXMln?zoMAJcc zMKaof_Up})q#DzdF?w^%tTI7STI^@8=Wk#enR*)&%8yje>+tKvUYbW8UAPg55xb70 zEn5&Ba~NmOJlgI#iS8W3-@N%>V!#z-ZRwfPO1)dQdQkaHsiqG|~we2ALqG7Ruup(DqSOft2RFg_X%3w?6VqvV1uzX_@F(diNVp z4{I|}35=11u$;?|JFBEE*gb;T`dy+8gWJ9~pNsecrO`t#V9jW-6mnfO@ff9od}b(3s4>p0i30gbGIv~1@a^F2kl7YO;DxmF3? zWi-RoXhzRJV0&XE@ACc?+@6?)LQ2XNm4KfalMtsc%4!Fn0rl zpHTrHwR>t>7W?t!Yc{*-^xN%9P0cs0kr=`?bQ5T*oOo&VRRu+1chM!qj%2I!@+1XF z4GWJ=7ix9;Wa@xoZ0RP`NCWw0*8247Y4jIZ>GEW7zuoCFXl6xIvz$ezsWgKdVMBH> z{o!A7f;R-@eK9Vj7R40xx)T<2$?F2E<>Jy3F;;=Yt}WE59J!1WN367 zA^6pu_zLoZIf*x031CcwotS{L8bJE(<_F%j_KJ2P_IusaZXwN$&^t716W{M6X2r_~ zaiMwdISX7Y&Qi&Uh0upS3TyEIXNDICQlT5fHXC`aji-c{U(J@qh-mWl-uMN|T&435 z5)a1dvB|oe%b2mefc=Vpm0C%IUYYh7HI*;3UdgNIz}R##(#{(_>82|zB0L*1i4B5j-xi9O4x10rs_J6*gdRBX=@VJ+==sWb&_Qc6tSOowM{BX@(zawtjl zdU!F4OYw2@Tk1L^%~JCwb|e#3CC>srRHQ*(N%!7$Mu_sKh@|*XtR>)BmWw!;8-mq7 zBBnbjwx8Kyv|hd*`5}84flTHR1Y@@uqjG`UG+jN_YK&RYTt7DVwfEDXDW4U+iO{>K zw1hr{_XE*S*K9TzzUlJH2rh^hUm2v7_XjwTuYap|>zeEDY$HOq3X4Tz^X}E9z)x4F zs+T?Ed+Hj<#jY-`Va~fT2C$=qFT-5q$@p9~0{G&eeL~tiIAHXA!f6C(rAlS^)&k<- zXU|ZVs}XQ>s5iONo~t!XXZgtaP$Iau;JT%h)>}v54yut~pykaNye4axEK#5@?TSsQ zE;Jvf9I$GVb|S`7$pG)4vgo9NXsKr?u=F!GnA%VS2z$@Z(!MR9?EPcAqi5ft)Iz6sNl`%kj+_H-X`R<>BFrBW=fSlD|{`D%@Rcbu2?%>t7i34k?Ujb)2@J-`j#4 zLK<69qcUuniIan-$A1+fR=?@+thwDIXtF1Tks@Br-xY zfB+zblrR(ke`U;6U~-;p1Kg8Lh6v~LjW@9l2P6s+?$2!ZRPX`(ZkRGe7~q(4&gEi<$ch`5kQ?*1=GSqkeV z{SA1EaW_A!t{@^UY2D^YO0(H@+kFVzZaAh0_`A`f(}G~EP~?B|%gtxu&g%^x{EYSz zk+T;_c@d;+n@$<>V%P=nk36?L!}?*=vK4>nJSm+1%a}9UlmTJTrfX4{Lb7smNQn@T zw9p2%(Zjl^bWGo1;DuMHN(djsEm)P8mEC2sL@KyPjwD@d%QnZ$ zMJ3cnn!_!iP{MzWk%PI&D?m?C(y2d|2VChluN^yHya(b`h>~GkI1y;}O_E57zOs!{ zt2C@M$^PR2U#(dZmA-sNreB@z-yb0Bf7j*yONhZG=onhx>t4)RB`r6&TP$n zgmN*)eCqvgriBO-abHQ8ECN0bw?z5Bxpx z=jF@?zFdVn?@gD5egM4o$m`}lV(CWrOKKq(sv*`mNcHcvw&Xryfw<{ch{O&qc#WCTXX6=#{MV@q#iHYba!OUY+MGeNTjP%Fj!WgM&`&RlI^=AWTOqy-o zHo9YFt!gQ*p7{Fl86>#-JLZo(b^O`LdFK~OsZBRR@6P?ad^Ujbqm_j^XycM4ZHFyg ziUbIFW#2tj`65~#2V!4z7DM8Z;fG0|APaQ{a2VNYpNotB7eZ5kp+tPDz&Lqs0j%Y4tA*URpcfi z_M(FD=fRGdqf430j}1z`O0I=;tLu81bwJXdYiN7_&a-?ly|-j*+=--XGvCq#32Gh(=|qj5F?kmihk{%M&$}udW5)DHK zF_>}5R8&&API}o0osZJRL3n~>76nUZ&L&iy^s>PMnNcYZ|9*1$v-bzbT3rpWsJ+y{ zPrg>5Zlery96Um?lc6L|)}&{992{_$J&=4%nRp9BAC6!IB=A&=tF>r8S*O-=!G(_( zwXbX_rGZgeiK*&n5E;f=k{ktyA1(;x_kiMEt0*gpp_4&(twlS2e5C?NoD{n>X2AT# zY@Zp?#!b1zNq96MQqeO*M1MMBin5v#RH52&Xd~DO6-BZLnA6xO1$sou(YJ1Dlc{WF zVa%2DyYm`V#81jP@70IJ;DX@y*iUt$MLm)ByAD$eUuji|5{ptFYq(q)mE(5bOpxjM z^Q`AHWq44SG3`_LxC9fwR)XRVIp=B%<(-lOC3jI#bb@dK(*vjom!=t|#<@dZql%>O z15y^{4tQoeW9Lu%G&V$90x6F)xN6y_oIn;!Q zs)8jT$;&;u%Y>=T3hg34A-+Y*na=|glcStr5D;&5*t5*DmD~x;zQAV5{}Ya`?RRGa zT*t9@$a~!co;pD^!J5bo?lDOWFx%)Y=-fJ+PDGc0>;=q=s?P4aHForSB+)v0WY2JH z?*`O;RHum6j%#LG)Vu#ciO#+jRC3!>T(9fr+XE7T2B7Z|0nR5jw@WG)kDDzTJ=o4~ zUpeyt7}_nd`t}j9BKqryOha{34erm)RmST)_9Aw)@ zHbiyg5n&E{_CQR@h<}34d7WM{s{%5wdty1l+KX8*?+-YkNK2Be*6&jc>@{Fd;Ps|| z26LqdI3#9le?;}risDq$K5G3yoqK}C^@-8z^wj%tdgw-6@F#Ju{Sg7+y)L?)U$ez> zoOaP$UFZ?y5BiFycir*pnaAaY+|%1%8&|(@VB)zweR%?IidwJyK5J!STzw&2RFx zZV@qeaCB01Hu#U9|1#=Msc8Pgz5P*4Lrp!Q+~(G!OiNR{qa7|r^H?FC6gVhkk3y7=uW#Sh;&>78bZ}aK*C#NH$9rX@M3f{nckYI+5QG?Aj1DM)@~z_ zw!UAD@gedTlePB*%4+55naJ8ak_;))#S;4ji!LOqY5VRI){GMwHR~}6t4g>5C_#U# ztYC!tjKjrKvRy=GAsJVK++~$|+s!w9z3H4G^mACv=EErXNSmH7qN}%PKcN|8%9=i)qS5+$L zu&ya~HW%RMVJi4T^pv?>mw*Gf<)-7gf#Qj|e#w2|v4#t!%Jk{&xlf;$_?jW*n!Pyx zkG$<18kiLOAUPuFfyu-EfWX%4jYnjBYc~~*9JEz6oa)_R|8wjZA|RNrAp%}14L7fW zi7A5Wym*K+V8pkqqO-X#3ft{0qs?KVt^)?kS>AicmeO&q+~J~ zp0YJ_P~_a8j= zsAs~G=8F=M{4GZL{|B__UorX@MRNQLn?*_gym4aW(~+i13knnk1P=khoC-ViMZk+x zLW(l}oAg1H`dU+Fv**;qw|ANDSRs>cGqL!Yw^`; zv;{E&8CNJcc)GHzTYM}f&NPw<6j{C3gaeelU#y!M)w-utYEHOCCJo|Vgp7K6C_$14 zqIrLUB0bsgz^D%V%fbo2f9#yb#CntTX?55Xy|Kps&Xek*4_r=KDZ z+`TQuv|$l}MWLzA5Ay6Cvsa^7xvwXpy?`w(6vx4XJ zWuf1bVSb#U8{xlY4+wlZ$9jjPk)X_;NFMqdgq>m&W=!KtP+6NL57`AMljW+es zzqjUjgz;V*kktJI?!NOg^s_)ph45>4UDA!Vo0hn>KZ+h-3=?Y3*R=#!fOX zP$Y~+14$f66ix?UWB_6r#fMcC^~X4R-<&OD1CSDNuX~y^YwJ>sW0j`T<2+3F9>cLo z#!j57$ll2K9(%$4>eA7(>FJX5e)pR5&EZK!IMQzOfik#FU*o*LGz~7u(8}XzIQRy- z!U7AlMTIe|DgQFmc%cHy_9^{o`eD%ja_L>ckU6$O4*U**o5uR7`FzqkU8k4gxtI=o z^P^oGFPm5jwZMI{;nH}$?p@uV8FT4r=|#GziKXK07bHJLtK}X%I0TON$uj(iJ`SY^ zc$b2CoxCQ>7LH@nxcdW&_C#fMYBtTxcg46dL{vf%EFCZ~eErMvZq&Z%Lhumnkn^4A zsx$ay(FnN7kYah}tZ@0?-0Niroa~13`?hVi6`ndno`G+E8;$<6^gsE-K3)TxyoJ4M zb6pj5=I8^FD5H@`^V#Qb2^0cx7wUz&cruA5g>6>qR5)O^t1(-qqP&1g=qvY#s&{bx zq8Hc%LsbK1*%n|Y=FfojpE;w~)G0-X4i*K3{o|J7`krhIOd*c*$y{WIKz2n2*EXEH zT{oml3Th5k*vkswuFXdGDlcLj15Nec5pFfZ*0?XHaF_lVuiB%Pv&p7z)%38}%$Gup zVTa~C8=cw%6BKn_|4E?bPNW4PT7}jZQLhDJhvf4z;~L)506IE0 zX!tWXX(QOQPRj-p80QG79t8T2^az4Zp2hOHziQlvT!|H)jv{Ixodabzv6lBj)6WRB z{)Kg@$~~(7$-az?lw$4@L%I&DI0Lo)PEJJziWP33a3azb?jyXt1v0N>2kxwA6b%l> zZqRpAo)Npi&loWbjFWtEV)783BbeIAhqyuc+~>i7aQ8shIXt)bjCWT6$~ro^>99G} z2XfmT0(|l!)XJb^E!#3z4oEGIsL(xd; zYX1`1I(cG|u#4R4T&C|m*9KB1`UzKvho5R@1eYtUL9B72{i(ir&ls8g!pD ztR|25xGaF!4z5M+U@@lQf(12?xGy`!|3E}7pI$k`jOIFjiDr{tqf0va&3pOn6Pu)% z@xtG2zjYuJXrV)DUrIF*y<1O1<$#54kZ#2;=X51J^F#0nZ0(;S$OZDt_U2bx{RZ=Q zMMdd$fH|!s{ zXq#l;{`xfV`gp&C>A`WrQU?d{!Ey5(1u*VLJt>i27aZ-^&2IIk=zP5p+{$q(K?2(b z8?9h)kvj9SF!Dr zoyF}?V|9;6abHxWk2cEvGs$-}Pg}D+ZzgkaN&$Snp%;5m%zh1E#?Wac-}x?BYlGN#U#Mek*}kek#I9XaHt?mz3*fDrRTQ#&#~xyeqJk1QJ~E$7qsw6 z?sV;|?*=-{M<1+hXoj?@-$y+(^BJ1H~wQ9G8C0#^aEAyhDduNX@haoa=PuPp zYsGv8UBfQaRHgBgLjmP^eh>fLMeh{8ic)?xz?#3kX-D#Z{;W#cd_`9OMFIaJg-=t`_3*!YDgtNQ2+QUEAJB9M{~AvT$H`E)IKmCR21H532+ata8_i_MR@ z2Xj<3w<`isF~Ah$W{|9;51ub*f4#9ziKrOR&jM{x7I_7()O@`F*5o$KtZ?fxU~g`t zUovNEVKYn$U~VX8eR)qb`7;D8pn*Pp$(otYTqL)5KH$lUS-jf}PGBjy$weoceAcPp z&5ZYB$r&P$MN{0H0AxCe4Qmd3T%M*5d4i%#!nmBCN-WU-4m4Tjxn-%j3HagwTxCZ9 z)j5vO-C7%s%D!&UfO>bi2oXiCw<-w{vVTK^rVbv#W=WjdADJy8$khnU!`ZWCIU`># zyjc^1W~pcu>@lDZ{zr6gv%)2X4n27~Ve+cQqcND%0?IFSP4sH#yIaXXYAq^z3|cg` z`I3$m%jra>e2W-=DiD@84T!cb%||k)nPmEE09NC%@PS_OLhkrX*U!cgD*;;&gIaA(DyVT4QD+q_xu z>r`tg{hiGY&DvD-)B*h+YEd+Zn)WylQl}<4>(_NlsKXCRV;a)Rcw!wtelM2_rWX`j zTh5A|i6=2BA(iMCnj_fob@*eA;V?oa4Z1kRBGaU07O70fb6-qmA$Hg$ps@^ka1=RO zTbE_2#)1bndC3VuK@e!Sftxq4=Uux}fDxXE#Q5_x=E1h>T5`DPHz zbH<_OjWx$wy7=%0!mo*qH*7N4tySm+R0~(rbus`7;+wGh;C0O%x~fEMkt!eV>U$`i z5>Q(o z=t$gPjgGh0&I7KY#k50V7DJRX<%^X z>6+ebc9efB3@eE2Tr){;?_w`vhgF>`-GDY(YkR{9RH(MiCnyRtd!LxXJ75z+?2 zGi@m^+2hKJ5sB1@Xi@s_@p_Kwbc<*LQ_`mr^Y%j}(sV_$`J(?_FWP)4NW*BIL~sR>t6 zM;qTJZ~GoY36&{h-Pf}L#y2UtR}>ZaI%A6VkU>vG4~}9^i$5WP2Tj?Cc}5oQxe2=q z8BeLa$hwCg_psjZyC2+?yX4*hJ58Wu^w9}}7X*+i5Rjqu5^@GzXiw#SUir1G1`jY% zOL=GE_ENYxhcyUrEt9XlMNP6kx6h&%6^u3@zB8KUCAa18T(R2J`%JjWZ z!{7cXaEW+Qu*iJPu+m>QqW}Lo$4Z+!I)0JNzZ&_M%=|B1yejFRM04bGAvu{=lNPd+ zJRI^DRQ(?FcVUD+bgEcAi@o(msqys9RTCG#)TjI!9~3-dc`>gW;HSJuQvH~d`MQs86R$|SKXHh zqS9Qy)u;T`>>a!$LuaE2keJV%;8g)tr&Nnc;EkvA-RanHXsy)D@XN0a>h}z2j81R; zsUNJf&g&rKpuD0WD@=dDrPHdBoK42WoBU|nMo17o(5^;M|dB4?|FsAGVrSyWcI`+FVw^vTVC`y}f(BwJl zrw3Sp151^9=}B})6@H*i4-dIN_o^br+BkcLa^H56|^2XsT0dESw2 zMX>(KqNl=x2K5=zIKg}2JpGAZu{I_IO}0$EQ5P{4zol**PCt3F4`GX}2@vr8#Y)~J zKb)gJeHcFnR@4SSh%b;c%J`l=W*40UPjF#q{<}ywv-=vHRFmDjv)NtmC zQx9qm)d%0zH&qG7AFa3VAU1S^(n8VFTC~Hb+HjYMjX8r#&_0MzlNR*mnLH5hi}`@{ zK$8qiDDvS_(L9_2vHgzEQ${DYSE;DqB!g*jhJghE&=LTnbgl&Xepo<*uRtV{2wDHN z)l;Kg$TA>Y|K8Lc&LjWGj<+bp4Hiye_@BfU(y#nF{fpR&|Ltbye?e^j0}8JC4#xi% zv29ZR%8%hk=3ZDvO-@1u8KmQ@6p%E|dlHuy#H1&MiC<*$YdLkHmR#F3ae;bKd;@*i z2_VfELG=B}JMLCO-6UQy^>RDE%K4b>c%9ki`f~Z2Qu8hO7C#t%Aeg8E%+}6P7Twtg z-)dj(w}_zFK&86KR@q9MHicUAucLVshUdmz_2@32(V`y3`&Kf8Q2I)+!n0mR=rrDU zXvv^$ho;yh*kNqJ#r1}b0|i|xRUF6;lhx$M*uG3SNLUTC@|htC z-=fsw^F%$qqz4%QdjBrS+ov}Qv!z00E+JWas>p?z@=t!WWU3K*?Z(0meTuTOC7OTx zU|kFLE0bLZ+WGcL$u4E}5dB0g`h|uwv3=H6f+{5z9oLv-=Q45+n~V4WwgO=CabjM% zBAN+RjM65(-}>Q2V#i1Na@a0`08g&y;W#@sBiX6Tpy8r}*+{RnyGUT`?XeHSqo#|J z^ww~c;ou|iyzpErDtlVU=`8N7JSu>4M z_pr9=tX0edVn9B}YFO2y(88j#S{w%E8vVOpAboK*27a7e4Ekjt0)hIX99*1oE;vex z7#%jhY=bPijA=Ce@9rRO(Vl_vnd00!^TAc<+wVvRM9{;hP*rqEL_(RzfK$er_^SN; z)1a8vo8~Dr5?;0X0J62Cusw$A*c^Sx1)dom`-)Pl7hsW4i(r*^Mw`z5K>!2ixB_mu z*Ddqjh}zceRFdmuX1akM1$3>G=#~|y?eYv(e-`Qy?bRHIq=fMaN~fB zUa6I8Rt=)jnplP>yuS+P&PxeWpJ#1$F`iqRl|jF$WL_aZFZl@kLo&d$VJtu&w?Q0O zzuXK>6gmygq(yXJy0C1SL}T8AplK|AGNUOhzlGeK_oo|haD@)5PxF}rV+5`-w{Aag zus45t=FU*{LguJ11Sr-28EZkq;!mJO7AQGih1L4rEyUmp>B!%X0YemsrV3QFvlgt* z5kwlPzaiJ+kZ^PMd-RRbl(Y?F*m`4*UIhIuf#8q>H_M=fM*L_Op-<_r zBZagV=4B|EW+KTja?srADTZXCd3Yv%^Chfpi)cg{ED${SI>InNpRj5!euKv?=Xn92 zsS&FH(*w`qLIy$doc>RE&A5R?u zzkl1sxX|{*fLpXvIW>9d<$ePROttn3oc6R!sN{&Y+>Jr@yeQN$sFR z;w6A<2-0%UA?c8Qf;sX7>>uKRBv3Ni)E9pI{uVzX|6Bb0U)`lhLE3hK58ivfRs1}d zNjlGK0hdq0qjV@q1qI%ZFMLgcpWSY~mB^LK)4GZ^h_@H+3?dAe_a~k*;9P_d7%NEFP6+ zgV(oGr*?W(ql?6SQ~`lUsjLb%MbfC4V$)1E0Y_b|OIYxz4?O|!kRb?BGrgiH5+(>s zoqM}v*;OBfg-D1l`M6T6{K`LG+0dJ1)!??G5g(2*vlNkm%Q(MPABT$r13q?|+kL4- zf)Mi5r$sn;u41aK(K#!m+goyd$c!KPl~-&-({j#D4^7hQkV3W|&>l_b!}!z?4($OA z5IrkfuT#F&S1(`?modY&I40%gtroig{YMvF{K{>5u^I51k8RriGd${z)=5k2tG zM|&Bp5kDTfb#vfuTTd?)a=>bX=lokw^y9+2LS?kwHQIWI~pYgy7 zb?A-RKVm_vM5!9?C%qYdfRAw& zAU7`up~%g=p@}pg#b7E)BFYx3g%(J36Nw(Dij!b>cMl@CSNbrW!DBDbTD4OXk!G4x zi}JBKc8HBYx$J~31PXH+4^x|UxK~(<@I;^3pWN$E=sYma@JP|8YL`L(zI6Y#c%Q{6 z*APf`DU$S4pr#_!60BH$FGViP14iJmbrzSrOkR;f3YZa{#E7Wpd@^4E-zH8EgPc-# zKWFPvh%WbqU_%ZEt`=Q?odKHc7@SUmY{GK`?40VuL~o)bS|is$Hn=<=KGHOsEC5tB zFb|q}gGlL97NUf$G$>^1b^3E18PZ~Pm9kX%*ftnolljiEt@2#F2R5ah$zbXd%V_Ev zyDd{1o_uuoBga$fB@Fw!V5F3jIr=a-ykqrK?WWZ#a(bglI_-8pq74RK*KfQ z0~Dzus7_l;pMJYf>Bk`)`S8gF!To-BdMnVw5M-pyu+aCiC5dwNH|6fgRsIKZcF&)g zr}1|?VOp}I3)IR@m1&HX1~#wsS!4iYqES zK}4J{Ei>;e3>LB#Oly>EZkW14^@YmpbgxCDi#0RgdM${&wxR+LiX}B+iRioOB0(pDKpVEI;ND?wNx>%e|m{RsqR_{(nmQ z3ZS}@t!p4a(BKx_-CYwrcyJ5u1TO9bcXti$8sy>xcLKqKCc#~UOZYD{llKTSFEjJ~ zyNWt>tLU}*>^`TvPxtP%F`ZJQw@W0^>x;!^@?k_)9#bF$j0)S3;mH-IR5y82l|%=F z2lR8zhP?XNP-ucZZ6A+o$xOyF!w;RaLHGh57GZ|TCXhJqY~GCh)aXEV$1O&$c}La1 zjuJxkY9SM4av^Hb;i7efiYaMwI%jGy`3NdY)+mcJhF(3XEiSlU3c|jMBi|;m-c?~T z+x0_@;SxcoY=(6xNgO$bBt~Pj8`-<1S|;Bsjrzw3@zSjt^JC3X3*$HI79i~!$RmTz zsblZsLYs7L$|=1CB$8qS!tXrWs!F@BVuh?kN(PvE5Av-*r^iYu+L^j^m9JG^#=m>@ z=1soa)H*w6KzoR$B8mBCXoU;f5^bVuwQ3~2LKg!yxomG1#XPmn(?YH@E~_ED+W6mxs%x{%Z<$pW`~ON1~2XjP5v(0{C{+6Dm$00tsd3w=f=ZENy zOgb-=f}|Hb*LQ$YdWg<(u7x3`PKF)B7ZfZ6;1FrNM63 z?O6tE%EiU@6%rVuwIQjvGtOofZBGZT1Sh(xLIYt9c4VI8`!=UJd2BfLjdRI#SbVAX ziT(f*RI^T!IL5Ac>ql7uduF#nuCRJ1)2bdvAyMxp-5^Ww5p#X{rb5)(X|fEhDHHW{ zw(Lfc$g;+Q`B0AiPGtmK%*aWfQQ$d!*U<|-@n2HZvCWSiw^I>#vh+LyC;aaVWGbmkENr z&kl*8o^_FW$T?rDYLO1Pyi%>@&kJKQoH2E0F`HjcN}Zlnx1ddoDA>G4Xu_jyp6vuT zPvC}pT&Owx+qB`zUeR|4G;OH(<<^_bzkjln0k40t`PQxc$7h(T8Ya~X+9gDc8Z9{Z z&y0RAU}#_kQGrM;__MK9vwIwK^aoqFhk~dK!ARf1zJqHMxF2?7-8|~yoO@_~Ed;_wvT%Vs{9RK$6uUQ|&@#6vyBsFK9eZW1Ft#D2)VpQRwpR(;x^ zdoTgMqfF9iBl%{`QDv7B0~8{8`8k`C4@cbZAXBu00v#kYl!#_Wug{)2PwD5cNp?K^ z9+|d-4z|gZ!L{57>!Ogfbzchm>J1)Y%?NThxIS8frAw@z>Zb9v%3_3~F@<=LG%r*U zaTov}{{^z~SeX!qgSYow`_5)ij*QtGp4lvF`aIGQ>@3ZTkDmsl#@^5*NGjOuu82}o zzLF~Q9SW+mP=>88%eSA1W4_W7-Q>rdq^?t=m6}^tDPaBRGFLg%ak93W!kOp#EO{6& zP%}Iff5HZQ9VW$~+9r=|Quj#z*=YwcnssS~9|ub2>v|u1JXP47vZ1&L1O%Z1DsOrDfSIMHU{VT>&>H=9}G3i@2rP+rx@eU@uE8rJNec zij~#FmuEBj03F1~ct@C@$>y)zB+tVyjV3*n`mtAhIM0$58vM9jOQC}JJOem|EpwqeMuYPxu3sv}oMS?S#o6GGK@8PN59)m&K4Dc&X% z(;XL_kKeYkafzS3Wn5DD>Yiw{LACy_#jY4op(>9q>>-*9@C0M+=b#bknAWZ37^(Ij zq>H%<@>o4a#6NydoF{_M4i4zB_KG)#PSye9bk0Ou8h%1Dtl7Q_y#7*n%g)?m>xF~( zjqvOwC;*qvN_3(*a+w2|ao0D?@okOvg8JskUw(l7n`0fncglavwKd?~l_ryKJ^Ky! zKCHkIC-o7%fFvPa$)YNh022lakMar^dgL=t#@XLyNHHw!b?%WlM)R@^!)I!smZL@k zBi=6wE5)2v&!UNV(&)oOYW(6Qa!nUjDKKBf-~Da=#^HE4(@mWk)LPvhyN3i4goB$3K8iV7uh zsv+a?