mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-2127 check that external user creds is linked to other user (#941)
This commit is contained in:
+14
-7
@@ -1111,6 +1111,14 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
AuthAttemptSessionInfo authAttemptSessionInfo = readAuthAttemptSessionInfo(authId);
|
||||
boolean isMainAuthSession = authAttemptSessionInfo.getSmSessionId() == null;
|
||||
|
||||
String token = null;
|
||||
SMAuthPermissions permissions = null;
|
||||
if (!isMainAuthSession) {
|
||||
//this is an additional authorization and we should to return the original permissions and userId
|
||||
token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId());
|
||||
permissions = getTokenPermissions(token);
|
||||
}
|
||||
|
||||
for (String authProviderId : authProviderIds) {
|
||||
var userCredentials = (Map<String, Object>) authInfo.getAuthData().get(authProviderId);
|
||||
var userIdFromCreds = findOrCreateExternalUserByCredentials(
|
||||
@@ -1118,6 +1126,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
authAttemptSessionInfo.getSessionParams(),
|
||||
userCredentials,
|
||||
finishAuthMonitor,
|
||||
permissions == null ? null : permissions.getUserId(),
|
||||
isMainAuthSession
|
||||
);
|
||||
|
||||
@@ -1129,13 +1138,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
userId = userIdFromCreds;
|
||||
}
|
||||
|
||||
String token;
|
||||
SMAuthPermissions permissions;
|
||||
if (!isMainAuthSession) {
|
||||
//this is an additional authorization and we should to return the original permissions and userId
|
||||
token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId());
|
||||
permissions = getTokenPermissions(token);
|
||||
} else {
|
||||
if (token == null && permissions == null) {
|
||||
try (Connection dbCon = database.openConnection()) {
|
||||
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
|
||||
String smSessionId;
|
||||
@@ -1194,12 +1197,16 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
|
||||
@NotNull Map<String, Object> sessionParameters,
|
||||
@NotNull Map<String, Object> userCredentials,
|
||||
@NotNull DBRProgressMonitor progressMonitor,
|
||||
@Nullable String activeUserId,
|
||||
boolean newUserAuthenticationTry
|
||||
) throws DBException {
|
||||
AuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
|
||||
SMAuthProvider<?> smAuthProviderInstance = authProvider.getInstance();
|
||||
String userId = findUserByCredentials(authProviderId, userCredentials);
|
||||
String userIdFromCredentials;
|
||||
if (activeUserId != null && userId != null && !activeUserId.equals(userId)) {
|
||||
throw new SMException("Credentials are not with current user");
|
||||
}
|
||||
try {
|
||||
userIdFromCredentials = smAuthProviderInstance.validateLocalAuth(progressMonitor, this, Map.of(), userCredentials, null);
|
||||
} catch (DBException e) {
|
||||
|
||||
Reference in New Issue
Block a user