// Copyright 1997 The Open Group Research Institute.  All rights reserved.

package krb5.lib;

import krb5.lib.asn1.*;

/**
 * KRB safe
 */
public class KRBSafe {

	/**
	 * Version
	 */
	public int pvno;

	/**
	 * Message type
	 */
	public int msgType;

	/**
	 * KRB safe body
	 */
	public KRBSafeBody safeBody;

	/**
	 * Checksum
	 */
	public Checksum cksum;

	/**
	 * Class constructor
	 *
	 * @param new_safeBody is of type KRBSafeBody
	 * @param new_cksum is of type Checksum
	 * @see krb5.lib.KRBSafeBody
	 * @see krb5.lib.Checksum
	 */
	public KRBSafe(KRBSafeBody new_safeBody, Checksum new_cksum) {
		pvno = Krb5.PVNO;
		msgType = Krb5.KRB_SAFE;
		safeBody = new_safeBody;
		cksum = new_cksum;
	}

	/**
	 * Class constructor
	 *
	 * @param data is of type byte[]
	 * @exception Asn1Exception an exception
	 * @exception RealmException an exception
	 * @exception KrbApErrException an exception
	 * @see krb5.lib.Asn1Exception
	 * @see krb5.lib.RealmException
	 * @see krb5.lib.KrbApErrException
	 */
	public KRBSafe(byte[] data) throws Asn1Exception,
		RealmException, KrbApErrException {
		this(new EncodeRef(data));
	}

	/**
	 * Class constructor
	 *
	 * @param ref is of type EncodeRef
	 * @exception Asn1Exception an exception
	 * @exception RealmException an exception
	 * @exception KrbApErrException an exception
	 * @see krb5.lib.asn1.EncodeRef
	 * @see krb5.lib.Asn1Exception
	 * @see krb5.lib.RealmException
	 * @see krb5.lib.KrbApErrException
	 */
	public KRBSafe(EncodeRef ref) throws Asn1Exception,
		RealmException, KrbApErrException {
		if (decode.TagApp(ref) != Krb5.KRB_SAFE)
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);
		EncodeRef subRef = decode.Sequence(ref.startOfData());

		if (decode.Tag(subRef) == 0) {
			pvno = decode.Integer(subRef.startOfData());
			if (pvno != Krb5.PVNO)
				//XXX check if KRB_AP_ERR_BADVERSION is correct return code
				throw new KrbApErrException(Krb5.KRB_AP_ERR_BADVERSION);
			subRef.next();
		}
		else
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);

		if (decode.Tag(subRef) == 1) {
			msgType = decode.Integer(subRef.startOfData());
			if (msgType != Krb5.KRB_SAFE)
				//XXX check if KRB_AP_ERR_MSG_TYPE is correct return code
				throw new KrbApErrException(Krb5.KRB_AP_ERR_MSG_TYPE);
			subRef.next();
		}
		else
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);

		if (decode.Tag(subRef) == 2) {
			safeBody = new KRBSafeBody(subRef.startOfData());
			subRef.next();
		}
		else
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);

		if (decode.Tag(subRef) == 3) {
			cksum = new Checksum(subRef.startOfData());
			subRef.next();
		}
		else
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);

		if (subRef.isMoreInSequence())
			throw new Asn1Exception(Krb5.ASN1_BAD_ID);
	}

	/**
	 * Encodes the object in asn1
	 *
	 * @return byte[] is a result
	 * @exception Asn1Exception an exception
	 * @see krb5.lib.Asn1Exception
	 */
	public byte[] asn1Encode() throws Asn1Exception {
		byte[][] krb_safe = {
			encode.prependExplicitTag(0, encode.Integer(pvno)),
			encode.prependExplicitTag(1, encode.Integer(msgType)),
			encode.prependExplicitTag(2, safeBody.asn1Encode()),
			encode.prependExplicitTag(3, cksum.asn1Encode())
		};
		return encode.prependExplicitTag(asn1Class.APPLICATION,
			msgType, encode.Sequence(krb_safe));
	}

}