#c4&NWeK(3AH;ETrMOIFgu{_@%XRwCZ;L=^8Ts)hix4Pf3yJRQ<8xb^CkdmC z?c_gB)XmRsk`9ch#tx4*hO=#qS7={~Vb4*tTf<5P%*-XMfUUYkI9T1cEF;ObfxxI-yNuA=I$dCtz3ey znVkctYD*`fUuZ(57+^B*R=Q}~{1z#2!ca?)+YsRQb+lt^LmEvZt_`=j^wqig+wz@n@ z`LIMQJT3bxMzuKg8EGBU+Q-6cs5(@5W?N>JpZL{$9VF)veF`L5%DSYTNQEypW%6$u zm_~}T{HeHj1bAlKl8ii92l9~$dm=UM21kLemA&b$;^!wB7#IKWGnF$TVq!!lBlG4 z{?Rjz?P(uvid+|i$VH?`-C&Gcb3{(~Vpg`w+O);Wk1|Mrjxrht0GfRUnZqz2MhrXa zqgVC9nemD5)H$to=~hp)c=l9?#~Z_7i~=U-`FZxb-|TR9@YCxx;Zjo-WpMNOn2)z) zFPGGVl%3N$f`gp$gPnWC+f4(rmts%fidpo^BJx72zAd7|*Xi{2VXmbOm)1`w^tm9% znM=0Fg4bDxH5PxPEm{P3#A(mxqlM7SIARP?|2&+c7qmU8kP&iApzL|F>Dz)Ixp_`O zP%xrP1M6@oYhgo$ZWwrAsYLa4 z|I;DAvJxno9HkQrhLPQk-8}=De{9U3U%)dJ$955?_AOms!9gia%)0E$Mp}$+0er@< zq7J&_SzvShM?e%V?_zUu{niL@gt5UFOjFJUJ}L?$f%eU%jUSoujr{^O=?=^{19`ON zlRIy8Uo_nqcPa6@yyz`CM?pMJ^^SN^Fqtt`GQ8Q#W4kE7`V9^LT}j#pMChl!j#g#J zr-=CCaV%xyFeQ9SK+mG(cTwW*)xa(eK;_Z(jy)woZp~> zA(4}-&VH+TEeLzPTqw&FOoK(ZjD~m{KW05fiGLe@E3Z2`rLukIDahE*`u!ubU)9`o zn^-lyht#E#-dt~S>}4y$-mSbR8{T@}22cn^refuQ08NjLOv?JiEWjyOnzk<^R5%gO zhUH_B{oz~u#IYwVnUg8?3P*#DqD8#X;%q%HY**=I>>-S|!X*-!x1{^l#OnR56O>iD zc;i;KS+t$koh)E3)w0OjWJl_aW2;xF=9D9Kr>)(5}4FqUbk# zI#$N8o0w;IChL49m9CJTzoC!|u{Ljd%ECgBOf$}&jA^$(V#P#~)`&g`H8E{uv52pp zwto`xUL-L&WTAVREEm$0g_gYPL(^vHq(*t1WCH_6alhkeW&GCZ3hL)|{O-jiFOBrF z!EW=Jej|dqQitT6!B-7&io2K)WIm~Q)v@yq%U|VpV+I?{y0@Yd%n8~-NuuM*pM~KA z85YB};IS~M(c<}4Hxx>qRK0cdl&e?t253N%vefkgds>Ubn8X}j6Vpgs>a#nFq$osY z1ZRwLqFv=+BTb=i%D2Wv>_yE0z}+niZ4?rE|*a3d7^kndWGwnFqt+iZ(7+aln<}jzbAQ(#Z2SS}3S$%Bd}^ zc9ghB%O)Z_mTZMRC&H#)I#fiLuIkGa^`4e~9oM5zKPx?zjkC&Xy0~r{;S?FS%c7w< zWbMpzc(xSw?9tGxG~_l}Acq}zjt5ClaB7-!vzqnlrX;}$#+PyQ9oU)_DfePh2E1<7 ztok6g6K^k^DuHR*iJ?jw?bs_whk|bx`dxu^nC6#e{1*m~z1eq7m}Cf$*^Eua(oi_I zAL+3opNhJteu&mWQ@kQWPucmiP)4|nFG`b2tpC;h{-PI@`+h?9v=9mn|0R-n8#t=+Z*FD(c5 zjj79Jxkgck*DV=wpFgRZuwr%}KTm+dx?RT@aUHJdaX-ODh~gByS?WGx&czAkvkg;x zrf92l8$Or_zOwJVwh>5rB`Q5_5}ef6DjS*$x30nZbuO3dijS*wvNEqTY5p1_A0gWr znH<(Qvb!os14|R)n2Ost>jS2;d1zyLHu`Svm|&dZD+PpP{Bh>U&`Md;gRl64q;>{8MJJM$?UNUd`aC>BiLe>*{ zJY15->yW+<3rLgYeTruFDtk1ovU<$(_y7#HgUq>)r0{^}Xbth}V#6?%5jeFYt;SG^ z3qF)=uWRU;Jj)Q}cpY8-H+l_n$2$6{ZR?&*IGr{>ek!69ZH0ZoJ*Ji+ezzlJ^%qL3 zO5a`6gwFw(moEzqxh=yJ9M1FTn!eo&qD#y5AZXErHs%22?A+JmS&GIolml!)rZTnUDM3YgzYfT#;OXn)`PWv3Ta z!-i|-Wojv*k&bC}_JJDjiAK(Ba|YZgUI{f}TdEOFT2+}nPmttytw7j%@bQZDV1vvj z^rp{gRkCDmYJHGrE1~e~AE!-&6B6`7UxVQuvRrfdFkGX8H~SNP_X4EodVd;lXd^>eV1jN+Tt4}Rsn)R0LxBz0c=NXU|pUe!MQQFkGBWbR3&(jLm z%RSLc#p}5_dO{GD=DEFr=Fc% z85CBF>*t!6ugI?soX(*JNxBp+-DdZ4X0LldiK}+WWGvXV(C(Ht|!3$psR=&c*HIM=BmX;pRIpz@Ale{9dhGe(U2|Giv;# zOc|;?p67J=Q(kamB*aus=|XP|m{jN^6@V*Bpm?ye56Njh#vyJqE=DweC;?Rv7faX~ zde03n^I~0B2vUmr;w^X37tVxUK?4}ifsSH5_kpKZIzpYu0;Kv}SBGfI2AKNp+VN#z`nI{UNDRbo-wqa4NEls zICRJpu)??cj^*WcZ^MAv+;bDbh~gpN$1Cor<{Y2oyIDws^JsfW^5AL$azE(T0p&pP z1Mv~6Q44R&RHoH95&OuGx2srIr<@zYJTOMKiVs;Bx3py89I87LOb@%mr`0)#;7_~Z zzcZj8?w=)>%5@HoCHE_&hnu(n_yQ-L(~VjpjjkbT7e)Dk5??fApg(d>vwLRJ-x{um z*Nt?DqTSxh_MIyogY!vf1mU1`Gld-&L)*43f6dilz`Q@HEz;+>MDDYv9u!s;WXeao zUq=TaL$P*IFgJzrGc>j1dDOd zed+=ZBo?w4mr$2)Ya}?vedDopomhW1`#P<%YOJ_j=WwClX0xJH-f@s?^tmzs_j7t!k zK@j^zS0Q|mM4tVP5Ram$VbS6|YDY&y?Q1r1joe9dj08#CM{RSMTU}(RCh`hp_Rkl- zGd|Cv~G@F{DLhCizAm9AN!^{rNs8hu!G@8RpnGx7e`-+K$ffN<0qjR zGq^$dj_Tv!n*?zOSyk5skI7JVKJ)3jysnjIu-@VSzQiP8r6MzudCU=~?v-U8yzo^7 zGf~SUTvEp+S*!X9uX!sq=o}lH;r{pzk~M*VA(uyQ`3C8!{C;)&6)95fv(cK!%Cuz$ z_Zal57H6kPN>25KNiI6z6F)jzEkh#%OqU#-__Xzy)KyH};81#N6OfX$$IXWzOn`Q& z4f$Z1t>)8&8PcYfEwY5UadU1yg+U*(1m2ZlHoC-!2?gB!!fLhmTl))D@dhvkx#+Yj z1O=LV{(T%{^IeCuFK>%QR!VZ4GnO5tK8a+thWE zg4VytZrwcS?7^ zuZfhYnB8dwd%VLO?DK7pV5Wi<(`~DYqOXn8#jUIL^)12*Dbhk4GmL_E2`WX&iT16o zk(t|hok(Y|v-wzn?4x34T)|+SfZP>fiq!><*%vnxGN~ypST-FtC+@TPv*vYv@iU!_ z@2gf|PrgQ?Ktf*9^CnJ(x*CtZVB8!OBfg0%!wL;Z8(tYYre0vcnPGlyCc$V(Ipl*P z_(J!a=o@vp^%Efme!K74(Ke7A>Y}|sxV+JL^aYa{~m%5#$$+R1? zGaQhZTTX!#s#=Xtpegqero$RNt&`4xn3g$)=y*;=N=Qai)}~`xtxI_N*#MMCIq#HFifT zz(-*m;pVH&+4bixL&Bbg)W5FN^bH87pAHp)zPkWNMfTFqS=l~AC$3FX3kQUSh_C?-ZftyClgM)o_D7cX$RGlEYblux0jv5 zTr|i-I3@ZPCGheCl~BGhImF)K4!9@?pC(gi3ozX=a!|r1)LFxy_8c&wY0<^{2cm|P zv6Y`QktY*;I)IUd5y3ne1CqpVanlY45z8hf4&$EUBnucDj16pDa4&GI&TArYhf*xh zdj>*%APH8(h~c>o@l#%T>R$e>rwVx_WUB|~V`p^JHsg*y12lzj&zF}w6W09HwB2yb z%Q~`es&(;7#*DUC_w-Dmt7|$*?TA_m;zB+-u{2;Bg{O}nV7G_@7~<)Bv8fH^G$XG8$(&{A zwXJK5LRK%M34(t$&NI~MHT{UQ9qN-V_yn|%PqC81EIiSzmMM=2zb`mIwiP_b)x+2M z7Gd`83h79j#SItpQ}luuf2uOU`my_rY5T{6P#BNlb%h%<#MZb=m@y5aW;#o1^2Z)SWo+b`y0gV^iRcZtz5!-05vF z7wNo=hc6h4hc&s@uL^jqRvD6thVYtbErDK9k!;+a0xoE0WL7zLixjn5;$fXvT=O3I zT6jI&^A7k6R{&5#lVjz#8%_RiAa2{di{`kx79K+j72$H(!ass|B%@l%KeeKchYLe_ z>!(JC2fxsv>XVen+Y42GeYPxMWqm`6F$(E<6^s|g(slNk!lL*6v^W2>f6hh^mE$s= z3D$)}{V5(Qm&A6bp%2Q}*GZ5Qrf}n7*Hr51?bJOyA-?B4vg6y_EX<*-e20h{=0Mxs zbuQGZ$fLyO5v$nQ&^kuH+mNq9O#MWSfThtH|0q1i!NrWj^S}_P;Q1OkYLW6U^?_7G zx2wg?CULj7))QU(n{$0JE%1t2dWrMi2g-Os{v|8^wK{@qlj%+1b^?NI z$}l2tjp0g>K3O+p%yK<9!XqmQ?E9>z&(|^Pi~aSRwI5x$jaA62GFz9%fmO3t3a>cq zK8Xbv=5Ps~4mKN5+Eqw12(!PEyedFXv~VLxMB~HwT1Vfo51pQ#D8e$e4pFZ{&RC2P z5gTIzl{3!&(tor^BwZfR8j4k{7Rq#`riKXP2O-Bh66#WWK2w=z;iD9GLl+3 zpHIaI4#lQ&S-xBK8PiQ%dwOh?%BO~DCo06pN7<^dnZCN@NzY{_Z1>rrB0U|nC&+!2 z2y!oBcTd2;@lzyk(B=TkyZ)zy0deK05*Q0zk+o$@nun`VI1Er7pjq>8V zNmlW{p7S^Btgb(TA}jL(uR>`0w8gHP^T~Sh5Tkip^spk4SBAhC{TZU}_Z)UJw-}zm zPq{KBm!k)?P{`-(9?LFt&YN4s%SIZ-9lJ!Ws~B%exHOeVFk3~}HewnnH(d)qkLQ_d z6h>O)pEE{vbOVw}E+jdYC^wM+AAhaI(YAibUc@B#_mDss0Ji&BK{WG`4 zOk>vSNq(Bq2IB@s>>Rxm6Wv?h;ZXkpb1l8u|+_qXWdC*jjcPCixq;!%BVPSp#hP zqo`%cNf&YoQXHC$D=D45RiT|5ngPlh?0T~?lUf*O)){K@*Kbh?3RW1j9-T?%lDk@y z4+~?wKI%Y!-=O|_IuKz|=)F;V7ps=5@g)RrE;;tvM$gUhG>jHcw2Hr@fS+k^Zr~>G z^JvPrZc}_&d_kEsqAEMTMJw!!CBw)u&ZVzmq+ZworuaE&TT>$pYsd9|g9O^0orAe8 z221?Va!l1|Y5X1Y?{G7rt1sX#qFA^?RLG^VjoxPf63;AS=_mVDfGJKg73L zsGdnTUD40y(>S##2l|W2Cy!H(@@5KBa(#gs`vlz}Y~$ot5VsqPQ{{YtjYFvIumZzt zA{CcxZLJR|4#{j7k~Tu*jkwz8QA|5G1$Cl895R`Zyp;irp1{KN){kB30O8P1W5;@bG znvX74roeMmQlUi=v9Y%(wl$ZC#9tKNFpvi3!C}f1m6Ct|l2g%psc{TJp)@yu)*e2> z((p0Fg*8gJ!|3WZke9;Z{8}&NRkv7iP=#_y-F}x^y?2m%-D_aj^)f04%mneyjo_;) z6qc_Zu$q37d~X``*eP~Q>I2gg%rrV8v=kDfpp$=%Vj}hF)^dsSWygoN(A$g*E=Do6FX?&(@F#7pbiJ`;c0c@Ul zDqW_90Wm#5f2L<(Lf3)3TeXtI7nhYwRm(F;*r_G6K@OPW4H(Y3O5SjUzBC}u3d|eQ8*8d@?;zUPE+i#QNMn=r(ap?2SH@vo*m z3HJ%XuG_S6;QbWy-l%qU;8x;>z>4pMW7>R}J%QLf%@1BY(4f_1iixd-6GlO7Vp*yU zp{VU^3?s?90i=!#>H`lxT!q8rk>W_$2~kbpz7eV{3wR|8E=8**5?qn8#n`*(bt1xRQrdGxyx2y%B$qmw#>ZV$c7%cO#%JM1lY$Y0q?Yuo> ze9KdJoiM)RH*SB%^;TAdX-zEjA7@%y=!0=Zg%iWK7jVI9b&Dk}0$Af&08KHo+ zOwDhFvA(E|ER%a^cdh@^wLUlmIv6?_3=BvX8jKk92L=Y}7Jf5OGMfh` zBdR1wFCi-i5@`9km{isRb0O%TX+f~)KNaEz{rXQa89`YIF;EN&gN)cigu6mNh>?Cm zAO&Im2flv6D{jwm+y<%WsPe4!89n~KN|7}Cb{Z;XweER73r}Qp2 zz}WP4j}U0&(uD&9yGy6`!+_v-S(yG*iytsTR#x_Rc>=6u^vnRDnf1gP{#2>`ffrAC% zTZ5WQ@hAK;P;>kX{D)mIXe4%a5p=LO1xXH@8T?mz7Q@d)$3pL{{B!2{-v70L*o1AO+|n5beiw~ zk@(>m?T3{2k2c;NWc^`4@P&Z?BjxXJ@;x1qhn)9Mn*IFdt_J-dIqx5#d`NfyfX~m( zIS~5)MfZ2Uy?_4W`47i}u0ZgPh<{D|w_d#;D}Q&U$Q-G}xM1A@1f{#%A$jh6Qp&0hQ<0bPOM z-{1Wm&p%%#eb_?x7i;bol EfAhh=DF6Tf literal 0 HcmV?d00001 diff --git a/demo/.mvn/wrapper/maven-wrapper.properties b/demo/.mvn/wrapper/maven-wrapper.properties new file mode 100644 index 0000000..642d572 --- /dev/null +++ b/demo/.mvn/wrapper/maven-wrapper.properties @@ -0,0 +1,2 @@ +distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.6.3/apache-maven-3.6.3-bin.zip +wrapperUrl=https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.5.6/maven-wrapper-0.5.6.jar diff --git a/demo/README.md b/demo/README.md new file mode 100644 index 0000000..e8693bd --- /dev/null +++ b/demo/README.md @@ -0,0 +1,30 @@ +# security-jwt-quickstart project + +This project uses Quarkus, the Supersonic Subatomic Java Framework. + +If you want to learn more about Quarkus, please visit its website: https://quarkus.io/ . + +## Running the application in dev mode + +You can run your application in dev mode that enables live coding using: +``` +./mvnw quarkus:dev +``` + +## Packaging and running the application + +The application can be packaged using `./mvnw package`. +It produces the `security-jwt-quickstart-1.0-SNAPSHOT-runner.jar` file in the `/target` directory. +Be aware that it’s not an _über-jar_ as the dependencies are copied into the `target/lib` directory. + +The application is now runnable using `java -jar target/security-jwt-quickstart-1.0-SNAPSHOT-runner.jar`. + +## Creating a native executable + +You can create a native executable using: `./mvnw package -Pnative`. + +Or, if you don't have GraalVM installed, you can run the native executable build in a container using: `./mvnw package -Pnative -Dquarkus.native.container-build=true`. + +You can then execute your native executable with: `./target/security-jwt-quickstart-1.0-SNAPSHOT-runner` + +If you want to learn more about building native executables, please consult https://quarkus.io/guides/building-native-image-guide. \ No newline at end of file diff --git a/demo/mvnw b/demo/mvnw new file mode 100755 index 0000000..41c0f0c --- /dev/null +++ b/demo/mvnw @@ -0,0 +1,310 @@ +#!/bin/sh +# ---------------------------------------------------------------------------- +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# ---------------------------------------------------------------------------- + +# ---------------------------------------------------------------------------- +# Maven Start Up Batch script +# +# Required ENV vars: +# ------------------ +# JAVA_HOME - location of a JDK home dir +# +# Optional ENV vars +# ----------------- +# M2_HOME - location of maven2's installed home dir +# MAVEN_OPTS - parameters passed to the Java VM when running Maven +# e.g. to debug Maven itself, use +# set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +# MAVEN_SKIP_RC - flag to disable loading of mavenrc files +# ---------------------------------------------------------------------------- + +if [ -z "$MAVEN_SKIP_RC" ] ; then + + if [ -f /etc/mavenrc ] ; then + . /etc/mavenrc + fi + + if [ -f "$HOME/.mavenrc" ] ; then + . "$HOME/.mavenrc" + fi + +fi + +# OS specific support. $var _must_ be set to either true or false. +cygwin=false; +darwin=false; +mingw=false +case "`uname`" in + CYGWIN*) cygwin=true ;; + MINGW*) mingw=true;; + Darwin*) darwin=true + # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home + # See https://developer.apple.com/library/mac/qa/qa1170/_index.html + if [ -z "$JAVA_HOME" ]; then + if [ -x "/usr/libexec/java_home" ]; then + export JAVA_HOME="`/usr/libexec/java_home`" + else + export JAVA_HOME="/Library/Java/Home" + fi + fi + ;; +esac + +if [ -z "$JAVA_HOME" ] ; then + if [ -r /etc/gentoo-release ] ; then + JAVA_HOME=`java-config --jre-home` + fi +fi + +if [ -z "$M2_HOME" ] ; then + ## resolve links - $0 may be a link to maven's home + PRG="$0" + + # need this for relative symlinks + while [ -h "$PRG" ] ; do + ls=`ls -ld "$PRG"` + link=`expr "$ls" : '.*-> \(.*\)$'` + if expr "$link" : '/.