Dbeaver/pro#6123 add unauthorize audit loging (#3977)

* dbeaver/pro#6123 remove reset user state

* dbeaver/pro#6123 remove reset user state on auth

* dbeaver/pro#6123 remove reset user state on auth

* dbeaver/pro#6123 fix last remote addr

* dbeaver/pro#6123 fix last remote addr

* dbeaver/pro#6123 fix last remote addr

* dbeaver/pro#6123 revert taking ip from header

---------

Co-authored-by: Daria Marutkina <125263541+dariamarutkina@users.noreply.github.com>
This commit is contained in:
Ruslan Musaev
2025-12-16 15:20:12 +01:00
committed by GitHub
co-authored by Daria Marutkina
parent c2045091d0
commit c119c93a7d
3 changed files with 19 additions and 9 deletions
@@ -254,18 +254,24 @@ public class WebSession extends BaseWebSession
}
// Note: for admin use only
public synchronized void resetUserState() throws DBException {
public synchronized void resetUserState(boolean needResetUserCache) throws DBException {
clearAuthTokens();
try {
resetSessionCache();
} catch (DBCException e) {
addSessionError(e);
log.error(e);
if (needResetUserCache) {
try {
resetSessionCache();
} catch (DBCException e) {
addSessionError(e);
log.error(e);
}
}
refreshUserData();
clearSessionContext();
}
public synchronized void resetUserState() throws DBException {
resetUserState(true);
}
@NotNull
public DBPEventListener getDataSourceConnectListener() {
return connectListener;
@@ -74,7 +74,7 @@ public class WebSessionAuthProcessor {
}
} catch (Exception e) {
if (resetUserStateOnError) {
webSession.resetUserState();
webSession.resetUserState(false);
}
throw new DBException(e.getMessage(), e);
}
@@ -27,6 +27,7 @@ import jakarta.servlet.ServletResponse;
import jakarta.servlet.http.HttpServletRequest;
import org.jkiss.code.NotNull;
import org.jkiss.code.Nullable;
import org.jkiss.dbeaver.model.qm.QMConstants;
import org.jkiss.utils.CommonUtils;
import java.lang.reflect.Method;
@@ -46,8 +47,11 @@ public class GraphQLLoggerUtil {
return null;
}
String userId = session.getUserContext().getUserId();
if (userId == null && session.getUserContext().isAuthorizedInSecurityManager()) {
return "anonymous";
if (userId == null) {
if (session.getUserContext().isAuthorizedInSecurityManager()) {
return QMConstants.QM_ANONYMOUS_DOMAIN;
}
return QMConstants.QM_UNAUTHORIZED_DOMAIN;
}
return userId;
}