mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
dbeaver/pro#7343 add additional validation for token auth (#3876)
Co-authored-by: Evgenia <139753579+EvgeniaBzzz@users.noreply.github.com>
This commit is contained in:
+4
@@ -74,4 +74,8 @@ public interface SMAuthProviderExternal<AUTH_SESSION extends SMSession> extends
|
||||
*/
|
||||
default void postAuthentication() {}
|
||||
|
||||
@Override
|
||||
default boolean supportsOpeningSessionAsChild() {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
+5
@@ -101,6 +101,11 @@ public class LocalAuthProvider implements SMAuthProvider<LocalAuthSession>, SMBr
|
||||
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean supportsOpeningSessionAsChild() {
|
||||
return false;
|
||||
}
|
||||
|
||||
public static boolean changeUserPassword(@NotNull WebSession webSession, @NotNull String oldPassword, @NotNull String newPassword) throws DBException {
|
||||
String userName = webSession.getUser().getUserId();
|
||||
|
||||
|
||||
+7
@@ -2472,6 +2472,13 @@ public class CBEmbeddedSecurityController<T extends ServletAuthApplication>
|
||||
if (autoAssign != null && CommonUtils.isNotEmpty(autoAssign.getAuthRoleAssignReason())) {
|
||||
log.info(activeUserId + " authenticated with role " + autoAssign.getAuthRole() + ", reason: " + autoAssign.getAuthRoleAssignReason());
|
||||
}
|
||||
} else {
|
||||
SMAuthProvider<?> authProviderInstance = authProvider.getInstance();
|
||||
if (!authProviderInstance.supportsOpeningSessionAsChild()) {
|
||||
var error = "Auth provider '" + authProviderId + "' doesn't support opening as a child session";
|
||||
updateAuthStatus(authId, SMAuthStatus.ERROR, dbStoredUserData, error, null);
|
||||
return SMAuthInfo.error(authId, error, isMainAuthSession, null, authInfo.getAppSessionId());
|
||||
}
|
||||
}
|
||||
dbStoredUserData.put(
|
||||
authConfiguration,
|
||||
|
||||
Reference in New Issue
Block a user