*' > /dev/null; then + PRG="$link" + else + PRG="`dirname "$PRG"`/$link" + fi + done + + saveddir=`pwd` + + M2_HOME=`dirname "$PRG"`/.. + + # make it fully qualified + M2_HOME=`cd "$M2_HOME" && pwd` + + cd "$saveddir" + # echo Using m2 at $M2_HOME +fi + +# For Cygwin, ensure paths are in UNIX format before anything is touched +if $cygwin ; then + [ -n "$M2_HOME" ] && + M2_HOME=`cygpath --unix "$M2_HOME"` + [ -n "$JAVA_HOME" ] && + JAVA_HOME=`cygpath --unix "$JAVA_HOME"` + [ -n "$CLASSPATH" ] && + CLASSPATH=`cygpath --path --unix "$CLASSPATH"` +fi + +# For Mingw, ensure paths are in UNIX format before anything is touched +if $mingw ; then + [ -n "$M2_HOME" ] && + M2_HOME="`(cd "$M2_HOME"; pwd)`" + [ -n "$JAVA_HOME" ] && + JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`" +fi + +if [ -z "$JAVA_HOME" ]; then + javaExecutable="`which javac`" + if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then + # readlink(1) is not available as standard on Solaris 10. + readLink=`which readlink` + if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then + if $darwin ; then + javaHome="`dirname \"$javaExecutable\"`" + javaExecutable="`cd \"$javaHome\" && pwd -P`/javac" + else + javaExecutable="`readlink -f \"$javaExecutable\"`" + fi + javaHome="`dirname \"$javaExecutable\"`" + javaHome=`expr "$javaHome" : '\(.*\)/bin'` + JAVA_HOME="$javaHome" + export JAVA_HOME + fi + fi +fi + +if [ -z "$JAVACMD" ] ; then + if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD="$JAVA_HOME/jre/sh/java" + else + JAVACMD="$JAVA_HOME/bin/java" + fi + else + JAVACMD="`which java`" + fi +fi + +if [ ! -x "$JAVACMD" ] ; then + echo "Error: JAVA_HOME is not defined correctly." >&2 + echo " We cannot execute $JAVACMD" >&2 + exit 1 +fi + +if [ -z "$JAVA_HOME" ] ; then + echo "Warning: JAVA_HOME environment variable is not set." +fi + +CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher + +# traverses directory structure from process work directory to filesystem root +# first directory with .mvn subdirectory is considered project base directory +find_maven_basedir() { + + if [ -z "$1" ] + then + echo "Path not specified to find_maven_basedir" + return 1 + fi + + basedir="$1" + wdir="$1" + while [ "$wdir" != '/' ] ; do + if [ -d "$wdir"/.mvn ] ; then + basedir=$wdir + break + fi + # workaround for JBEAP-8937 (on Solaris 10/Sparc) + if [ -d "${wdir}" ]; then + wdir=`cd "$wdir/.."; pwd` + fi + # end of workaround + done + echo "${basedir}" +} + +# concatenates all lines of a file +concat_lines() { + if [ -f "$1" ]; then + echo "$(tr -s '\n' ' ' < "$1")" + fi +} + +BASE_DIR=`find_maven_basedir "$(pwd)"` +if [ -z "$BASE_DIR" ]; then + exit 1; +fi + +########################################################################################## +# Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +# This allows using the maven wrapper in projects that prohibit checking in binary data. +########################################################################################## +if [ -r "$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" ]; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found .mvn/wrapper/maven-wrapper.jar" + fi +else + if [ "$MVNW_VERBOSE" = true ]; then + echo "Couldn't find .mvn/wrapper/maven-wrapper.jar, downloading it ..." + fi + if [ -n "$MVNW_REPOURL" ]; then + jarUrl="$MVNW_REPOURL/io/takari/maven-wrapper/0.5.6/maven-wrapper-0.5.6.jar" + else + jarUrl="https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.5.6/maven-wrapper-0.5.6.jar" + fi + while IFS="=" read key value; do + case "$key" in (wrapperUrl) jarUrl="$value"; break ;; + esac + done < "$BASE_DIR/.mvn/wrapper/maven-wrapper.properties" + if [ "$MVNW_VERBOSE" = true ]; then + echo "Downloading from: $jarUrl" + fi + wrapperJarPath="$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" + if $cygwin; then + wrapperJarPath=`cygpath --path --windows "$wrapperJarPath"` + fi + + if command -v wget > /dev/null; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found wget ... using wget" + fi + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + wget "$jarUrl" -O "$wrapperJarPath" + else + wget --http-user=$MVNW_USERNAME --http-password=$MVNW_PASSWORD "$jarUrl" -O "$wrapperJarPath" + fi + elif command -v curl > /dev/null; then + if [ "$MVNW_VERBOSE" = true ]; then + echo "Found curl ... using curl" + fi + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + curl -o "$wrapperJarPath" "$jarUrl" -f + else + curl --user $MVNW_USERNAME:$MVNW_PASSWORD -o "$wrapperJarPath" "$jarUrl" -f + fi + + else + if [ "$MVNW_VERBOSE" = true ]; then + echo "Falling back to using Java to download" + fi + javaClass="$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.java" + # For Cygwin, switch paths to Windows format before running javac + if $cygwin; then + javaClass=`cygpath --path --windows "$javaClass"` + fi + if [ -e "$javaClass" ]; then + if [ ! -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then + if [ "$MVNW_VERBOSE" = true ]; then + echo " - Compiling MavenWrapperDownloader.java ..." + fi + # Compiling the Java class + ("$JAVA_HOME/bin/javac" "$javaClass") + fi + if [ -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then + # Running the downloader + if [ "$MVNW_VERBOSE" = true ]; then + echo " - Running MavenWrapperDownloader.java ..." + fi + ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$MAVEN_PROJECTBASEDIR") + fi + fi + fi +fi +########################################################################################## +# End of extension +########################################################################################## + +export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"} +if [ "$MVNW_VERBOSE" = true ]; then + echo $MAVEN_PROJECTBASEDIR +fi +MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS" + +# For Cygwin, switch paths to Windows format before running java +if $cygwin; then + [ -n "$M2_HOME" ] && + M2_HOME=`cygpath --path --windows "$M2_HOME"` + [ -n "$JAVA_HOME" ] && + JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"` + [ -n "$CLASSPATH" ] && + CLASSPATH=`cygpath --path --windows "$CLASSPATH"` + [ -n "$MAVEN_PROJECTBASEDIR" ] && + MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"` +fi + +# Provide a "standardized" way to retrieve the CLI args that will +# work with both Windows and non-Windows executions. +MAVEN_CMD_LINE_ARGS="$MAVEN_CONFIG $@" +export MAVEN_CMD_LINE_ARGS + +WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +exec "$JAVACMD" \ + $MAVEN_OPTS \ + -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \ + "-Dmaven.home=${M2_HOME}" "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \ + ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@" diff --git a/demo/mvnw.cmd b/demo/mvnw.cmd new file mode 100644 index 0000000..8611571 --- /dev/null +++ b/demo/mvnw.cmd @@ -0,0 +1,182 @@ +@REM ---------------------------------------------------------------------------- +@REM Licensed to the Apache Software Foundation (ASF) under one +@REM or more contributor license agreements. See the NOTICE file +@REM distributed with this work for additional information +@REM regarding copyright ownership. The ASF licenses this file +@REM to you under the Apache License, Version 2.0 (the +@REM "License"); you may not use this file except in compliance +@REM with the License. You may obtain a copy of the License at +@REM +@REM http://www.apache.org/licenses/LICENSE-2.0 +@REM +@REM Unless required by applicable law or agreed to in writing, +@REM software distributed under the License is distributed on an +@REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +@REM KIND, either express or implied. See the License for the +@REM specific language governing permissions and limitations +@REM under the License. +@REM ---------------------------------------------------------------------------- + +@REM ---------------------------------------------------------------------------- +@REM Maven Start Up Batch script +@REM +@REM Required ENV vars: +@REM JAVA_HOME - location of a JDK home dir +@REM +@REM Optional ENV vars +@REM M2_HOME - location of maven2's installed home dir +@REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands +@REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a keystroke before ending +@REM MAVEN_OPTS - parameters passed to the Java VM when running Maven +@REM e.g. to debug Maven itself, use +@REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +@REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files +@REM ---------------------------------------------------------------------------- + +@REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on' +@echo off +@REM set title of command window +title %0 +@REM enable echoing by setting MAVEN_BATCH_ECHO to 'on' +@if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO% + +@REM set %HOME% to equivalent of $HOME +if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%") + +@REM Execute a user defined script before this one +if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre +@REM check for pre script, once with legacy .bat ending and once with .cmd ending +if exist "%HOME%\mavenrc_pre.bat" call "%HOME%\mavenrc_pre.bat" +if exist "%HOME%\mavenrc_pre.cmd" call "%HOME%\mavenrc_pre.cmd" +:skipRcPre + +@setlocal + +set ERROR_CODE=0 + +@REM To isolate internal variables from possible post scripts, we use another setlocal +@setlocal + +@REM ==== START VALIDATION ==== +if not "%JAVA_HOME%" == "" goto OkJHome + +echo. +echo Error: JAVA_HOME not found in your environment. >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +:OkJHome +if exist "%JAVA_HOME%\bin\java.exe" goto init + +echo. +echo Error: JAVA_HOME is set to an invalid directory. >&2 +echo JAVA_HOME = "%JAVA_HOME%" >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +@REM ==== END VALIDATION ==== + +:init + +@REM Find the project base dir, i.e. the directory that contains the folder ".mvn". +@REM Fallback to current working directory if not found. + +set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR% +IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir + +set EXEC_DIR=%CD% +set WDIR=%EXEC_DIR% +:findBaseDir +IF EXIST "%WDIR%"\.mvn goto baseDirFound +cd .. +IF "%WDIR%"=="%CD%" goto baseDirNotFound +set WDIR=%CD% +goto findBaseDir + +:baseDirFound +set MAVEN_PROJECTBASEDIR=%WDIR% +cd "%EXEC_DIR%" +goto endDetectBaseDir + +:baseDirNotFound +set MAVEN_PROJECTBASEDIR=%EXEC_DIR% +cd "%EXEC_DIR%" + +:endDetectBaseDir + +IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig + +@setlocal EnableExtensions EnableDelayedExpansion +for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a +@endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS% + +:endReadAdditionalConfig + +SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe" +set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar" +set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +set DOWNLOAD_URL="https://repo.maven.apache.org/maven2/io/takari/maven-wrapper/0.5.6/maven-wrapper-0.5.6.jar" + +FOR /F "tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO ( + IF "%%A"=="wrapperUrl" SET DOWNLOAD_URL=%%B +) + +@REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +@REM This allows using the maven wrapper in projects that prohibit checking in binary data. +if exist %WRAPPER_JAR% ( + if "%MVNW_VERBOSE%" == "true" ( + echo