mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
Revert "dbeaver/cloudbeaver#4249 added session rotation (#4274)"
This reverts commit d79054a5d8.
This commit is contained in:
-7
@@ -116,13 +116,6 @@ public abstract class BaseWebSession extends AbstractSessionPersistent {
|
||||
}
|
||||
}
|
||||
|
||||
public void migrateEventHandlersTo(@NotNull BaseWebSession target) {
|
||||
synchronized (sessionEventHandlers) {
|
||||
sessionEventHandlers.forEach(target::addEventHandler);
|
||||
sessionEventHandlers.clear();
|
||||
}
|
||||
}
|
||||
|
||||
public boolean updateSMSession(SMAuthInfo smAuthInfo) throws DBException {
|
||||
return userContext.refresh(smAuthInfo);
|
||||
}
|
||||
|
||||
+6
-41
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -199,42 +199,6 @@ public class CBSessionManager implements WebAppSessionManager {
|
||||
return httpSession.getId();
|
||||
}
|
||||
|
||||
/**
|
||||
* Invalidates the current HTTP session, creates a new one, and binds a new {@link WebSession} to it.
|
||||
*/
|
||||
@NotNull
|
||||
public WebSession rotateSession(
|
||||
@NotNull HttpServletRequest request,
|
||||
@NotNull WebSession webSession
|
||||
) throws DBWebException {
|
||||
HttpSession oldHttpSession = request.getSession(false);
|
||||
if (oldHttpSession != null) {
|
||||
oldHttpSession.invalidate();
|
||||
}
|
||||
String newSessionId = request.getSession(true).getId();
|
||||
|
||||
String locale = webSession.getLocale();
|
||||
String remoteAddr = webSession.getLastRemoteAddr();
|
||||
String remoteUserAgent = webSession.getLastRemoteUserAgent();
|
||||
var requestInfo = new WebHttpRequestInfo(newSessionId, locale, remoteAddr, remoteUserAgent);
|
||||
WebSession newWebSession;
|
||||
try {
|
||||
newWebSession = createWebSessionImpl(requestInfo);
|
||||
} catch (DBException e) {
|
||||
throw new DBWebException(e);
|
||||
}
|
||||
webSession.migrateEventHandlersTo(newWebSession);
|
||||
String oldSessionId = webSession.getSessionId();
|
||||
synchronized (sessionMap) {
|
||||
sessionMap.remove(oldSessionId);
|
||||
sessionMap.put(newSessionId, newWebSession);
|
||||
}
|
||||
webSession.close(false, false);
|
||||
|
||||
log.debug("Session rotated '" + oldSessionId + "' -> '" + newSessionId + "'");
|
||||
return newWebSession;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns not expired session from cache, or restore it.
|
||||
*
|
||||
@@ -319,14 +283,15 @@ public class CBSessionManager implements WebAppSessionManager {
|
||||
|
||||
@Override
|
||||
@Nullable
|
||||
public WebSession findWebSession(@NotNull HttpServletRequest request) {
|
||||
public WebSession findWebSession(HttpServletRequest request) {
|
||||
String sessionId = getSessionId(request);
|
||||
WebSession webSession;
|
||||
synchronized (sessionMap) {
|
||||
var session = sessionMap.get(sessionId);
|
||||
webSession = (session instanceof WebSession) ? (WebSession) session : null;
|
||||
if (session instanceof WebSession) {
|
||||
return (WebSession) session;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
return webSession;
|
||||
}
|
||||
|
||||
@Override
|
||||
|
||||
+1
-2
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -36,7 +36,6 @@ public interface DBWServiceAuth extends DBWService {
|
||||
|
||||
@WebAction(authRequired = false)
|
||||
WebAuthStatus authLogin(
|
||||
@NotNull HttpServletRequest httpRequest,
|
||||
@NotNull WebSession webSession,
|
||||
@NotNull String providerId,
|
||||
@Nullable String providerConfigurationId,
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
|
||||
+1
-2
