From 164be980f4dce25ee169f6d2f0866ff7b2fb4f75 Mon Sep 17 00:00:00 2001 From: Alexander Skoblikov Date: Wed, 29 Jun 2022 22:43:08 +0300 Subject: [PATCH] CB-2127 check that external user creds is linked to other user (#941) --- .../CBEmbeddedSecurityController.java | 21 ++++++++++++------- 1 file changed, 14 insertions(+), 7 deletions(-) diff --git a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java index 405248d55c..4377c8bfc3 100644 --- a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java +++ b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java @@ -1111,6 +1111,14 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen AuthAttemptSessionInfo authAttemptSessionInfo = readAuthAttemptSessionInfo(authId); boolean isMainAuthSession = authAttemptSessionInfo.getSmSessionId() == null; + String token = null; + SMAuthPermissions permissions = null; + if (!isMainAuthSession) { + //this is an additional authorization and we should to return the original permissions and userId + token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId()); + permissions = getTokenPermissions(token); + } + for (String authProviderId : authProviderIds) { var userCredentials = (Map) authInfo.getAuthData().get(authProviderId); var userIdFromCreds = findOrCreateExternalUserByCredentials( @@ -1118,6 +1126,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen authAttemptSessionInfo.getSessionParams(), userCredentials, finishAuthMonitor, + permissions == null ? null : permissions.getUserId(), isMainAuthSession ); @@ -1129,13 +1138,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen userId = userIdFromCreds; } - String token; - SMAuthPermissions permissions; - if (!isMainAuthSession) { - //this is an additional authorization and we should to return the original permissions and userId - token = findTokenBySmSession(authAttemptSessionInfo.getSmSessionId()); - permissions = getTokenPermissions(token); - } else { + if (token == null && permissions == null) { try (Connection dbCon = database.openConnection()) { try (JDBCTransaction txn = new JDBCTransaction(dbCon)) { String smSessionId; @@ -1194,12 +1197,16 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen @NotNull Map sessionParameters, @NotNull Map userCredentials, @NotNull DBRProgressMonitor progressMonitor, + @Nullable String activeUserId, boolean newUserAuthenticationTry ) throws DBException { AuthProviderDescriptor authProvider = getAuthProvider(authProviderId); SMAuthProvider smAuthProviderInstance = authProvider.getInstance(); String userId = findUserByCredentials(authProviderId, userCredentials); String userIdFromCredentials; + if (activeUserId != null && userId != null && !activeUserId.equals(userId)) { + throw new SMException("Credentials are not with current user"); + } try { userIdFromCredentials = smAuthProviderInstance.validateLocalAuth(progressMonitor, this, Map.of(), userCredentials, null); } catch (DBException e) {