dbeaver/pro#5816 link websession with address (#3564)

* dbeaver/pro#5816 link websession with address

* dbeaver/pro#5816 flag to disable ip binging

---------

Co-authored-by: kseniaguzeeva <112612526+kseniaguzeeva@users.noreply.github.com>
This commit is contained in:
Alexander Skoblikov
2025-07-14 19:06:52 +02:00
committed by GitHub
co-authored by kseniaguzeeva
parent 79804619d3
commit c476a56661
4 changed files with 30 additions and 6 deletions
+1 -1
View File
@@ -26,7 +26,7 @@
},
expireSessionAfterPeriod: "${CLOUDBEAVER_EXPIRE_SESSION_AFTER_PERIOD:1800000}",
bindSessionToIp: "${CLOUDBEAVER_BIND_SESSION_TO_IP:true}",
develMode: "${CLOUDBEAVER_DEVEL_MODE:false}",
enableSecurityManager: false,
@@ -90,7 +90,7 @@ public class WebSession extends BaseWebSession
public static String RUNTIME_PARAM_AUTH_INFOS = "auth-infos";
private final AtomicInteger taskCount = new AtomicInteger();
private String lastRemoteAddr;
private final String lastRemoteAddr;
private String lastRemoteUserAgent;
private String locale;
@@ -118,7 +118,8 @@ public class WebSession extends BaseWebSession
this(requestInfo.getId(),
CommonUtils.toString(requestInfo.getLocale()),
application,
sessionHandlers
sessionHandlers,
requestInfo.getLastRemoteAddress()
);
updateSessionParameters(requestInfo);
}
@@ -127,9 +128,14 @@ public class WebSession extends BaseWebSession
@NotNull String id,
@Nullable String locale,
@NotNull ServletApplication application,
@NotNull Map<String, DBWSessionHandler> sessionHandlers
@NotNull Map<String, DBWSessionHandler> sessionHandlers,
@NotNull String remoteAddr
) throws DBException {
super(id, application);
if (CommonUtils.isEmpty(remoteAddr)) {
throw new DBException("Remote address cannot be empty");
}
this.lastRemoteAddr = remoteAddr;
this.lastAccessTime = this.createTime;
this.sessionHandlers = sessionHandlers;
setLocale(CommonUtils.toString(locale, this.locale));
@@ -458,7 +464,6 @@ public class WebSession extends BaseWebSession
}
public synchronized void updateSessionParameters(WebHttpRequestInfo requestInfo) {
this.lastRemoteAddr = requestInfo.getLastRemoteAddress();
this.lastRemoteUserAgent = requestInfo.getLastRemoteUserAgent();
this.cacheExpired = false;
}
@@ -52,6 +52,7 @@ public class CBServerConfig implements WebServerConfiguration {
@SerializedName("database")
private WebDatabaseConfig databaseConfiguration = new WebDatabaseConfig();
private String staticContent = "";
private boolean bindSessionToIp = true;
public CBServerConfig() {
this.securityManagerConfiguration = createSecurityManagerConfiguration();
@@ -186,4 +187,8 @@ public class CBServerConfig implements WebServerConfiguration {
public boolean isSecureCookies() {
return secureCookies;
}
public boolean isBindSessionToIp() {
return bindSessionToIp;
}
}
@@ -1,6 +1,6 @@
/*
* DBeaver - Universal Database Manager
* Copyright (C) 2010-2024 DBeaver Corp and others
* Copyright (C) 2010-2025 DBeaver Corp and others
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -156,6 +156,20 @@ public class CBSessionManager implements WebAppSessionManager {
}
}
String currentRemote = request.getRemoteAddr();
if (application.getServerConfiguration().isBindSessionToIp()
&& (CommonUtils.isEmpty(currentRemote) || !currentRemote.equals(webSession.getLastRemoteAddr()))
) {
var error = new DBWebException(
"Session remote address mismatch. Expected: " + webSession.getLastRemoteAddr() +
", actual: " + currentRemote,
DBWebException.ERROR_CODE_ACCESS_DENIED
);
log.error(error);
webSession.addSessionError(error);
closeSession(webSession.getSessionId());
}
return webSession;
}