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -37,7 +37,6 @@ public class WebServiceBindingAuth extends WebServiceBindingBase<DBWServiceAuth>
|
||||
public void bindWiring(DBWBindingContext model) {
|
||||
model.getQueryType()
|
||||
.dataFetcher("authLogin", env -> getService(env).authLogin(
|
||||
GraphQLEndpoint.getServletRequestOrThrow(env),
|
||||
getWebSession(env, false),
|
||||
getArgumentVal(env, "provider"),
|
||||
getArgument(env, "configuration"),
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
|
||||
+4
-21
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* DBeaver - Universal Database Manager
|
||||
* Copyright (C) 2010-2026 DBeaver Corp and others
|
||||
* Copyright (C) 2010-2025 DBeaver Corp and others
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -67,8 +67,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
|
||||
@Override
|
||||
public WebAuthStatus authLogin(
|
||||
@NotNull HttpServletRequest httpRequest,
|
||||
@NotNull WebSession inputWebSession,
|
||||
@NotNull WebSession webSession,
|
||||
@NotNull String providerId,
|
||||
@Nullable String providerConfigurationId,
|
||||
@Nullable Map<String, Object> authParameters,
|
||||
@@ -76,13 +75,6 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
boolean forceSessionsLogout
|
||||
) throws DBWebException {
|
||||
try {
|
||||
WebSession webSession = inputWebSession;
|
||||
if (inputWebSession.getUser() == null) {
|
||||
// Rotate anonymous web sessions during login attempts to prevent session fixation attacks.
|
||||
webSession = CBApplication.getInstance().getSessionManager()
|
||||
.rotateSession(httpRequest, inputWebSession);
|
||||
}
|
||||
|
||||
var smAuthInfo = initiateAuthentication(webSession, providerId, providerConfigurationId, authParameters, forceSessionsLogout);
|
||||
//TODO deprecated, use asyncAuthLogin for federated auth, exits for backward compatibility
|
||||
linkWithActiveUser = linkWithActiveUser && CBApplication.getInstance().getAppConfiguration()
|
||||
@@ -93,8 +85,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
} else {
|
||||
//run it sync
|
||||
var authProcessor = new WebSessionAuthProcessor(webSession, smAuthInfo, linkWithActiveUser);
|
||||
List<WebAuthInfo> authInfos = authProcessor.authenticateSession();
|
||||
return new WebAuthStatus(smAuthInfo.getAuthStatus(), authInfos);
|
||||
return new WebAuthStatus(smAuthInfo.getAuthStatus(), authProcessor.authenticateSession());
|
||||
}
|
||||
} catch (SMTooManySessionsException e) {
|
||||
throw new DBWebException("User authentication failed", e.getErrorType(), e);
|
||||
@@ -104,22 +95,14 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
|
||||
}
|
||||
|
||||
@Override
|
||||
@NotNull
|
||||
public WebAsyncAuthStatus federatedLogin(
|
||||
@NotNull HttpServletRequest httpRequest,
|
||||
@NotNull WebSession inputWebSession,
|
||||
@NotNull WebSession webSession,
|
||||
@NotNull String providerId,
|
||||
@Nullable String providerConfigurationId,
|
||||
boolean linkWithActiveUser,
|
||||
boolean forceSessionsLogout
|
||||
) throws DBWebException {
|
||||
WebSession webSession = inputWebSession;
|
||||
if (inputWebSession.getUser() == null) {
|
||||
// Rotate anonymous web sessions during login attempts to prevent session fixation attacks.
|
||||
webSession = CBApplication.getInstance().getSessionManager()
|
||||
.rotateSession(httpRequest, inputWebSession);
|
||||
}
|
||||
|
||||
WebAuthProviderDescriptor providerDescriptor = WebAuthProviderRegistry.getInstance().getAuthProvider(providerId);
|
||||
if (providerDescriptor == null) {
|
||||
throw new DBWebException("Provider '" + providerId + "' not found");
|
||||
|
||||
Reference in New Issue
Block a user