1 /** 2 * Portions of this software was developed by employees of the National Institute 3 * of Standards and Technology (NIST), an agency of the Federal Government and is 4 * being made available as a public service. Pursuant to title 17 United States 5 * Code Section 105, works of NIST employees are not subject to copyright 6 * protection in the United States. This software may be subject to foreign 7 * copyright. Permission in the United States and in foreign countries, to the 8 * extent that NIST may hold copyright, to use, copy, modify, create derivative 9 * works, and distribute this software and its documentation without fee is hereby 10 * granted on a non-exclusive basis, provided that this notice and disclaimer 11 * of warranty appears in all copies. 12 * 13 * THE SOFTWARE IS PROVIDED 'AS IS' WITHOUT ANY WARRANTY OF ANY KIND, EITHER 14 * EXPRESSED, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, ANY WARRANTY 15 * THAT THE SOFTWARE WILL CONFORM TO SPECIFICATIONS, ANY IMPLIED WARRANTIES OF 16 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND FREEDOM FROM 17 * INFRINGEMENT, AND ANY WARRANTY THAT THE DOCUMENTATION WILL CONFORM TO THE 18 * SOFTWARE, OR ANY WARRANTY THAT THE SOFTWARE WILL BE ERROR FREE. IN NO EVENT 19 * SHALL NIST BE LIABLE FOR ANY DAMAGES, INCLUDING, BUT NOT LIMITED TO, DIRECT, 20 * INDIRECT, SPECIAL OR CONSEQUENTIAL DAMAGES, ARISING OUT OF, RESULTING FROM, 21 * OR IN ANY WAY CONNECTED WITH THIS SOFTWARE, WHETHER OR NOT BASED UPON WARRANTY, 22 * CONTRACT, TORT, OR OTHERWISE, WHETHER OR NOT INJURY WAS SUSTAINED BY PERSONS OR 23 * PROPERTY OR OTHERWISE, AND WHETHER OR NOT LOSS WAS SUSTAINED FROM, OR AROSE OUT 24 * OF THE RESULTS OF, OR USE OF, THE SOFTWARE OR SERVICES PROVIDED HEREUNDER. 25 */ 26 27 package gov.nist.secauto.swid.swidval; 28 29 import gov.nist.secauto.decima.core.assessment.result.ResultStatusBehavior; 30 import gov.nist.secauto.decima.core.requirement.Requirement; 31 32 import java.util.Map; 33 import java.util.Set; 34 35 public class SWIDValResultStatusBehavior implements ResultStatusBehavior { 36 private static final String TAG_TYPES_QNAME = "{" + XMLConstants.REQUIREMENTS_SWID_EXTENSION_NS + "}tag-type"; 37 private static final String SCOPE_QNAME = "{" + XMLConstants.REQUIREMENTS_SWID_EXTENSION_NS + "}scope"; 38 private final TagType tagType; 39 private final boolean authoritative; 40 41 public SWIDValResultStatusBehavior(TagType tagType, boolean authoritative) { 42 this.tagType = tagType; 43 this.authoritative = authoritative; 44 } 45 46 @Override 47 public boolean isInScope(Requirement requirement) { 48 Map<String, Set<String>> tags = requirement.getMetadataTagValueMap(); 49 50 Set<String> tagTypes = tags.get(TAG_TYPES_QNAME); 51 Set<String> scopeValues = tags.get(SCOPE_QNAME); 52 String scope = authoritative ? "authoritative" : "non-authoritative"; 53 boolean matchTagType 54 = tagTypes == null || tagTypes.isEmpty() || tagTypes.contains("all") || tagTypes.contains(tagType.getName()); 55 boolean matchScope 56 = scopeValues == null || scopeValues.isEmpty() || scopeValues.contains("all") || scopeValues.contains(scope); 57 return matchTagType && matchScope; 58 } 59 60 }