Found %WRAPPER_JAR% + ) +) else ( + if not "%MVNW_REPOURL%" == "" ( + SET DOWNLOAD_URL="%MVNW_REPOURL%/io/takari/maven-wrapper/0.5.6/maven-wrapper-0.5.6.jar" + ) + if "%MVNW_VERBOSE%" == "true" ( + echo Couldn't find %WRAPPER_JAR%, downloading it ... + echo Downloading from: %DOWNLOAD_URL% + ) + + powershell -Command "&{"^ + "$webclient = new-object System.Net.WebClient;"^ + "if (-not ([string]::IsNullOrEmpty('%MVNW_USERNAME%') -and [string]::IsNullOrEmpty('%MVNW_PASSWORD%'))) {"^ + "$webclient.Credentials = new-object System.Net.NetworkCredential('%MVNW_USERNAME%', '%MVNW_PASSWORD%');"^ + "}"^ + "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $webclient.DownloadFile('%DOWNLOAD_URL%', '%WRAPPER_JAR%')"^ + "}" + if "%MVNW_VERBOSE%" == "true" ( + echo Finished downloading %WRAPPER_JAR% + ) +) +@REM End of extension + +@REM Provide a "standardized" way to retrieve the CLI args that will +@REM work with both Windows and non-Windows executions. +set MAVEN_CMD_LINE_ARGS=%* + +%MAVEN_JAVA_EXE% %JVM_CONFIG_MAVEN_PROPS% %MAVEN_OPTS% %MAVEN_DEBUG_OPTS% -classpath %WRAPPER_JAR% "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %* +if ERRORLEVEL 1 goto error +goto end + +:error +set ERROR_CODE=1 + +:end +@endlocal & set ERROR_CODE=%ERROR_CODE% + +if not "%MAVEN_SKIP_RC%" == "" goto skipRcPost +@REM check for post script, once with legacy .bat ending and once with .cmd ending +if exist "%HOME%\mavenrc_post.bat" call "%HOME%\mavenrc_post.bat" +if exist "%HOME%\mavenrc_post.cmd" call "%HOME%\mavenrc_post.cmd" +:skipRcPost + +@REM pause the script if MAVEN_BATCH_PAUSE is set to 'on' +if "%MAVEN_BATCH_PAUSE%" == "on" pause + +if "%MAVEN_TERMINATE_CMD%" == "on" exit %ERROR_CODE% + +exit /B %ERROR_CODE% diff --git a/demo/pom.xml b/demo/pom.xml new file mode 100644 index 0000000..787ab55 --- /dev/null +++ b/demo/pom.xml @@ -0,0 +1,126 @@ + + + 4.0.0 + + + org.pagan.quarkus + extensions + 1.0-SNAPSHOT + + + demo + + + + + + ${quarkus.platform.group-id} + ${quarkus.platform.artifact-id} + ${quarkus.platform.version} + pom + import + + + + + + io.quarkus + quarkus-resteasy + + + org.pagan.quarkus + jedis + 1.0-SNAPSHOT + + + org.pagan.quarkus + janitor + 1.0-SNAPSHOT + + + org.pagan.quarkus + cayenne + 1.0-SNAPSHOT + + + io.quarkus + quarkus-jdbc-postgresql + + + + + + io.quarkus + quarkus-maven-plugin + ${quarkus-plugin.version} + + + + build + + + + + + maven-compiler-plugin + ${compiler-plugin.version} + + + maven-surefire-plugin + ${surefire-plugin.version} + + + org.jboss.logmanager.LogManager + + + + + + + + native + + + native + + + + + + maven-failsafe-plugin + ${surefire-plugin.version} + + + + integration-test + verify + + + + ${project.build.directory}/${project.build.finalName}-runner + + + + + + + + + native + + + + diff --git a/demo/src/main/docker/Dockerfile.jvm b/demo/src/main/docker/Dockerfile.jvm new file mode 100644 index 0000000..e5a2cbd --- /dev/null +++ b/demo/src/main/docker/Dockerfile.jvm @@ -0,0 +1,47 @@ +#### +# This Dockerfile is used in order to build a container that runs the Quarkus application in JVM mode +# +# Before building the docker image run: +# +# mvn package +# +# Then, build the image with: +# +# docker build -f src/main/docker/Dockerfile.jvm -t quarkus/security-jwt-quickstart-jvm . +# +# Then run the container using: +# +# docker run -i --rm -p 8080:8080 quarkus/security-jwt-quickstart-jvm +# +### +FROM registry.access.redhat.com/ubi8/ubi-minimal:8.1 + +ARG JAVA_PACKAGE=java-11-openjdk-headless +ARG RUN_JAVA_VERSION=1.3.5 + +ENV LANG='en_US.UTF-8' LANGUAGE='en_US:en' + +# Install java and the run-java script +# Also set up permissions for user `1001` +RUN microdnf install openssl curl ca-certificates ${JAVA_PACKAGE} \ + && microdnf update \ + && microdnf clean all \ + && mkdir /deployments \ + && chown 1001 /deployments \ + && chmod "g+rwX" /deployments \ + && chown 1001:root /deployments \ + && curl https://repo1.maven.org/maven2/io/fabric8/run-java-sh/${RUN_JAVA_VERSION}/run-java-sh-${RUN_JAVA_VERSION}-sh.sh -o /deployments/run-java.sh \ + && chown 1001 /deployments/run-java.sh \ + && chmod 540 /deployments/run-java.sh \ + && echo "securerandom.source=file:/dev/urandom" >> /etc/alternatives/jre/lib/security/java.security + +# Configure the JAVA_OPTIONS, you can add -XshowSettings:vm to also display the heap size. +ENV JAVA_OPTIONS="-Dquarkus.http.host=0.0.0.0 -Djava.util.logging.manager=org.jboss.logmanager.LogManager" + +COPY target/lib/* /deployments/lib/ +COPY target/*-runner.jar /deployments/app.jar + +EXPOSE 8080 +USER 1001 + +ENTRYPOINT [ "/deployments/run-java.sh" ] \ No newline at end of file diff --git a/demo/src/main/docker/Dockerfile.native b/demo/src/main/docker/Dockerfile.native new file mode 100644 index 0000000..d7e28ca --- /dev/null +++ b/demo/src/main/docker/Dockerfile.native @@ -0,0 +1,30 @@ +#### +# This Dockerfile is used in order to build a container that runs the Quarkus application in native (no JVM) mode +# +# Before building the docker image run: +# +# mvn package -Pnative -Dquarkus.native.container-build=true +# +# Then, build the image with: +# +# docker build -f src/main/docker/Dockerfile.native -t quarkus/security-jwt-quickstart . +# +# Then run the container using: +# +# docker run -i --rm -p 8080:8080 quarkus/security-jwt-quickstart +# +### +FROM registry.access.redhat.com/ubi8/ubi-minimal:8.1 +WORKDIR /work/ +COPY target/*-runner /work/application + +# set up permissions for user `1001` +RUN chmod 775 /work /work/application \ + && chown -R 1001 /work \ + && chmod -R "g+rwX" /work \ + && chown -R 1001:root /work + +EXPOSE 8080 +USER 1001 + +CMD ["./application", "-Dquarkus.http.host=0.0.0.0"] \ No newline at end of file diff --git a/demo/src/main/java/org/pagan/janitor/LoginResource.java b/demo/src/main/java/org/pagan/janitor/LoginResource.java new file mode 100644 index 0000000..879e682 --- /dev/null +++ b/demo/src/main/java/org/pagan/janitor/LoginResource.java @@ -0,0 +1,39 @@ +package org.pagan.janitor; + +import javax.annotation.security.RolesAllowed; +import javax.enterprise.context.RequestScoped; +import javax.inject.Inject; +import javax.ws.rs.FormParam; +import javax.ws.rs.POST; +import javax.ws.rs.Path; +import javax.ws.rs.Produces; +import javax.ws.rs.core.Response; +import javax.ws.rs.core.MediaType; +import org.pagan.janitor.cache.SessionCacheImpl; +import org.pagan.janitor.cache.SessionInfo; + +@Path("/auth") +@RequestScoped +public class LoginResource { + + @Inject + SessionInfo session; + + @Inject + SessionCacheImpl sessionCache; + + @POST + @Path("/login") + @Produces(MediaType.APPLICATION_JSON) + @RolesAllowed({"anonymous"}) + public Response login (@FormParam("login") String login, @FormParam("pass") String pass) { +// System.out.println(login + " : " + pass); + if (login.equals("demo") && pass.equals("demo")) { + SessionInfo si = new SessionInfo().role("admin");//.name("demo"); + return sessionCache.loginSuccessResponse(si); + } else { + return Response.status(Response.Status.FORBIDDEN).build(); + } + } + +} \ No newline at end of file diff --git a/demo/src/main/java/org/pagan/janitor/TokenSecuredResource.java b/demo/src/main/java/org/pagan/janitor/TokenSecuredResource.java new file mode 100644 index 0000000..0c93b95 --- /dev/null +++ b/demo/src/main/java/org/pagan/janitor/TokenSecuredResource.java @@ -0,0 +1,123 @@ +package org.pagan.janitor; + + +import javax.annotation.security.PermitAll; +import javax.annotation.security.RolesAllowed; +import javax.enterprise.context.RequestScoped; +import javax.inject.Inject; +import javax.ws.rs.GET; +import javax.ws.rs.Path; +import javax.ws.rs.Produces; +import javax.ws.rs.core.MediaType; +import org.pagan.janitor.cache.SessionInfo; + +//import org.eclipse.microprofile.jwt.JsonWebToken; + +/** + * Version 2 of the TokenSecuredResource + */ +@Path("/test") +@RequestScoped +public class TokenSecuredResource { + + +// @Inject +// CayenneSupport cayenne; +// +// @Inject +// JedisSupport jedis; + + @Inject + SessionInfo session; + + @GET + @Produces(MediaType.TEXT_PLAIN) + @PermitAll + public String get () { +// System.out.println(session.role()); + return "permit-all"; + } + + + + @GET + @Path("/admin") + @Produces(MediaType.TEXT_PLAIN) + @RolesAllowed({"devel", "admin", "user"}) + public String init() { + long start = System.currentTimeMillis(); +// StringBuilder sb = new StringBuilder(); +// +// for (int i = 0; i < 20; i++) { +// try (Jedis jedisContext = jedis.context()) { +// +// HashMap info = new HashMap() { +// { +// put("created_at", "100100"); +// put("expires_at", "200200"); +// put("role", "admin"); +// put("last_action_at", String.valueOf(System.currentTimeMillis())); +// } +// }; +// jedisContext.hset("", info); +// } +// } +// +// ObjectContext cayenneContext = cayenne.context(); +// long count = ObjectSelect.query(SecUser.class).selectCount(cayenneContext); +//// System.out.println("count = " + count); +// System.out.println(System.currentTimeMillis()); +// ObjectSelect.query(SecUser.class).iterate(cayenneContext, (SecUser a) -> { +////// System.out.println(a.getFirstName() + " " + a.getLastName()); +// }); +//// try (ResultBatchIterator batchIterator = ObjectSelect.query(SecUser.class).batchIterator(cayenneContext, 100)) { +//// for (List list : batchIterator) { +//// for (SecUser a : list) { +////// sb.append(a.getFirstName().substring(0,1) + ""); +//// for (int i = 0; i < 20; i++) { +////// sb.append(a.getLastName() + " " + a.getFirstName() + " " + a.getMiddleName() + " (" + a.getContactEmail() + ") "); +//// } +//// +////// System.out.println(a.getFirstName() + " " + a.getLastName() + " "); +//// } +//// } +//// } +//// while (batchIterator.hasNext()) { +//// List next = batchIterator.next(); +//// for (SecUser user : next) { +////// System.out.println("user = " + user.getFirstName() + ":" + user.getLastName()); +//// } +//// } +// +//// throw new UnsupportedOperationException("asd"); +//// ObjectContext newContext = serverRuntime.newContext(); + return String.valueOf(System.currentTimeMillis() - start); + } + +// @Inject +// JsonWebToken jwt; + +// @GET() +// @Path("permit-all") +// @PermitAll +// @Produces(MediaType.TEXT_PLAIN) +// public String hello(@Context SecurityContext ctx) { +// Principal caller = ctx.getUserPrincipal(); +// String name = caller == null ? "anonymous" : caller.getName(); +// String helloReply = String.format("hello + %s, isSecure: %s, authScheme: %s", name, ctx.isSecure(), ctx.getAuthenticationScheme()); +// return helloReply; +// } +// +// @GET() +// @Path("roles-allowed") +// @RolesAllowed({"Echoer", "Subscriber"}) +// @Produces(MediaType.TEXT_PLAIN) +// public String helloRolesAllowed(@Context SecurityContext ctx) { +// Principal caller = ctx.getUserPrincipal(); +// String name = caller == null ? "anonymous" : caller.getName(); +//// boolean hasJWT = jwt.getClaimNames() != null; +//// String helloReply = String.format("hello + %s, isSecure: %s, authScheme: %s, hasJWT: %s", name, ctx.isSecure(), ctx.getAuthenticationScheme(), hasJWT); +//// return