From 6569ff68dc38db4e16bb3e4c7a4fa58e2b2ba65d Mon Sep 17 00:00:00 2001 From: Alexander Skoblikov Date: Fri, 24 Jun 2022 19:15:37 +0300 Subject: [PATCH] CB-2127 authorization fixes --- .../model/session/WebSessionAuthJob.java | 4 +- .../service/core/DBWServiceCore.java | 4 +- .../service/auth/WebAuthStatus.java | 10 ++--- .../CBEmbeddedSecurityController.java | 42 +++++++++++++------ 4 files changed, 39 insertions(+), 21 deletions(-) diff --git a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSessionAuthJob.java b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSessionAuthJob.java index 5459fe2d60..ed46236d16 100644 --- a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSessionAuthJob.java +++ b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSessionAuthJob.java @@ -46,7 +46,7 @@ import java.util.Map; public class WebSessionAuthJob extends WebAsyncTaskProcessor { private static final Log log = Log.getLog(WebSessionAuthJob.class); - private static final int MAX_ATTEMPT = 10; + private static final int MAX_ATTEMPT = 20; @NotNull private final WebSession webSession; @NotNull @@ -131,7 +131,7 @@ public class WebSessionAuthJob extends WebAsyncTaskProcessor { if (!providerEnabled && webSession.getUser() != null) { linkWithActiveUser = true; } - } else if (!providerEnabled || !webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) { + } else if (!providerEnabled && !webSession.hasPermission(DBWConstants.PERMISSION_ADMIN)) { throw new DBWebException("Authentication provider '" + providerId + "' is disabled"); } diff --git a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java index 48fab03bed..ebcd724f43 100644 --- a/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java +++ b/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java @@ -16,11 +16,11 @@ */ package io.cloudbeaver.service.core; -import io.cloudbeaver.service.DBWService; import io.cloudbeaver.DBWebException; import io.cloudbeaver.WebAction; import io.cloudbeaver.model.*; import io.cloudbeaver.model.session.WebSession; +import io.cloudbeaver.service.DBWService; import org.jkiss.code.NotNull; import org.jkiss.code.Nullable; import org.jkiss.dbeaver.model.navigator.DBNBrowseSettings; @@ -142,7 +142,7 @@ public interface DBWServiceCore extends DBWService { /////////////////////////////////////////// // Async tasks - @WebAction + @WebAction(requirePermissions = {}) WebAsyncTaskInfo getAsyncTaskInfo(WebSession webSession, String taskId, Boolean removeOnFinish) throws DBWebException; @WebAction diff --git a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/WebAuthStatus.java b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/WebAuthStatus.java index 0e696799aa..15d3afd642 100644 --- a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/WebAuthStatus.java +++ b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/WebAuthStatus.java @@ -8,18 +8,18 @@ import java.util.List; public class WebAuthStatus { private final WebAsyncTaskInfo taskInfo; - private final String redirectUrl; + private final String redirectLink; private final List userTokens; public WebAuthStatus(WebAsyncTaskInfo taskInfo, String redirectUrl) { this.taskInfo = taskInfo; - this.redirectUrl = redirectUrl; + this.redirectLink = redirectUrl; this.userTokens = null; } public WebAuthStatus(List userTokens) { this.taskInfo = null; - this.redirectUrl = null; + this.redirectLink = null; this.userTokens = userTokens; } @@ -29,8 +29,8 @@ public class WebAuthStatus { } @Property - public String getRedirectUrl() { - return redirectUrl; + public String getRedirectLink() { + return redirectLink; } @Property diff --git a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java index b48c77914e..190e0cebc3 100644 --- a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java +++ b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java @@ -942,17 +942,34 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen @NotNull SMAuthStatus authStatus, @NotNull Map authInfo, @Nullable String error) throws DBException { + var existAuthInfo = getAuthStatus(authId); + if (existAuthInfo.getAuthStatus() != SMAuthStatus.IN_PROGRESS) { + throw new SMException("Authorization already finished and cannot be updated"); + } + updateAuthStatus(authId, authStatus, authInfo, null, null); + } + + private void updateAuthStatus(@NotNull String authId, + @NotNull SMAuthStatus authStatus, + @NotNull Map authInfo, + @Nullable String error, + @Nullable String smSessionId) throws DBException { try (Connection dbCon = database.openConnection(); JDBCTransaction txn = new JDBCTransaction(dbCon)) { try (PreparedStatement dbStat = dbCon.prepareStatement( - "UPDATE CB_AUTH_ATTEMPT SET AUTH_STATUS=?,AUTH_ERROR=? WHERE AUTH_ID=?")) { + "UPDATE CB_AUTH_ATTEMPT SET AUTH_STATUS=?,AUTH_ERROR=?,SESSION_ID=? WHERE AUTH_ID=?")) { dbStat.setString(1, authStatus.toString()); if (error != null) { dbStat.setString(2, error); } else { dbStat.setNull(2, Types.VARCHAR); } - dbStat.setString(3, authId); + if (smSessionId != null) { + dbStat.setString(3, smSessionId); + } else { + dbStat.setNull(3, Types.VARCHAR); + } + dbStat.setString(4, authId); if (dbStat.executeUpdate() <= 0) { throw new DBCException("Auth attempt '" + authId + "' doesn't exist"); } @@ -966,7 +983,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen + "KEY(AUTH_ID,AUTH_PROVIDER_ID) VALUES(?,?,?)")) { dbStat.setString(1, authId); dbStat.setString(2, providerId); - dbStat.setString(4, gson.toJson(authData)); + dbStat.setString(3, gson.toJson(authData)); dbStat.execute(); } } @@ -1077,17 +1094,15 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen userCredentials, finishAuthMonitor ); - if (userId == null) { - userId = userIdFromCreds; - } else if (!userId.equals(userIdFromCreds)) { - throw new SMException("Authorization attempt contains different users"); + + if (userIdFromCreds == null) { + var error = "Invalid user credentials"; + updateAuthStatus(authId, SMAuthStatus.ERROR, authInfo.getAuthData(), error); + return SMAuthInfo.error(authId, error); } + userId = userIdFromCreds; } - - if (userId == null) { - return SMAuthInfo.error(authId, "Invalid user credentials"); - } try (Connection dbCon = database.openConnection()) { try (JDBCTransaction txn = new JDBCTransaction(dbCon)) { var smSessionId = createSessionIfNotExist( @@ -1100,10 +1115,13 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen var token = generateAuthToken(smSessionId, userId, dbCon); var permissions = getUserPermissions(userId); txn.commit(); + updateAuthStatus(authId, SMAuthStatus.SUCCESS, authInfo.getAuthData(), null, smSessionId); return SMAuthInfo.success(authId, token, new SMAuthPermissions(userId, smSessionId, permissions), authInfo.getAuthData()); } } catch (SQLException e) { - throw new SMException("Error during token generation", e); + var error = "Error during token generation"; + updateAuthStatus(authId, SMAuthStatus.ERROR, authInfo.getAuthData(), error); + throw new SMException(error, e); } }