mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-1345 SAML session management fix
This commit is contained in:
@@ -52,6 +52,9 @@ import org.jkiss.dbeaver.runtime.properties.ObjectPropertyDescriptor;
|
||||
import org.jkiss.dbeaver.runtime.properties.PropertyCollector;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
import javax.servlet.http.Cookie;
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
import java.io.InputStream;
|
||||
import java.util.Arrays;
|
||||
import java.util.LinkedHashMap;
|
||||
@@ -344,4 +347,22 @@ public class WebServiceUtils {
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
public static void addResponseCookie(HttpServletResponse response, String cookieName, String cookieValue, long maxSessionIdleTime) {
|
||||
Cookie sessionCookie = new Cookie(cookieName, cookieValue);
|
||||
if (maxSessionIdleTime > 0) {
|
||||
sessionCookie.setMaxAge((int) (maxSessionIdleTime / 1000));
|
||||
}
|
||||
sessionCookie.setPath(CBApplication.getInstance().getRootURI());
|
||||
response.addCookie(sessionCookie);
|
||||
}
|
||||
|
||||
public static String getRequestCookie(HttpServletRequest request, String cookieName) {
|
||||
for (Cookie cookie : request.getCookies()) {
|
||||
if (cookie.getName().equals(cookieName)) {
|
||||
return cookie.getValue();
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
+6
-11
@@ -58,7 +58,6 @@ import org.jkiss.dbeaver.registry.ProjectMetadata;
|
||||
import org.jkiss.dbeaver.runtime.jobs.DisconnectJob;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
|
||||
import javax.servlet.http.Cookie;
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
import javax.servlet.http.HttpSession;
|
||||
@@ -447,17 +446,13 @@ public class WebSession implements DBASession, DBAAuthCredentialsProvider, IAdap
|
||||
log.error("Error persisting web session", e);
|
||||
}
|
||||
}
|
||||
{
|
||||
long maxSessionIdleTime = CBApplication.getInstance().getMaxSessionIdleTime();
|
||||
|
||||
SimpleDateFormat sdf = new SimpleDateFormat(DBConstants.DEFAULT_ISO_TIMESTAMP_FORMAT);
|
||||
sdf.setTimeZone(TimeZone.getTimeZone("GMT"));
|
||||
Cookie sessionCookie = new Cookie(SESSION_TEMP_COOKIE, sdf.format(new Date(System.currentTimeMillis() + maxSessionIdleTime)));
|
||||
sessionCookie.setMaxAge((int) (maxSessionIdleTime / 1000));
|
||||
sessionCookie.setPath(CBApplication.getInstance().getRootURI());
|
||||
//sessionCookie.setComment("CB session cookie");
|
||||
response.addCookie(sessionCookie);
|
||||
}
|
||||
long maxSessionIdleTime = CBApplication.getInstance().getMaxSessionIdleTime();
|
||||
SimpleDateFormat sdf = new SimpleDateFormat(DBConstants.DEFAULT_ISO_TIMESTAMP_FORMAT);
|
||||
sdf.setTimeZone(TimeZone.getTimeZone("GMT"));
|
||||
String cookieValue = sdf.format(new Date(System.currentTimeMillis() + maxSessionIdleTime));
|
||||
WebServiceUtils.addResponseCookie(
|
||||
response, SESSION_TEMP_COOKIE, cookieValue, maxSessionIdleTime);
|
||||
}
|
||||
|
||||
@Association
|
||||
|
||||
+12
@@ -20,6 +20,7 @@ import io.cloudbeaver.DBWebException;
|
||||
import io.cloudbeaver.server.CBApplication;
|
||||
import io.cloudbeaver.server.CBPlatform;
|
||||
import org.jkiss.code.NotNull;
|
||||
import org.jkiss.code.Nullable;
|
||||
import org.jkiss.dbeaver.Log;
|
||||
import org.jkiss.dbeaver.runtime.DBWorkbench;
|
||||
import org.jkiss.utils.CommonUtils;
