CB-2127 check that external user creds is linked to other user (#941)

This commit is contained in:
Alexander Skoblikov
2022-06-29 22:43:08 +03:00
committed by GitHub
parent 54073a4bc7
commit 164be980f4
@@ -1111,6 +1111,14 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
AuthAttemptSessionInfo authAttemptSessionInfo = readAuthAttemptSessionInfo(authId);
boolean isMainAuthSession = authAttemptSessionInfo.getSmSessionId() == null;
String token = null;
SMAuthPermissions permissions = null;
if (!isMainAuthSession) {
//this is an additional authorization and we should to return the original permissions and userId
token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId());
permissions = getTokenPermissions(token);
}
for (String authProviderId : authProviderIds) {
var userCredentials = (Map<String, Object>) authInfo.getAuthData().get(authProviderId);
var userIdFromCreds = findOrCreateExternalUserByCredentials(
@@ -1118,6 +1126,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
authAttemptSessionInfo.getSessionParams(),
userCredentials,
finishAuthMonitor,
permissions == null ? null : permissions.getUserId(),
isMainAuthSession
);
@@ -1129,13 +1138,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
userId = userIdFromCreds;
}
String token;
SMAuthPermissions permissions;
if (!isMainAuthSession) {
//this is an additional authorization and we should to return the original permissions and userId
token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId());
permissions = getTokenPermissions(token);
} else {
if (token == null && permissions == null) {
try (Connection dbCon = database.openConnection()) {
try (JDBCTransaction txn = new JDBCTransaction(dbCon)) {
String smSessionId;
@@ -1194,12 +1197,16 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen
@NotNull Map<String, Object> sessionParameters,
@NotNull Map<String, Object> userCredentials,
@NotNull DBRProgressMonitor progressMonitor,
@Nullable String activeUserId,
boolean newUserAuthenticationTry
) throws DBException {
AuthProviderDescriptor authProvider = getAuthProvider(authProviderId);
SMAuthProvider<?> smAuthProviderInstance = authProvider.getInstance();
String userId = findUserByCredentials(authProviderId, userCredentials);
String userIdFromCredentials;
if (activeUserId != null && userId != null && !activeUserId.equals(userId)) {
throw new SMException("Credentials are not with current user");
}
try {
userIdFromCredentials = smAuthProviderInstance.validateLocalAuth(progressMonitor, this, Map.of(), userCredentials, null);
} catch (DBException e) {