From e0cfb5e623931cc7679df1375a59eb642bd5ed50 Mon Sep 17 00:00:00 2001 From: Alexander Skoblikov Date: Wed, 29 Jun 2022 19:25:31 +0300 Subject: [PATCH] CB-2213 send information about previous sm session on login (#931) --- .../cloudbeaver/model/session/WebSession.java | 4 ++ .../service/auth/RPSessionHandler.java | 4 +- .../service/auth/impl/WebServiceAuthImpl.java | 2 + .../internal/AuthAttemptSessionInfo.java | 23 +++++++- .../CBEmbeddedSecurityController.java | 56 +++++++++++++------ 5 files changed, 71 insertions(+), 18 deletions(-) diff --git a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSession.java b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSession.java index a3f464bf28..896c97c4a9 100644 --- a/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSession.java +++ b/server/bundles/io.cloudbeaver.model/src/io/cloudbeaver/model/session/WebSession.java @@ -228,6 +228,10 @@ public class WebSession extends AbstractSessionPersistent implements SMSession, return allMetaParams; } + public synchronized WebUserContext getUserContext() { + return userContext; + } + public synchronized String getUserId() { return userContext.getUserId(); } diff --git a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/RPSessionHandler.java b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/RPSessionHandler.java index 27c3688c3d..fcb178b64b 100644 --- a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/RPSessionHandler.java +++ b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/RPSessionHandler.java @@ -81,7 +81,9 @@ public class RPSessionHandler implements DBWSessionHandler { webSession.getProgressMonitor(), sessionParameters, credentials); try { SMAuthInfo smAuthInfo = securityController.authenticate( - webSession.getSessionId(), sessionParameters, + webSession.getSessionId(), + webSession.getUserContext().getSmSessionId(), + sessionParameters, WebSession.CB_SESSION_TYPE, authProvider.getId(), null, userCredentials); webSession.updateSMAuthInfo(smAuthInfo); } catch (SMException e) { diff --git a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java index accf30bdf2..ca2fa06499 100644 --- a/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java +++ b/server/bundles/io.cloudbeaver.service.auth/src/io/cloudbeaver/service/auth/impl/WebServiceAuthImpl.java @@ -66,9 +66,11 @@ public class WebServiceAuthImpl implements DBWServiceAuth { authParameters = Map.of(); } SMController securityController = webSession.getSecurityController(); + String currentSmSessionId = webSession.getUserContext().getSmSessionId(); try { var smAuthInfo = securityController.authenticate( webSession.getSessionId(), + currentSmSessionId, webSession.getSessionParameters(), WebSession.CB_SESSION_TYPE, providerId, diff --git a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/AuthAttemptSessionInfo.java b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/AuthAttemptSessionInfo.java index 0f4401a0b1..7c5aee36e3 100644 --- a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/AuthAttemptSessionInfo.java +++ b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/AuthAttemptSessionInfo.java @@ -17,31 +17,52 @@ package io.cloudbeaver.service.security.internal; +import org.jkiss.code.NotNull; +import org.jkiss.code.Nullable; import org.jkiss.dbeaver.model.security.SMSessionType; import java.util.Map; public class AuthAttemptSessionInfo { + @NotNull private final String appSessionId; + @Nullable + private final String smSessionId; + @NotNull private final SMSessionType sessionType; + @NotNull private final Map sessionParams; - public AuthAttemptSessionInfo(String appSessionId, SMSessionType sessionType, Map sessionParams) { + public AuthAttemptSessionInfo( + @NotNull String appSessionId, + @Nullable String smSessionId, + @NotNull SMSessionType sessionType, + @NotNull Map sessionParams + ) { this.appSessionId = appSessionId; + this.smSessionId = smSessionId; this.sessionType = sessionType; this.sessionParams = sessionParams; } + @NotNull public String getAppSessionId() { return appSessionId; } + @NotNull public SMSessionType getSessionType() { return sessionType; } + @NotNull public Map getSessionParams() { return sessionParams; } + + @Nullable + public String getSmSessionId() { + return smSessionId; + } } diff --git a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java index 3470969f2f..c2aded16d1 100644 --- a/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java +++ b/server/bundles/io.cloudbeaver.service.security/src/io/cloudbeaver/service/security/internal/CBEmbeddedSecurityController.java @@ -793,7 +793,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen } } - private String createSessionIfNotExist( + private String createSmSession( @NotNull String appSessionId, @Nullable String userId, @NotNull Map parameters, @@ -837,7 +837,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen public SMAuthInfo authenticateAnonymousUser(@NotNull String appSessionId, @NotNull Map sessionParameters, @NotNull SMSessionType sessionType) throws DBException { try (Connection dbCon = database.openConnection()) { try (JDBCTransaction txn = new JDBCTransaction(dbCon)) { - var smSessionId = createSessionIfNotExist(appSessionId, null, sessionParameters, sessionType, dbCon); + var smSessionId = createSmSession(appSessionId, null, sessionParameters, sessionType, dbCon); var token = generateAuthToken(smSessionId, null, dbCon); var permissions = getAnonymousUserPermissions(); txn.commit(); @@ -856,6 +856,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen @Override public SMAuthInfo authenticate( @NotNull String appSessionId, + @Nullable String previousSmSessionId, @NotNull Map sessionParameters, @NotNull SMSessionType sessionType, @NotNull String authProviderId, @@ -879,6 +880,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen authProviderConfigurationId, userIdentifyingCredentials, appSessionId, + previousSmSessionId, sessionType, sessionParameters ); @@ -905,6 +907,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen String authProviderConfigurationId, Map authData, String appSessionId, + String prevSessionId, SMSessionType sessionType, Map sessionParameters ) throws DBException { @@ -912,13 +915,18 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen try (Connection dbCon = database.openConnection()) { try (JDBCTransaction txn = new JDBCTransaction(dbCon)) { try (PreparedStatement dbStat = dbCon.prepareStatement( - "INSERT INTO CB_AUTH_ATTEMPT(AUTH_ID,AUTH_STATUS,APP_SESSION_ID,SESSION_TYPE,APP_SESSION_STATE) " + - "VALUES(?,?,?,?,?)")) { + "INSERT INTO CB_AUTH_ATTEMPT(AUTH_ID,AUTH_STATUS,APP_SESSION_ID,SESSION_TYPE,APP_SESSION_STATE,SESSION_ID) " + + "VALUES(?,?,?,?,?,?)")) { dbStat.setString(1, authAttemptId); dbStat.setString(2, status.toString()); dbStat.setString(3, appSessionId); dbStat.setString(4, sessionType.getSessionType()); dbStat.setString(5, gson.toJson(sessionParameters)); + if (prevSessionId != null && isSmSessionNotExpired(prevSessionId)) { + dbStat.setString(6, prevSessionId); + } else { + dbStat.setNull(6, Types.VARCHAR); + } dbStat.execute(); } @@ -939,6 +947,11 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen } } + private boolean isSmSessionNotExpired(String prevSessionId) { + //TODO: implement after we start tracking user logout + return true; + } + @Override public void updateAuthStatus(@NotNull String authId, @NotNull SMAuthStatus authStatus, @@ -1101,7 +1114,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen authProviderId, authAttemptSessionInfo.getSessionParams(), userCredentials, - finishAuthMonitor + finishAuthMonitor, + authAttemptSessionInfo.getSmSessionId() == null ); if (userIdFromCreds == null) { @@ -1114,13 +1128,18 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen try (Connection dbCon = database.openConnection()) { try (JDBCTransaction txn = new JDBCTransaction(dbCon)) { - var smSessionId = createSessionIfNotExist( - authAttemptSessionInfo.getAppSessionId(), - userId, - authAttemptSessionInfo.getSessionParams(), - authAttemptSessionInfo.getSessionType(), - dbCon - ); + String smSessionId; + if (authAttemptSessionInfo.getSmSessionId() == null) { + smSessionId = createSmSession( + authAttemptSessionInfo.getAppSessionId(), + userId, + authAttemptSessionInfo.getSessionParams(), + authAttemptSessionInfo.getSessionType(), + dbCon + ); + } else { + smSessionId = authAttemptSessionInfo.getSmSessionId(); + } var token = generateAuthToken(smSessionId, userId, dbCon); var permissions = getUserPermissions(userId); txn.commit(); @@ -1137,7 +1156,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen private AuthAttemptSessionInfo readAuthAttemptSessionInfo(@NotNull String authId) throws DBException { try (Connection dbCon = database.openConnection()) { try (PreparedStatement dbStat = dbCon.prepareStatement( - "SELECT APP_SESSION_ID,SESSION_TYPE,APP_SESSION_STATE FROM CB_AUTH_ATTEMPT WHERE AUTH_ID=?" + "SELECT APP_SESSION_ID,SESSION_TYPE,APP_SESSION_STATE,SESSION_ID FROM CB_AUTH_ATTEMPT WHERE AUTH_ID=?" )) { dbStat.setString(1, authId); try (ResultSet dbResult = dbStat.executeQuery()) { @@ -1149,7 +1168,9 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen Map sessionParams = gson.fromJson( dbResult.getString(3), MAP_STRING_OBJECT_TYPE ); - return new AuthAttemptSessionInfo(appSessionId, sessionType, sessionParams); + String smSessionId = dbResult.getString(4); + + return new AuthAttemptSessionInfo(appSessionId, smSessionId, sessionType, sessionParams); } } } catch (SQLException e) { @@ -1161,7 +1182,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen @NotNull String authProviderId, @NotNull Map sessionParameters, @NotNull Map userCredentials, - @NotNull DBRProgressMonitor progressMonitor + @NotNull DBRProgressMonitor progressMonitor, + boolean newUserAuthenticationTry ) throws DBException { AuthProviderDescriptor authProvider = getAuthProvider(authProviderId); SMAuthProvider smAuthProviderInstance = authProvider.getInstance(); @@ -1172,7 +1194,7 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen } catch (DBException e) { return null; } - if (userId == null) { + if (userId == null && newUserAuthenticationTry) { if (!(authProvider.getInstance() instanceof SMAuthProviderExternal)) { return null; } @@ -1187,6 +1209,8 @@ public class CBEmbeddedSecurityController implements SMAdminController, SMAuthen } } setUserCredentials(userId, authProviderId, userCredentials); + } else { + userId = userIdFromCredentials; } if (authProvider.isTrusted()) { if (WebAppUtils.getWebApplication().isMultiNode()) {