Revert "dbeaver/cloudbeaver#4249 added session rotation (#4274)"

This reverts commit d79054a5d8.
This commit is contained in:
Serge Rider
2026-05-08 17:21:40 +02:00
parent 3a250e2e7a
commit 20b129d5a2
7 changed files with 14 additions and 75 deletions
@@ -116,13 +116,6 @@ public abstract class BaseWebSession extends AbstractSessionPersistent {
}
}
public void migrateEventHandlersTo(@NotNull BaseWebSession target) {
synchronized (sessionEventHandlers) {
sessionEventHandlers.forEach(target::addEventHandler);
sessionEventHandlers.clear();
}
}
public boolean updateSMSession(SMAuthInfo smAuthInfo) throws DBException {
return userContext.refresh(smAuthInfo);
}
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -199,42 +199,6 @@ public class CBSessionManager implements WebAppSessionManager {
return httpSession.getId();
}
/**
* Invalidates the current HTTP session, creates a new one, and binds a new {@link WebSession} to it.
*/
@NotNull
public WebSession rotateSession(
@NotNull HttpServletRequest request,
@NotNull WebSession webSession
) throws DBWebException {
HttpSession oldHttpSession = request.getSession(false);
if (oldHttpSession != null) {
oldHttpSession.invalidate();
}
String newSessionId = request.getSession(true).getId();
String locale = webSession.getLocale();
String remoteAddr = webSession.getLastRemoteAddr();
String remoteUserAgent = webSession.getLastRemoteUserAgent();
var requestInfo = new WebHttpRequestInfo(newSessionId, locale, remoteAddr, remoteUserAgent);
WebSession newWebSession;
try {
newWebSession = createWebSessionImpl(requestInfo);
} catch (DBException e) {
throw new DBWebException(e);
}
webSession.migrateEventHandlersTo(newWebSession);
String oldSessionId = webSession.getSessionId();
synchronized (sessionMap) {
sessionMap.remove(oldSessionId);
sessionMap.put(newSessionId, newWebSession);
}
webSession.close(false, false);
log.debug("Session rotated '" + oldSessionId + "' -> '" + newSessionId + "'");
return newWebSession;
}
/**
* Returns not expired session from cache, or restore it.
*
@@ -319,14 +283,15 @@ public class CBSessionManager implements WebAppSessionManager {
@Override
@Nullable
public WebSession findWebSession(@NotNull HttpServletRequest request) {
public WebSession findWebSession(HttpServletRequest request) {
String sessionId = getSessionId(request);
WebSession webSession;
synchronized (sessionMap) {
var session = sessionMap.get(sessionId);
webSession = (session instanceof WebSession) ? (WebSession) session : null;
if (session instanceof WebSession) {
return (WebSession) session;
}
return null;
}
return webSession;
}
@Override
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -36,7 +36,6 @@ public interface DBWServiceAuth extends DBWService {
@WebAction(authRequired = false)
WebAuthStatus authLogin(
@NotNull HttpServletRequest httpRequest,
@NotNull WebSession webSession,
@NotNull String providerId,
@Nullable String providerConfigurationId,
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -37,7 +37,6 @@ public class WebServiceBindingAuth extends WebServiceBindingBase<DBWServiceAuth>
public void bindWiring(DBWBindingContext model) {
model.getQueryType()
.dataFetcher("authLogin", env -> getService(env).authLogin(
GraphQLEndpoint.getServletRequestOrThrow(env),
getWebSession(env, false),
getArgumentVal(env, "provider"),
getArgument(env, "configuration"),
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2026 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -67,8 +67,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
@Override
public WebAuthStatus authLogin(
@NotNull HttpServletRequest httpRequest,
@NotNull WebSession inputWebSession,
@NotNull WebSession webSession,
@NotNull String providerId,
@Nullable String providerConfigurationId,
@Nullable Map<String, Object> authParameters,
@@ -76,13 +75,6 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
boolean forceSessionsLogout
) throws DBWebException {
try {
WebSession webSession = inputWebSession;
if (inputWebSession.getUser() == null) {
// Rotate anonymous web sessions during login attempts to prevent session fixation attacks.
webSession = CBApplication.getInstance().getSessionManager()
.rotateSession(httpRequest, inputWebSession);
}
var smAuthInfo = initiateAuthentication(webSession, providerId, providerConfigurationId, authParameters, forceSessionsLogout);
//TODO deprecated, use asyncAuthLogin for federated auth, exits for backward compatibility
linkWithActiveUser = linkWithActiveUser && CBApplication.getInstance().getAppConfiguration()
@@ -93,8 +85,7 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
} else {
//run it sync
var authProcessor = new WebSessionAuthProcessor(webSession, smAuthInfo, linkWithActiveUser);
List<WebAuthInfo> authInfos = authProcessor.authenticateSession();
return new WebAuthStatus(smAuthInfo.getAuthStatus(), authInfos);
return new WebAuthStatus(smAuthInfo.getAuthStatus(), authProcessor.authenticateSession());
}
} catch (SMTooManySessionsException e) {
throw new DBWebException("User authentication failed", e.getErrorType(), e);
@@ -104,22 +95,14 @@ public class WebServiceAuthImpl implements DBWServiceAuth {
}
@Override
@NotNull
public WebAsyncAuthStatus federatedLogin(
@NotNull HttpServletRequest httpRequest,
@NotNull WebSession inputWebSession,
@NotNull WebSession webSession,
@NotNull String providerId,
@Nullable String providerConfigurationId,
boolean linkWithActiveUser,
boolean forceSessionsLogout
) throws DBWebException {
WebSession webSession = inputWebSession;
if (inputWebSession.getUser() == null) {
// Rotate anonymous web sessions during login attempts to prevent session fixation attacks.
webSession = CBApplication.getInstance().getSessionManager()
.rotateSession(httpRequest, inputWebSession);
}
WebAuthProviderDescriptor providerDescriptor = WebAuthProviderRegistry.getInstance().getAuthProvider(providerId);
if (providerDescriptor == null) {
throw new DBWebException("Provider '" + providerId + "' not found");