helloReply; +// return "2" +// } +} \ No newline at end of file diff --git a/demo/src/main/java/org/pagan/janitor/session/DemoCache.java b/demo/src/main/java/org/pagan/janitor/session/DemoCache.java new file mode 100644 index 0000000..2f403a7 --- /dev/null +++ b/demo/src/main/java/org/pagan/janitor/session/DemoCache.java @@ -0,0 +1,59 @@ +package org.pagan.janitor.session; + +import java.util.Map; +import javax.enterprise.context.ApplicationScoped; +import javax.inject.Inject; +import org.pagan.janitor.cache.SessionCacheImpl; +import org.pagan.janitor.cache.SessionInfo; +import org.pagan.quarkus.jedis.JedisSupport; +import redis.clients.jedis.Jedis; + +/** + * + * @author Edward M. Kagan + */ +@ApplicationScoped +public class DemoCache extends SessionCacheImpl { + + @Inject + JedisSupport jedisSupport; + + @Override + public SessionInfo get(String sessionId) { + Map session; + try (Jedis jedis = jedisSupport.context()) { + session = jedis.hgetAll(sessionId); + } + return new SessionInfo() + .sessionId(sessionId) + .csrfToken(session.get("csrf")) + .role(session.get("role")) +// .name(session.get("name")) + .createdAt(Long.valueOf(session.get("created"))) + .expiresAt(Long.valueOf(session.get("expires"))); + } + + @Override + public void put(String sessionId, SessionInfo sessionInfo) { + try (Jedis jedis = jedisSupport.context()) { + jedis.hset(sessionId, "csrf", sessionInfo.csrfToken()); + jedis.hset(sessionId, "role", sessionInfo.role()); +// jedis.hset(sessionId, "name", sessionInfo.name()); + jedis.hset(sessionId, "created", String.valueOf(sessionInfo.createdAt())); + jedis.hset(sessionId, "expires", String.valueOf(sessionInfo.expiresAt())); + jedis.expire(sessionId, config.sessionLifetime.intValue()); + } + } + + @Override + public void del(String sessionId) { + try (Jedis jedis = jedisSupport.context()) { + jedis.hdel(sessionId, "csrf"); + jedis.hdel(sessionId, "role"); +// jedis.hdel(sessionId, "name"); + jedis.hdel(sessionId, "created"); + jedis.hdel(sessionId, "expires"); + } + } + +} diff --git a/demo/src/main/resources/META-INF/resources/index.html b/demo/src/main/resources/META-INF/resources/index.html new file mode 100644 index 0000000..b7ebadb --- /dev/null +++ b/demo/src/main/resources/META-INF/resources/index.html @@ -0,0 +1,19 @@ + + + + + security-jwt-quickstart - 1.0-SNAPSHOT + + + +
+
+
+
+

+ +
+ + + + \ No newline at end of file diff --git a/demo/src/main/resources/application.properties b/demo/src/main/resources/application.properties new file mode 100644 index 0000000..90590d4 --- /dev/null +++ b/demo/src/main/resources/application.properties @@ -0,0 +1,29 @@ + +quarkus.banner.enabled=false + +# Cayenne model source +quarkus.cayenne.config=cayenne-expero.xml + +# Redis connection config +quarkus.jedis.shards=redis://localhost:6379 +quarkus.jedis.poolMax=40 +quarkus.jedis.maxWait=100500 +quarkus.jedis.log=true + +# Cayenne Data Source config +#quarkus.janitor.session-lifetime=3600 + +# Data Source config +quarkus.datasource.transactions=disabled +quarkus.datasource.initial-size=2 +quarkus.datasource.min-size=10 +quarkus.datasource.max-size=40 +quarkus.datasource.acquisition-timeout=10 +quarkus.datasource.url=jdbc:postgresql://localhost:5432/sqs_development +quarkus.datasource.driver=org.postgresql.Driver +quarkus.datasource.username=sqs_development +quarkus.datasource.password=sqs_development + +# quarkus +# quarkus.liquibase.change-log=db/liquibase-changelog-master.xml + diff --git a/demo/src/test/java/org/acme/security/jwt/NativeTokenSecuredResourceIT.java b/demo/src/test/java/org/acme/security/jwt/NativeTokenSecuredResourceIT.java new file mode 100644 index 0000000..7ec5a1b --- /dev/null +++ b/demo/src/test/java/org/acme/security/jwt/NativeTokenSecuredResourceIT.java @@ -0,0 +1,9 @@ +//package org.acme.security.jwt; +// +//import io.quarkus.test.junit.NativeImageTest; +// +//@NativeImageTest +//public class NativeTokenSecuredResourceIT extends TokenSecuredResourceTest { +// +// // Execute the same tests but in native mode. +//} \ No newline at end of file diff --git a/demo/src/test/java/org/acme/security/jwt/TokenSecuredResourceTest.java b/demo/src/test/java/org/acme/security/jwt/TokenSecuredResourceTest.java new file mode 100644 index 0000000..77c5ecd --- /dev/null +++ b/demo/src/test/java/org/acme/security/jwt/TokenSecuredResourceTest.java @@ -0,0 +1,21 @@ +//package org.acme.security.jwt; +// +//import io.quarkus.test.junit.QuarkusTest; +//import org.junit.jupiter.api.Test; +// +//import static io.restassured.RestAssured.given; +//import static org.hamcrest.CoreMatchers.is; +// +//@QuarkusTest +//public class TokenSecuredResourceTest { +// +// @Test +// public void testHelloEndpoint() { +// given() +// .when().get("/secured") +// .then() +// .statusCode(200) +// .body(is("hello")); +// } +// +//} \ No newline at end of file diff --git a/janitor/deployment/.classpath b/janitor/deployment/.classpath new file mode 100644 index 0000000..8131be0 --- /dev/null +++ b/janitor/deployment/.classpath @@ -0,0 +1,33 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/janitor/deployment/.project b/janitor/deployment/.project new file mode 100644 index 0000000..45ea084 --- /dev/null +++ b/janitor/deployment/.project @@ -0,0 +1,23 @@ + + + quarkus-smallrye-jwt-deployment + + + + + + org.eclipse.jdt.core.javabuilder + + + + + org.eclipse.m2e.core.maven2Builder + + + + + + org.eclipse.jdt.core.javanature + org.eclipse.m2e.core.maven2Nature + + diff --git a/janitor/deployment/.settings/org.eclipse.core.resources.prefs b/janitor/deployment/.settings/org.eclipse.core.resources.prefs new file mode 100644 index 0000000..cdfe4f1 --- /dev/null +++ b/janitor/deployment/.settings/org.eclipse.core.resources.prefs @@ -0,0 +1,5 @@ +eclipse.preferences.version=1 +encoding//src/main/java=UTF-8 +encoding//src/test/java=UTF-8 +encoding//src/test/resources=UTF-8 +encoding/=UTF-8 diff --git a/janitor/deployment/.settings/org.eclipse.jdt.core.prefs b/janitor/deployment/.settings/org.eclipse.jdt.core.prefs new file mode 100644 index 0000000..b8947ec --- /dev/null +++ b/janitor/deployment/.settings/org.eclipse.jdt.core.prefs @@ -0,0 +1,6 @@ +eclipse.preferences.version=1 +org.eclipse.jdt.core.compiler.codegen.targetPlatform=1.8 +org.eclipse.jdt.core.compiler.compliance=1.8 +org.eclipse.jdt.core.compiler.problem.forbiddenReference=warning +org.eclipse.jdt.core.compiler.release=disabled +org.eclipse.jdt.core.compiler.source=1.8 diff --git a/janitor/deployment/.settings/org.eclipse.m2e.core.prefs b/janitor/deployment/.settings/org.eclipse.m2e.core.prefs new file mode 100644 index 0000000..f897a7f --- /dev/null +++ b/janitor/deployment/.settings/org.eclipse.m2e.core.prefs @@ -0,0 +1,4 @@ +activeProfiles= +eclipse.preferences.version=1 +resolveWorkspaceProjects=true +version=1 diff --git a/janitor/deployment/pom.xml b/janitor/deployment/pom.xml new file mode 100644 index 0000000..bd463d3 --- /dev/null +++ b/janitor/deployment/pom.xml @@ -0,0 +1,63 @@ + + + 4.0.0 + + + org.pagan.quarkus + janitor-parent + 1.0-SNAPSHOT + + + janitor-deployment + ${project.artifactId} + + + + io.quarkus + quarkus-security-deployment + ${quarkus.platform.version} + + + io.quarkus + quarkus-vertx-web-deployment + ${quarkus.platform.version} + + + io.quarkus + quarkus-arc-deployment + ${quarkus.platform.version} + + + org.pagan.quarkus + janitor + 1.0-SNAPSHOT + + + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + diff --git a/janitor/deployment/src/main/java/pagan/janitor/JanitorProcessor.java b/janitor/deployment/src/main/java/pagan/janitor/JanitorProcessor.java new file mode 100644 index 0000000..526e2fa --- /dev/null +++ b/janitor/deployment/src/main/java/pagan/janitor/JanitorProcessor.java @@ -0,0 +1,54 @@ +package pagan.janitor; + +import io.quarkus.arc.deployment.AdditionalBeanBuildItem; +import io.quarkus.arc.deployment.BeanContainerBuildItem; +import io.quarkus.deployment.annotations.BuildProducer; +import io.quarkus.deployment.annotations.BuildStep; +import io.quarkus.deployment.annotations.ExecutionTime; +import io.quarkus.deployment.annotations.Record; +import io.quarkus.deployment.builditem.FeatureBuildItem; +import org.pagan.janitor.JanitorConfig; +import org.pagan.janitor.JanitorRecorder; +import org.pagan.janitor.cache.SessionCacheConfig; +import org.pagan.janitor.cache.SessionCacheImpl; +import org.pagan.janitor.cache.SessionInfo; +import org.pagan.janitor.security.JanitorAuthMechanism; +import org.pagan.janitor.security.JanitorPrincipalProducer; +import org.pagan.janitor.security.JanitorIdentityProvider; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +class JanitorProcessor { + + JanitorConfig config; + + @BuildStep + void registerAdditionalBeans(BuildProducer additionalBeans) { + AdditionalBeanBuildItem.Builder unremovable + = AdditionalBeanBuildItem.builder().setUnremovable(); + unremovable.addBeanClass(JanitorIdentityProvider.class); + unremovable.addBeanClass(JanitorAuthMechanism.class); + unremovable.addBeanClass(SessionInfo.class); + unremovable.addBeanClass(SessionCacheConfig.class); + additionalBeans.produce(unremovable.build()); + AdditionalBeanBuildItem.Builder removable = AdditionalBeanBuildItem.builder(); + removable.addBeanClass(SessionCacheImpl.class); + removable.addBeanClass(JanitorPrincipalProducer.class); + additionalBeans.produce(removable.build()); + } + + @BuildStep + FeatureBuildItem feature() { + return new FeatureBuildItem("janitor"); + } + + @BuildStep + @Record(ExecutionTime.RUNTIME_INIT) + void configureCache(JanitorRecorder recorder, BeanContainerBuildItem container) { + recorder.configureAuthMechanism(container.getValue(), config); + } + + +} diff --git a/janitor/pom.xml b/janitor/pom.xml new file mode 100644 index 0000000..bf41d26 --- /dev/null +++ b/janitor/pom.xml @@ -0,0 +1,22 @@ + + + 4.0.0 + + + org.pagan.quarkus + extensions + 1.0-SNAPSHOT + + + janitor-parent + ${project.artifactId} + pom + + + deployment + runtime + + + \ No newline at end of file diff --git a/janitor/runtime/.classpath b/janitor/runtime/.classpath new file mode 100644 index 0000000..5e8a55f --- /dev/null +++ b/janitor/runtime/.classpath @@ -0,0 +1,27 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/janitor/runtime/.project b/janitor/runtime/.project new file mode 100644 index 0000000..0b955f9 --- /dev/null +++ b/janitor/runtime/.project @@ -0,0 +1,23 @@ + + + quarkus-smallrye-jwt + + + + + + org.eclipse.jdt.core.javabuilder + + + + + org.eclipse.m2e.core.maven2Builder + + + + + + org.eclipse.jdt.core.javanature + org.eclipse.m2e.core.maven2Nature + + diff --git a/janitor/runtime/.settings/org.eclipse.core.resources.prefs b/janitor/runtime/.settings/org.eclipse.core.resources.prefs new file mode 100644 index 0000000..e9441bb --- /dev/null +++ b/janitor/runtime/.settings/org.eclipse.core.resources.prefs @@ -0,0 +1,3 @@ +eclipse.preferences.version=1 +encoding//src/main/java=UTF-8 +encoding/=UTF-8 diff --git a/janitor/runtime/.settings/org.eclipse.jdt.core.prefs