From 2b74234c2cc0e7d54c5dd8da46aa929871499e9b Mon Sep 17 00:00:00 2001 From: Andrii Shvaika Date: Thu, 17 Nov 2022 13:55:50 +0200 Subject: [PATCH] Fix possible race condition and signature change case. Additional improvements on UI are required --- .../settings/DefaultJwtSettingsService.java | 22 ++++++++++--------- .../security/model/token/JwtTokenFactory.java | 4 ++-- 2 files changed, 14 insertions(+), 12 deletions(-) diff --git a/application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java b/application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java index e306dd1d2d..36beaecea3 100644 --- a/application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java +++ b/application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java @@ -103,27 +103,29 @@ public class DefaultJwtSettingsService implements JwtSettingsService { @Override public JwtSettings reloadJwtSettings() { - synchronized (this) { - this.jwtSettings = null; - } - return getJwtSettings(); + return getJwtSettings(true); } @Override public JwtSettings getJwtSettings() { - if (this.jwtSettings == null) { + return getJwtSettings(false); + } + + public JwtSettings getJwtSettings(boolean forceReload) { + if (this.jwtSettings == null || forceReload) { synchronized (this) { - if (this.jwtSettings == null) { - this.jwtSettings = getJwtSettingsFromDb(); - if (this.jwtSettings == null) { - this.jwtSettings = getJwtSettingsFromYml(); + if (this.jwtSettings == null || forceReload) { + JwtSettings result = getJwtSettingsFromDb(); + if (result == null) { + result = getJwtSettingsFromYml(); log.warn("Loading the JWT settings from YML since there are no settings in DB. Looks like the upgrade script was not applied."); } - if (isSigningKeyDefault(jwtSettings)) { + if (isSigningKeyDefault(result)) { log.warn("WARNING: The platform is configured to use default JWT Signing Key. " + "This is a security issue that needs to be resolved. Please change the JWT Signing Key using the Web UI. " + "Navigate to \"System settings -> Security settings\" while logged in as a System Administrator."); } + this.jwtSettings = result; } } } diff --git a/application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java b/application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java index 6da68c37f3..71fd66231a 100644 --- a/application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java +++ b/application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java @@ -205,10 +205,10 @@ public class JwtTokenFactory { return Jwts.parser() .setSigningKey(jwtSettingsService.getJwtSettings().getTokenSigningKey()) .parseClaimsJws(token.getToken()); - } catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException | SignatureException ex) { + } catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException ex) { log.debug("Invalid JWT Token", ex); throw new BadCredentialsException("Invalid JWT token: ", ex); - } catch (ExpiredJwtException expiredEx) { + } catch (SignatureException | ExpiredJwtException expiredEx) { log.debug("JWT Token is expired", expiredEx); throw new JwtExpiredTokenException(token, "JWT Token expired", expiredEx); }