Browse Source

Fix possible race condition and signature change case. Additional improvements on UI are required

pull/7637/head
Andrii Shvaika 4 years ago
parent
commit
2b74234c2c
  1. 22
      application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java
  2. 4
      application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java

22
application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java

@ -103,27 +103,29 @@ public class DefaultJwtSettingsService implements JwtSettingsService {
@Override
public JwtSettings reloadJwtSettings() {
synchronized (this) {
this.jwtSettings = null;
}
return getJwtSettings();
return getJwtSettings(true);
}
@Override
public JwtSettings getJwtSettings() {
if (this.jwtSettings == null) {
return getJwtSettings(false);
}
public JwtSettings getJwtSettings(boolean forceReload) {
if (this.jwtSettings == null || forceReload) {
synchronized (this) {
if (this.jwtSettings == null) {
this.jwtSettings = getJwtSettingsFromDb();
if (this.jwtSettings == null) {
this.jwtSettings = getJwtSettingsFromYml();
if (this.jwtSettings == null || forceReload) {
JwtSettings result = getJwtSettingsFromDb();
if (result == null) {
result = getJwtSettingsFromYml();
log.warn("Loading the JWT settings from YML since there are no settings in DB. Looks like the upgrade script was not applied.");
}
if (isSigningKeyDefault(jwtSettings)) {
if (isSigningKeyDefault(result)) {
log.warn("WARNING: The platform is configured to use default JWT Signing Key. " +
"This is a security issue that needs to be resolved. Please change the JWT Signing Key using the Web UI. " +
"Navigate to \"System settings -> Security settings\" while logged in as a System Administrator.");
}
this.jwtSettings = result;
}
}
}

4
application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java

@ -205,10 +205,10 @@ public class JwtTokenFactory {
return Jwts.parser()
.setSigningKey(jwtSettingsService.getJwtSettings().getTokenSigningKey())
.parseClaimsJws(token.getToken());
} catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException | SignatureException ex) {
} catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException ex) {
log.debug("Invalid JWT Token", ex);
throw new BadCredentialsException("Invalid JWT token: ", ex);
} catch (ExpiredJwtException expiredEx) {
} catch (SignatureException | ExpiredJwtException expiredEx) {
log.debug("JWT Token is expired", expiredEx);
throw new JwtExpiredTokenException(token, "JWT Token expired", expiredEx);
}

Loading…
Cancel
Save