From 1fd10e29a4cbf95c39188e1b6cd8a6524e218237 Mon Sep 17 00:00:00 2001 From: Ainur <59531286+yagudin10@users.noreply.github.com> Date: Wed, 18 May 2022 17:21:40 +0300 Subject: [PATCH] CB-1970 add session permissions to rest api (#834) * CB-1970 add session permissions to rest api * CB-1970 put session id into auth permissions * CB-1970 put session id into SMAuthPermissions --- .../internal/CBEmbeddedSecurityController.java | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java index 0f1a1618c7..d0a93b3671 100644 --- a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java +++ b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java @@ -824,7 +824,7 @@ public class CBEmbeddedSecurityController implements SMAdminController { var token = generateAuthToken(appSessionId, null, dbCon); var permissions = getAnonymousUserPermissions(); txn.commit(); - return new SMAuthInfo(token, new SMAuthPermissions(null, permissions)); + return new SMAuthInfo(token, new SMAuthPermissions(null, appSessionId, permissions)); } } catch (SQLException e) { throw new DBException(e.getMessage(), e); @@ -851,7 +851,7 @@ public class CBEmbeddedSecurityController implements SMAdminController { var token = generateAuthToken(appSessionId, userId, dbCon); var permissions = getUserPermissions(userId); txn.commit(); - return new SMAuthInfo(token, new SMAuthPermissions(userId, permissions)); + return new SMAuthInfo(token, new SMAuthPermissions(userId, appSessionId, permissions)); } } catch (SQLException e) { throw new DBException(e.getMessage(), e); @@ -923,8 +923,9 @@ public class CBEmbeddedSecurityController implements SMAdminController { @Override public SMAuthPermissions getTokenPermissions(String token) throws DBException { String userId; + String sessionId; try (Connection dbCon = database.openConnection(); - PreparedStatement dbStat = dbCon.prepareStatement("SELECT USER_ID, EXPIRATION_TIME FROM CB_AUTH_TOKEN WHERE TOKEN_ID=?"); + PreparedStatement dbStat = dbCon.prepareStatement("SELECT USER_ID, EXPIRATION_TIME, SESSION_ID FROM CB_AUTH_TOKEN WHERE TOKEN_ID=?"); ) { dbStat.setString(1, token); try (var dbResult = dbStat.executeQuery()) { @@ -936,12 +937,13 @@ public class CBEmbeddedSecurityController implements SMAdminController { if (Timestamp.from(Instant.now()).after(expiredDate)) { throw new SMException("Token expired"); } + sessionId = dbResult.getString(3); } } catch (SQLException e) { throw new DBCException("Error reading token info in database", e); } var permissions = userId == null ? getAnonymousUserPermissions() : getUserPermissions(userId); - return new SMAuthPermissions(userId, permissions); + return new SMAuthPermissions(userId, sessionId, permissions); } @Override