|
||||
@@ -72,14 +73,17 @@ public class WebSessionManager {
|
||||
return true;
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public WebSession getWebSession(@NotNull HttpServletRequest request, @NotNull HttpServletResponse response) throws DBWebException {
|
||||
return getWebSession(request, response, true);
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public WebSession getWebSession(@NotNull HttpServletRequest request, @NotNull HttpServletResponse response, boolean errorOnNoFound) throws DBWebException {
|
||||
return getWebSession(request, response, true, errorOnNoFound);
|
||||
}
|
||||
|
||||
@NotNull
|
||||
public WebSession getWebSession(@NotNull HttpServletRequest request, @NotNull HttpServletResponse response, boolean updateInfo, boolean errorOnNoFound) throws DBWebException {
|
||||
HttpSession httpSession = request.getSession(true);
|
||||
String sessionId = httpSession.getId();
|
||||
@@ -113,6 +117,14 @@ public class WebSessionManager {
|
||||
return webSession;
|
||||
}
|
||||
|
||||
@Nullable
|
||||
public WebSession getWebSession(@NotNull String sessionId) {
|
||||
synchronized (sessionMap) {
|
||||
return sessionMap.get(sessionId);
|
||||
}
|
||||
}
|
||||
|
||||
@Nullable
|
||||
public WebSession findWebSession(HttpServletRequest request) {
|
||||
String sessionId = request.getSession().getId();
|
||||
synchronized (sessionMap) {
|
||||
|
||||
+12
-1
@@ -101,7 +101,18 @@ public class CBJettyServer {
|
||||
}
|
||||
}
|
||||
|
||||
SessionHandler sessionHandler = new SessionHandler();
|
||||
SessionHandler sessionHandler = new SessionHandler()/* {
|
||||
public HttpCookie access(HttpSession session, boolean secure) {
|
||||
HttpCookie cookie = getSessionCookie(session, _context == null ? "/" : (_context.getContextPath()), secure);
|
||||
return cookie;
|
||||
}
|
||||
|
||||
@Override
|
||||
public int getRefreshCookieAge() {
|
||||
// Refresh cookie always (we need it for FA requests)
|
||||
return 1;
|
||||
}
|
||||
}*/;
|
||||
DefaultSessionCache sessionCache = new DefaultSessionCache(sessionHandler);
|
||||
FileSessionDataStore sessionStore = new FileSessionDataStore();
|
||||
|
||||
|
||||
+5
-3
@@ -24,7 +24,9 @@ import javax.servlet.SessionCookieConfig;
|
||||
|
||||
public class CBServerContextListener implements ServletContextListener {
|
||||
|
||||
public static final String DBEAVER_SESSION_COOKIE_NAME = "DBEAVER_SESSION_ID";
|
||||
public static final String CB_SESSION_COOKIE_NAME = "cb-session-id";
|
||||
// One week
|
||||
//private static final int CB_SESSION_LIFE_TIME = 60 * 60 * 24 * 7;
|
||||
|
||||
public void contextInitialized(ServletContextEvent sce) {
|
||||
SessionCookieConfig scf = sce.getServletContext().getSessionCookieConfig();
|
||||
@@ -32,10 +34,10 @@ public class CBServerContextListener implements ServletContextListener {
|
||||
scf.setComment("Cloudbeaver Session ID");
|
||||
//scf.setDomain(domain);
|
||||
//scf.setHttpOnly(httpOnly);
|
||||
//scf.setMaxAge(maxAge);
|
||||
//scf.setMaxAge(CB_SESSION_LIFE_TIME);
|
||||
scf.setPath(CBApplication.getInstance().getRootURI());
|
||||
//scf.setSecure(isSecure);
|
||||
scf.setName(DBEAVER_SESSION_COOKIE_NAME);
|
||||
scf.setName(CB_SESSION_COOKIE_NAME);
|
||||
}
|
||||
|
||||
public void contextDestroyed(ServletContextEvent sce) {
|
||||
|
||||
Reference in New Issue
Block a user