b/janitor/runtime/.settings/org.eclipse.jdt.core.prefs new file mode 100644 index 0000000..b8947ec --- /dev/null +++ b/janitor/runtime/.settings/org.eclipse.jdt.core.prefs @@ -0,0 +1,6 @@ +eclipse.preferences.version=1 +org.eclipse.jdt.core.compiler.codegen.targetPlatform=1.8 +org.eclipse.jdt.core.compiler.compliance=1.8 +org.eclipse.jdt.core.compiler.problem.forbiddenReference=warning +org.eclipse.jdt.core.compiler.release=disabled +org.eclipse.jdt.core.compiler.source=1.8 diff --git a/janitor/runtime/.settings/org.eclipse.m2e.core.prefs b/janitor/runtime/.settings/org.eclipse.m2e.core.prefs new file mode 100644 index 0000000..f897a7f --- /dev/null +++ b/janitor/runtime/.settings/org.eclipse.m2e.core.prefs @@ -0,0 +1,4 @@ +activeProfiles= +eclipse.preferences.version=1 +resolveWorkspaceProjects=true +version=1 diff --git a/janitor/runtime/pom.xml b/janitor/runtime/pom.xml new file mode 100644 index 0000000..551fb24 --- /dev/null +++ b/janitor/runtime/pom.xml @@ -0,0 +1,97 @@ + + + 4.0.0 + + + org.pagan.quarkus + janitor-parent + 1.0-SNAPSHOT + + + janitor + ${project.artifactId} + + + + io.quarkus + quarkus-resteasy + + + io.quarkus + quarkus-core + ${quarkus.platform.version} + + + io.quarkus + quarkus-vertx-web + ${quarkus.platform.version} + + + io.quarkus + quarkus-security + ${quarkus.platform.version} + + + + + org.pagan.quarkus + cayenne + 1.0-SNAPSHOT + + + + + + + + io.quarkus + quarkus-bootstrap-maven-plugin + ${quarkus.platform.version} + + + + extension-descriptor + + + ${project.groupId}:${project.artifactId}-deployment:${project.version} + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/JanitorConfig.java b/janitor/runtime/src/main/java/org/pagan/janitor/JanitorConfig.java new file mode 100644 index 0000000..dec231b --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/JanitorConfig.java @@ -0,0 +1,79 @@ +package org.pagan.janitor; + +import io.quarkus.runtime.annotations.ConfigItem; +import io.quarkus.runtime.annotations.ConfigRoot; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ + @ConfigRoot(name = "janitor") +public class JanitorConfig { + + /** + * Session cookie name + */ + @ConfigItem(defaultValue = "session") + public String cookieName; + + /** + * CSRF protection enabled + */ + @ConfigItem(defaultValue = "false") + public boolean csrfDisabled; + + /** + * CSRF token updated on each request + */ + @ConfigItem(defaultValue = "false") + public boolean oneTimeCsrfToken; + + /** + * CSRF token updates after each POST, DELETE, UPDATE and PUT request + */ + @ConfigItem(defaultValue = "true") + public boolean oneCommitCsrfToken; + + /** + * CSRF token updates randomly on some requests based + */ + @ConfigItem(defaultValue = "false") + public boolean randomUpdateCsrf; + + /** + * Is last accessed path stored in session + */ + @ConfigItem(defaultValue = "true") + public boolean trackLastPath; + + /** + * Is last access time stored in session + */ + @ConfigItem(defaultValue = "true") + public boolean trackLastAccessTime; + + /** + * If true session expiration time will be extended on each access + */ + @ConfigItem(defaultValue = "true") + public boolean extendSessionOnAccess; + + /** + * Session lifetime in seconds + */ + @ConfigItem(defaultValue = "60") + public Long sessionLifetime; + + /** + * Configures header or cookie name + */ + @ConfigItem(defaultValue = "X-CSRF-TOKEN") + public String csrfName; + + /** + * If true janitor put csrf token in cookie + */ + @ConfigItem(defaultValue = "false") + public boolean csrfInCookie; + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/JanitorRecorder.java b/janitor/runtime/src/main/java/org/pagan/janitor/JanitorRecorder.java new file mode 100644 index 0000000..f4c67fb --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/JanitorRecorder.java @@ -0,0 +1,35 @@ +package org.pagan.janitor; + +import io.quarkus.arc.runtime.BeanContainer; +import io.quarkus.runtime.annotations.Recorder; +import org.pagan.janitor.cache.SessionCacheConfig; +//import org.pagan.janitor.cache.CayenneSessionCache; +import org.pagan.janitor.security.JanitorAuthMechanism; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +@Recorder +public class JanitorRecorder { + +// public void configureCache( +// BeanContainer container, +// int sessionLifeTime, +// String coockieName) { +// CayenneSessionCache sessionCache = container.instance(CayenneSessionCache.class); +// sessionCache.setSessionLifeTime(sessionLifeTime); +// sessionCache.setCoockieName(coockieName); +// } + + public void configureAuthMechanism(BeanContainer container, JanitorConfig config) { + + SessionCacheConfig cacheConfig = container.instance(SessionCacheConfig.class); + cacheConfig.setConfig(config); + + JanitorAuthMechanism authMechanism = container.instance(JanitorAuthMechanism.class); + authMechanism.setConfig(config); + + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCache.java b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCache.java new file mode 100644 index 0000000..e21746f --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCache.java @@ -0,0 +1,15 @@ +package org.pagan.janitor.cache; + +import javax.ws.rs.core.Response; + +/** + * + * @author pagan + */ +public interface SessionCache { + + public SessionInfo get(String sessionId); + public void put(String sessionId, SessionInfo sessionInfo); + public void del(String sessionId); + public Response loginSuccessResponse(SessionInfo sessionInfo); +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheConfig.java b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheConfig.java new file mode 100644 index 0000000..6322b8a --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheConfig.java @@ -0,0 +1,25 @@ +package org.pagan.janitor.cache; + +import javax.inject.Singleton; +import org.pagan.janitor.JanitorConfig; + +/** + * + * @author Edward M. Kagan + */ +@Singleton +public class SessionCacheConfig { + + public String cookieName; + public String csrfName; + public boolean csrfInCookie; + public Long sessionLifetime; + + public void setConfig(JanitorConfig config) { + this.cookieName = config.cookieName; + this.csrfName = config.csrfName; + this.csrfInCookie = config.csrfInCookie; + this.sessionLifetime = config.sessionLifetime; + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheImpl.java b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheImpl.java new file mode 100644 index 0000000..af08c17 --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionCacheImpl.java @@ -0,0 +1,77 @@ +package org.pagan.janitor.cache; + +import io.quarkus.arc.DefaultBean; +import javax.ws.rs.core.Response; +import java.util.HashMap; +import java.util.UUID; +import javax.enterprise.context.ApplicationScoped; +import javax.inject.Inject; +import javax.ws.rs.core.NewCookie; +import javax.ws.rs.core.Response.ResponseBuilder; + +/** + * + * @author Edward M. Kagan + */ +@DefaultBean +@ApplicationScoped +public class SessionCacheImpl implements SessionCache { + + @Inject + protected SessionCacheConfig config; + + HashMap sessions; + + public SessionCacheImpl() { + this.sessions = new HashMap(); + } + + @Override + public SessionInfo get(String sessionId) { + System.out.println(">>> get"); + for (String si : this.sessions.keySet()) { + System.out.println(si + " > " + this.sessions.get(si)); + } + return this.sessions.get(sessionId); + } + + @Override + public void put(String sessionId, SessionInfo sessionInfo) { + System.out.println(">>> put"); + this.sessions.put(sessionId, sessionInfo); + for (String si : this.sessions.keySet()) { + System.out.println(si + " > " + this.sessions.get(si)); + } + } + + @Override + public void del(String sessionId) { + this.sessions.remove(sessionId); + } + + @Override + public Response loginSuccessResponse(SessionInfo sessionInfo) { +// System.out.println("config = " + config); + final String sessionId = UUID.randomUUID().toString(); + final String csrfToken = UUID.randomUUID().toString(); + final long createdAt = System.currentTimeMillis(); + final long expiresAt = createdAt + config.sessionLifetime * 1000 * 1000; + sessionInfo.createdAt(createdAt); + sessionInfo.expiresAt(expiresAt); + sessionInfo.sessionId(sessionId); + sessionInfo.csrfToken(csrfToken); + put(sessionId, sessionInfo); + ResponseBuilder builder = Response.ok().cookie(new NewCookie(config.cookieName, + sessionId, "/", null, null, config.sessionLifetime.intValue(), + false, true)); + if (config.csrfInCookie) { + builder.cookie(new NewCookie(config.csrfName, + sessionInfo.csrfToken(), "/", null, null, config.sessionLifetime.intValue(), + false, true)); + } else { + builder.header(config.csrfName, sessionInfo.csrfToken()); + } + return builder.build(); + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionInfo.java b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionInfo.java new file mode 100644 index 0000000..52fa356 --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/cache/SessionInfo.java @@ -0,0 +1,79 @@ +package org.pagan.janitor.cache; + +import java.security.Principal; + +public class SessionInfo implements Principal { + + public static final SessionInfo ANONYMOUS = new SessionInfo().role("anonymous"); + private String sessionId; + private long createdAt; + private long expiresAt; + private String name; + private String role; + private String csrfToken; + + public SessionInfo() {} + + public String sessionId() { + return sessionId; + } + + public SessionInfo sessionId(String sessionId) { + this.sessionId = sessionId; + return this; + } + + public long createdAt() { + return createdAt; + } + + public SessionInfo createdAt(long createdAt) { + this.createdAt = createdAt; + return this; + } + + public long expiresAt() { + return expiresAt; + } + + public SessionInfo expiresAt(long expiresAt) { + this.expiresAt = expiresAt; + return this; + } + + public SessionInfo name(String name) { + this.name = name; + return this; + } + + public String name () { + return getName(); + } + + public String role() { + return role; + } + + public SessionInfo role(String role) { + this.role = role; + return this; + } + + public String csrfToken() { + return csrfToken; + } + + public SessionInfo csrfToken(String csrfToken) { + this.csrfToken = csrfToken; + return this; + } + + @Override + public String getName() { + return this.name; + } + + + + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthMechanism.java b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthMechanism.java new file mode 100644 index 0000000..120cd16 --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthMechanism.java @@ -0,0 +1,94 @@ +package org.pagan.janitor.security; + +import io.netty.handler.codec.http.HttpResponseStatus; +import io.quarkus.security.identity.IdentityProviderManager; +import io.quarkus.security.identity.SecurityIdentity; +import io.quarkus.security.identity.request.AuthenticationRequest; +import io.quarkus.vertx.http.runtime.security.ChallengeData; +import io.quarkus.vertx.http.runtime.security.HttpAuthenticationMechanism; +import io.quarkus.vertx.http.runtime.security.HttpCredentialTransport; +import io.vertx.core.http.HttpMethod; +import io.vertx.core.http.HttpServerRequest; +import io.vertx.core.http.HttpServerResponse; +import io.vertx.core.http.Cookie; +import io.vertx.ext.web.RoutingContext; +import java.util.Collections; +import java.util.Set; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionStage; +import javax.enterprise.context.ApplicationScoped; +import org.pagan.janitor.JanitorConfig; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +@ApplicationScoped +public class JanitorAuthMechanism implements HttpAuthenticationMechanism { + + JanitorConfig config; + + public void setConfig(JanitorConfig config) { + this.config = config; + } + + @Override + public CompletionStage authenticate(RoutingContext context, IdentityProviderManager janitorIdentityProvider) { + Cookie cookie = context.getCookie(config.cookieName); + if (cookie != null) { + final HttpServerRequest request = context.request(); + final HttpMethod method = request.method(); + final String path = request.path(); + final String origin = request.getHeader("Origin"); + final HttpServerResponse response = context.response(); + String csrfToken = null; + String csrfTarget = config.csrfName; + if (config.csrfInCookie) { + csrfTarget = config.csrfName; + Cookie csrfCookie = context.getCookie(csrfTarget); + if (csrfCookie != null) { + csrfToken = csrfCookie.getValue(); + } + } else { + csrfToken = request.getHeader(csrfTarget); + } + return janitorIdentityProvider.authenticate(new JanitorAuthenticationRequest(cookie.getValue(), method, csrfToken, path, origin, response, config.csrfInCookie, csrfTarget)); + } else { + return janitorIdentityProvider.authenticate(JanitorAuthenticationRequest.REJECTOR); + } + } + + @Override + public CompletionStage getChallenge(RoutingContext rc) { + System.out.println("getChallenge"); + return CompletableFuture.completedFuture( + new ChallengeData( + HttpResponseStatus.UNAUTHORIZED.code(), "", "" + ) + ); + } + + @Override + public CompletionStage sendChallenge(RoutingContext context) { + System.out.println("sendChallenge"); + Cookie cookie = context.getCookie(config.cookieName); + if (cookie != null) { + cookie.setMaxAge(0); + } + context.response().setStatusCode(HttpResponseStatus.UNAUTHORIZED.code()); + return CompletableFuture.completedFuture(false); + } + + @Override + public Set> getCredentialTypes() { + System.out.println("getCredentialTypes"); + return Collections.singleton(JanitorAuthenticationRequest.class); + } + + @Override + public HttpCredentialTransport getCredentialTransport() { + System.out.println("getCredentialTransport"); + return new HttpCredentialTransport(HttpCredentialTransport.Type.COOKIE, config.cookieName); + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthenticationRequest.java b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthenticationRequest.java new file mode 100644 index 0000000..2060fa6 --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorAuthenticationRequest.java @@ -0,0 +1,76 @@ +package org.pagan.janitor.security; + +import io.quarkus.security.identity.request.AuthenticationRequest; +import io.vertx.core.http.HttpMethod; +import io.vertx.core.http.HttpServerResponse; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +public class JanitorAuthenticationRequest implements AuthenticationRequest { + + public static final JanitorAuthenticationRequest REJECTOR = new JanitorAuthenticationRequest( + null, null, null, null, null, null, true, null + ); + + private final String sessionId; + private final HttpMethod method; + private final String csrfToken; + private final String path; + private final HttpServerResponse response; + private final String origin; + private final boolean csrfCookie; + private final String csrfTarget; + + public JanitorAuthenticationRequest(String sessionId, + HttpMethod method, + String csrfToken, + String path, + String origin, + HttpServerResponse response, + boolean csrfCookie, + String csrfTarget) { + this.sessionId = sessionId; + this.method = method; + this.csrfToken = csrfToken; + this.path = path; + this.origin = origin; + this.response = response; + this.csrfCookie = csrfCookie; + this.csrfTarget = csrfTarget; + } + + public String getSessionId() { + return sessionId; + } + + public HttpMethod getMethod() { + return method; + } + + public String getCsrfToken() { + return csrfToken; + } + + public String getPath() { + return path; + } + + public String getOrigin() { + return origin; + } + + public boolean isCsrfCookie() { + return csrfCookie; + } + + public String getCsrfTarget() { + return csrfTarget; + } + + void putHeader(String header, String value) { + response.putHeader(header, value); + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorIdentityProvider.java b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorIdentityProvider.java new file mode 100644 index 0000000..bf9d32d --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorIdentityProvider.java @@ -0,0 +1,112 @@ +package org.pagan.janitor.security; + +import io.quarkus.security.AuthenticationFailedException; +import io.quarkus.security.identity.AuthenticationRequestContext; +import io.quarkus.security.identity.IdentityProvider; +import io.quarkus.security.identity.SecurityIdentity; +import io.quarkus.security.runtime.QuarkusSecurityIdentity; +import io.vertx.core.http.HttpMethod; +import io.vertx.core.logging.Logger; +import io.vertx.core.logging.LoggerFactory; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionStage; +import javax.enterprise.context.ApplicationScoped; +import javax.inject.Inject; +import org.pagan.janitor.cache.SessionCache; +import org.pagan.janitor.cache.SessionInfo; +//import org.pagan.janitor.security.JanitorPrincipalProducer.NullSessionToken; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +@ApplicationScoped +public class JanitorIdentityProvider implements IdentityProvider { + + private static final Logger LOG = LoggerFactory.getLogger(JanitorIdentityProvider.class.getName()); + + @Inject + SessionCache sessionCache; + + @Override + public Class getRequestType() { + return JanitorAuthenticationRequest.class; + } + + @Override + public CompletionStage authenticate( + JanitorAuthenticationRequest request, + AuthenticationRequestContext context) { + if (request.getMethod() == null) { + return anonymous(); + } + + final HttpMethod method = request.getMethod(); + final String sessionId = request.getSessionId(); + final String csrfToken = request.getCsrfToken(); + final String path = request.getPath(); + + if (request.getOrigin() != null && request.getOrigin().length() > 0) + { +// request.putHeader("Access-Control-Allow-Origin", request.getOrigin()); +// request.putHeader("Access-Control-Allow-Methods", "POST, PUT, GET, OPTIONS, DELETE, PATCH, HEAD"); +// request.putHeader("Access-Control-Allow-Credentials", "true"); +// request.putHeader("Access-Control-Max-Age", "1209600"); +// request.putHeader("Access-Control-Expose-Headers", "X-CSRF-TOKEN, X-CSRF-ERROR"); +// request.putHeader("Access-Control-Allow-Headers", "origin, accept, authorization, content-type, x-requested-with, x-csrf-token, x-csrf-error"); + } + + if (method == HttpMethod.OPTIONS) { + LOG.debug("method = OPTIONS"); + return anonymous(); + } + + if (sessionId == null) { + LOG.debug("sessionId = null"); + return anonymous(); + } + + SessionInfo sessionInfo = sessionCache.get(sessionId); + LOG.debug("sessionInfo = " + sessionInfo); + + if (sessionInfo == null) { + LOG.debug("session info not found in session storage"); + return anonymous(); + } + + if (method != HttpMethod.GET && method != HttpMethod.HEAD) { + LOG.debug("path = " + path); + if (!path.equals("/api/auth/") && !path.equals("/api/auth") ) { + if (csrfToken == null) { + LOG.warn("csrfToken is null"); + return failed(); + } + if (!sessionInfo.csrfToken().equals(csrfToken)) { + LOG.error("bad csrfToken"); + return failed(); + } + } + } + + return principal(sessionInfo); + } + + private CompletionStage anonymous() { + return principal(SessionInfo.ANONYMOUS); + } + + private CompletionStage principal(SessionInfo sessionInfo) { + return CompletableFuture.completedFuture( + QuarkusSecurityIdentity.builder().setPrincipal(sessionInfo) + .addRole(sessionInfo.role()) + .build() + ); + } + + private CompletionStage failed() { + CompletableFuture cf = new CompletableFuture(); + cf.completeExceptionally(new AuthenticationFailedException()); + return cf; + } + +} diff --git a/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorPrincipalProducer.java b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorPrincipalProducer.java new file mode 100644 index 0000000..5251732 --- /dev/null +++ b/janitor/runtime/src/main/java/org/pagan/janitor/security/JanitorPrincipalProducer.java @@ -0,0 +1,76 @@ +package org.pagan.janitor.security; + +import io.quarkus.security.identity.SecurityIdentity; +import io.vertx.core.logging.Logger; +import io.vertx.core.logging.LoggerFactory; +import javax.annotation.Priority; +import javax.enterprise.context.RequestScoped; +import javax.enterprise.inject.Alternative; +import javax.enterprise.inject.Produces; +import javax.inject.Inject; +import org.pagan.janitor.cache.SessionInfo; + +/** + * @author Edward M. Kagan + * <kaganem@2pm.tech> + */ +@Priority(1) +@Alternative +@RequestScoped +public class JanitorPrincipalProducer { + + private static final Logger LOG + = LoggerFactory.getLogger(JanitorPrincipalProducer.class.getName()); + + @Inject + SecurityIdentity identity; + + @Produces + @RequestScoped + SessionInfo currentSessionPrincipalOrNull() { + LOG.debug("currentSessionPrincipalOrNull"); + if (identity.getPrincipal() instanceof SessionInfo) { + return (SessionInfo) identity.getPrincipal(); + } + throw new IllegalStateException("Current principal " + + identity.getPrincipal() + " is not a Coockie token"); + } + +// public static class NullSessionToken extends SessionInfo { +// +// private static final UnsupportedOperationException MUTATION_ALERT +// = new UnsupportedOperationException( +// "Null session does not support mutations, dummy" +// ); +// +// @Override +// protected void setCsrfToken(String csrfToken) { +// throw MUTATION_ALERT; +// } +// +// @Override +// protected void setRoleName(String userRoleName) { +// throw MUTATION_ALERT; +// } +// +// @Override +// protected void setUserId(long userId) { +// throw MUTATION_ALERT; +// } +// +// @Override +// protected void setExpiresAt(long sessionExpiresAt) { +// throw MUTATION_ALERT; +// } +// +// @Override +// protected void setCreatedAt(long sessionCreatedAt) { +// throw MUTATION_ALERT; +// } +// +// @Override +// protected void setSessionId(String sessionId) { +// throw MUTATION_ALERT; +// } +// } +} diff --git a/jedis/.gitignore b/jedis/.gitignore new file mode 100644 index 0000000..56c447b --- /dev/null +++ b/jedis/.gitignore @@ -0,0 +1,124 @@ + +# Created by https://www.gitignore.io/api/maven,java,intellij +# Edit at https://www.gitignore.io/?templates=maven,java,intellij + +### Intellij ### +# Covers JetBrains IDEs: IntelliJ, RubyMine, PhpStorm, AppCode, PyCharm, CLion, Android Studio and WebStorm +# Reference: https://intellij-support.jetbrains.com/hc/en-us/articles/206544839 + +# User-specific stuff +.idea/**/workspace.xml +.idea/**/tasks.xml +.idea/**/usage.statistics.xml +.idea/**/dictionaries +.idea/**/shelf + +# Generated files +.idea/**/contentModel.xml + +# Sensitive or high-churn files +.idea/**/dataSources/ +.idea/**/dataSources.ids +.idea/**/dataSources.local.xml +.idea/**/sqlDataSources.xml +.idea/**/dynamic.xml +.idea/**/uiDesigner.xml +.idea/**/dbnavigator.xml + +# Gradle +.idea/**/gradle.xml +.idea/**/libraries + +# Gradle and Maven with auto-import +# When using Gradle or Maven with auto-import, you should exclude module files, +# since they will be recreated, and may cause churn. Uncomment if using +# auto-import. +# .idea/modules.xml +# .idea/*.iml +# .idea/modules + +# CMake +cmake-build-*/ + +# Mongo Explorer plugin +.idea/**/mongoSettings.xml + +# File-based project format +*.iws + +# IntelliJ +out/ + +# mpeltonen/sbt-idea plugin +.idea_modules/ + +# JIRA plugin +atlassian-ide-plugin.xml + +# Cursive Clojure plugin +.idea/replstate.xml + +# Crashlytics plugin (for Android Studio and IntelliJ) +com_crashlytics_export_strings.xml +crashlytics.properties +crashlytics-build.properties +fabric.properties + +# Editor-based Rest Client +.idea/httpRequests + +# Android studio 3.1+ serialized cache file +.idea/caches/build_file_checksums.ser + +# JetBrains templates +**___jb_tmp___ + +### Intellij Patch ### +# Comment Reason: https://github.com/joeblau/gitignore.io/issues/186#issuecomment-215987721 + +# *.iml +# modules.xml +# .idea/misc.xml +# *.ipr + +# Sonarlint plugin +.idea/sonarlint + +### Java ### +# Compiled class file +*.class + +# Log file +*.log + +# BlueJ files +*.ctxt + +# Mobile Tools for Java (J2ME) +.mtj.tmp/ + +# Package Files # +*.jar +*.war +*.nar +*.ear +*.zip +*.tar.gz +*.rar + +# virtual machine crash logs, see http://www.java.com/en/download/help/error_hotspot.xml +hs_err_pid* + +### Maven ### +target/ +pom.xml.tag +pom.xml.releaseBackup +pom.xml.versionsBackup +pom.xml.next +release.properties +dependency-reduced-pom.xml +buildNumber.properties +.mvn/timing.properties +.mvn/wrapper/maven-wrapper.jar + +# End of https://www.gitignore.io/api/maven,java,intellij diff --git a/jedis/deployment/pom.xml b/jedis/deployment/pom.xml new file mode 100644 index 0000000..e4c9a7b --- /dev/null +++ b/jedis/deployment/pom.xml @@ -0,0 +1,58 @@ + + + 4.0.0 + + + org.pagan.quarkus + jedis-parent + 1.0-SNAPSHOT + + + jedis-deployment + ${project.artifactId} + + + + io.quarkus + quarkus-core-deployment + ${quarkus.platform.version} + + + io.quarkus + quarkus-arc-deployment + ${quarkus.platform.version} + + + io.quarkus + quarkus-agroal-deployment + ${quarkus.platform.version} + + + org.pagan.quarkus + jedis + 1.0-SNAPSHOT + + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + \ No newline at end of file diff --git a/jedis/deployment/src/main/java/org/pagan/quarkus/jedis/JedisProccessor.java b/jedis/deployment/src/main/java/org/pagan/quarkus/jedis/JedisProccessor.java new file mode 100644 index 0000000..b5fb652 --- /dev/null +++ b/jedis/deployment/src/main/java/org/pagan/quarkus/jedis/JedisProccessor.java @@ -0,0 +1,58 @@ +package org.pagan.quarkus.jedis; + +import io.quarkus.arc.deployment.AdditionalBeanBuildItem; +import io.quarkus.arc.deployment.BeanContainerBuildItem; +import io.quarkus.deployment.annotations.BuildProducer; +import io.quarkus.deployment.annotations.BuildStep; +import io.quarkus.deployment.annotations.ExecutionTime; +import io.quarkus.deployment.annotations.Record; +import io.quarkus.deployment.builditem.FeatureBuildItem; +import io.quarkus.deployment.builditem.ServiceStartBuildItem; +import io.quarkus.deployment.builditem.ShutdownContextBuildItem; + +/** + * + * @author Edward M. Kagan + */ +public class JedisProccessor { + + private JedisConfig config; + + @BuildStep + FeatureBuildItem feature() { + System.out.println("JedisProccessor - feature"); + return new FeatureBuildItem("jedis"); + } + + @BuildStep + AdditionalBeanBuildItem beans() { + System.out.println("JedisProccessor - beans"); + return AdditionalBeanBuildItem.unremovableOf(JedisSupport.class); + } + + @Record(ExecutionTime.RUNTIME_INIT) + @BuildStep + void build(JedisRecorder recorder, BuildProducer serviceStart, BeanContainerBuildItem beanContainer, ShutdownContextBuildItem shutdownContext) { + System.out.println("JedisProccessor - build"); +// BuildProducer reflectiveClassBuildItemBuildProducer) { +// reflectiveClassBuildItemBuildProducer.produce(new ReflectiveClassBuildItem(false, false, BaseGenericObjectPool.class.getName())); +// reflectiveClassBuildItemBuildProducer.produce(new ReflectiveClassBuildItem(false, false, DefaultEvictionPolicy.class.getName())); + recorder.initialize(config, beanContainer.getValue(), shutdownContext); + serviceStart.produce(new ServiceStartBuildItem("jedis")); + } + + // @BuildStep +// SubstrateProxyDefinitionBuildItem httpProxies() { +// return new SubstrateProxyDefinitionBuildItem(MBeanServer.class.getName(), +// MBeanServerConnection.class.getName(), +// KeyedObjectPool.class.getName(), +// KeyedPooledObjectFactory.class.getName(), +// ObjectPool.class.getName(), +// PooledObject.class.getName(), +// PooledObjectFactory.class.getName(), +// SwallowedExceptionListener.class.getName(), +// TrackedUse.class.getName(), +// UsageTracking.class.getName()); +// } + +} diff --git a/jedis/pom.xml b/jedis/pom.xml new file mode 100644 index 0000000..461f985 --- /dev/null +++ b/jedis/pom.xml @@ -0,0 +1,22 @@ + + + 4.0.0 + + + org.pagan.quarkus + extensions + 1.0-SNAPSHOT + + + jedis-parent + ${project.artifactId} + pom + + + deployment + runtime + + + \ No newline at end of file diff --git a/jedis/runtime/pom.xml b/jedis/runtime/pom.xml new file mode 100644 index 0000000..58f22cc --- /dev/null +++ b/jedis/runtime/pom.xml @@ -0,0 +1,77 @@ + + + 4.0.0 + + + org.pagan.quarkus + jedis-parent + 1.0-SNAPSHOT + + + jedis + ${project.artifactId} + + + + io.quarkus + quarkus-core + ${quarkus.platform.version} + + + io.quarkus + quarkus-arc + ${quarkus.platform.version} + + + io.quarkus + quarkus-agroal + ${quarkus.platform.version} + + + redis.clients + jedis + ${jedis.version} + + + + + + + + io.quarkus + quarkus-bootstrap-maven-plugin + ${quarkus.platform.version} + + + + extension-descriptor + + + ${project.groupId}:${project.artifactId}-deployment:${project.version} + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compiler-plugin.version} + + + + io.quarkus + quarkus-extension-processor + ${quarkus.platform.version} + + + + + + + + \ No newline at end of file diff --git a/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisConfig.java b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisConfig.java new file mode 100644 index 0000000..21b6b82 --- /dev/null +++ b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisConfig.java @@ -0,0 +1,38 @@ +package org.pagan.quarkus.jedis; + +import io.quarkus.runtime.annotations.ConfigItem; +import io.quarkus.runtime.annotations.ConfigPhase; +import io.quarkus.runtime.annotations.ConfigRoot; + +/** + * + * @author Edward M. Kagan + */ +@ConfigRoot(name = "jedis", phase = ConfigPhase.BUILD_AND_RUN_TIME_FIXED) +public class JedisConfig { + + /** + * Comma-separated list of Redis-shards, with port number obviously + */ + @ConfigItem(defaultValue = "localhost:6379") + public String shards; + + /** + * Max connections pool size + */ + @ConfigItem(defaultValue = "15") + public int poolMax; + + /** + * Connection acquisition timeout + */ + @ConfigItem(defaultValue = "50") + public long maxWait; + + /** + * Will Jedis log activity + */ + @ConfigItem(defaultValue = "true") + public boolean log; + +} diff --git a/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisRecorder.java b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisRecorder.java new file mode 100644 index 0000000..51aac17 --- /dev/null +++ b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisRecorder.java @@ -0,0 +1,16 @@ +package org.pagan.quarkus.jedis; + +import io.quarkus.arc.runtime.BeanContainer; +import io.quarkus.runtime.ShutdownContext; +import io.quarkus.runtime.annotations.Recorder; + +@Recorder +public class JedisRecorder { + + public void initialize(JedisConfig config, BeanContainer container, ShutdownContext shutdownContext) { + JedisSupport support = container.instance(JedisSupport.class); + support.initialize(config); + shutdownContext.addShutdownTask(() -> support.shutdown()); + } + +} diff --git a/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisSupport.java b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisSupport.java new file mode 100644 index 0000000..8699acc --- /dev/null +++ b/jedis/runtime/src/main/java/org/pagan/quarkus/jedis/JedisSupport.java @@ -0,0 +1,59 @@ +package org.pagan.quarkus.jedis; + +import java.net.URI; +import java.util.Arrays; +import java.util.List; +import java.util.stream.Collectors; +import javax.inject.Singleton; +import redis.clients.jedis.JedisPool; +import redis.clients.jedis.JedisPoolConfig; +import redis.clients.jedis.JedisShardInfo; +import redis.clients.jedis.ShardedJedisPool; +import redis.clients.jedis.Jedis; +import redis.clients.jedis.ShardedJedis; + +/** + * + * @author Edward M. Kagan + */ +@Singleton +public class JedisSupport { + + ShardedJedisPool shardedJedisPool = null; + JedisPool jedisPool = null; + + public JedisSupport() { + System.out.println("Jedis support now"); + } + + public void initialize(JedisConfig config) { + JedisPoolConfig poolConfig = new JedisPoolConfig(); + poolConfig.setTestOnBorrow(true); + poolConfig.setMaxWaitMillis(config.maxWait); + poolConfig.setMaxTotal(config.poolMax); +// poolConfig.setJmxEnabled(false); + poolConfig.setJmxEnabled(true); + if (config.shards.contains(",")) { + List jedisShards = Arrays.stream(config.shards.split(",")).map(uri -> { + return new JedisShardInfo(URI.create(uri)); + }).collect(Collectors.toList()); + this.shardedJedisPool = new ShardedJedisPool(poolConfig, jedisShards); + + } else { + this.jedisPool = new JedisPool(poolConfig, URI.create(config.shards)); + } + } + + public ShardedJedis sharedContext () { + return shardedJedisPool.getResource(); + } + + public Jedis context () { + return jedisPool.getResource(); + } + + public void shutdown() { +// redisRuntime.shutdown(); + } + +} diff --git a/pom.xml b/pom.xml new file mode 100644 index 0000000..8196076 --- /dev/null +++ b/pom.xml @@ -0,0 +1,47 @@ + + + 4.0.0 + + org.pagan.quarkus + extensions + ${project.artifactId} + 1.0-SNAPSHOT + pom + + + + + ${quarkus.platform.group-id} + ${quarkus.platform.artifact-id} + ${quarkus.platform.version} + pom + import + + + + + + cayenne + jedis + janitor + + demo + + + 3.8.1 + true + 1.8 + 1.8 + UTF-8 + UTF-8 + 1.3.1.Final + quarkus-universe-bom + io.quarkus + 1.3.1.Final + 2.22.1 + 4.1.RC2 + 3.2.0 + +