Browse Source

Fix possible race condition and signature change case. Additional improvements on UI are required

pull/7637/head
Andrii Shvaika 4 years ago
parent
commit
2b74234c2c
  1. 22
      application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java
  2. 4
      application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java

22
application/src/main/java/org/thingsboard/server/service/security/auth/jwt/settings/DefaultJwtSettingsService.java

@ -103,27 +103,29 @@ public class DefaultJwtSettingsService implements JwtSettingsService {
@Override @Override
public JwtSettings reloadJwtSettings() { public JwtSettings reloadJwtSettings() {
synchronized (this) { return getJwtSettings(true);
this.jwtSettings = null;
}
return getJwtSettings();
} }
@Override @Override
public JwtSettings getJwtSettings() { public JwtSettings getJwtSettings() {
if (this.jwtSettings == null) { return getJwtSettings(false);
}
public JwtSettings getJwtSettings(boolean forceReload) {
if (this.jwtSettings == null || forceReload) {
synchronized (this) { synchronized (this) {
if (this.jwtSettings == null) { if (this.jwtSettings == null || forceReload) {
this.jwtSettings = getJwtSettingsFromDb(); JwtSettings result = getJwtSettingsFromDb();
if (this.jwtSettings == null) { if (result == null) {
this.jwtSettings = getJwtSettingsFromYml(); result = getJwtSettingsFromYml();
log.warn("Loading the JWT settings from YML since there are no settings in DB. Looks like the upgrade script was not applied."); log.warn("Loading the JWT settings from YML since there are no settings in DB. Looks like the upgrade script was not applied.");
} }
if (isSigningKeyDefault(jwtSettings)) { if (isSigningKeyDefault(result)) {
log.warn("WARNING: The platform is configured to use default JWT Signing Key. " + log.warn("WARNING: The platform is configured to use default JWT Signing Key. " +
"This is a security issue that needs to be resolved. Please change the JWT Signing Key using the Web UI. " + "This is a security issue that needs to be resolved. Please change the JWT Signing Key using the Web UI. " +
"Navigate to \"System settings -> Security settings\" while logged in as a System Administrator."); "Navigate to \"System settings -> Security settings\" while logged in as a System Administrator.");
} }
this.jwtSettings = result;
} }
} }
} }

4
application/src/main/java/org/thingsboard/server/service/security/model/token/JwtTokenFactory.java

@ -205,10 +205,10 @@ public class JwtTokenFactory {
return Jwts.parser() return Jwts.parser()
.setSigningKey(jwtSettingsService.getJwtSettings().getTokenSigningKey()) .setSigningKey(jwtSettingsService.getJwtSettings().getTokenSigningKey())
.parseClaimsJws(token.getToken()); .parseClaimsJws(token.getToken());
} catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException | SignatureException ex) { } catch (UnsupportedJwtException | MalformedJwtException | IllegalArgumentException ex) {
log.debug("Invalid JWT Token", ex); log.debug("Invalid JWT Token", ex);
throw new BadCredentialsException("Invalid JWT token: ", ex); throw new BadCredentialsException("Invalid JWT token: ", ex);
} catch (ExpiredJwtException expiredEx) { } catch (SignatureException | ExpiredJwtException expiredEx) {
log.debug("JWT Token is expired", expiredEx); log.debug("JWT Token is expired", expiredEx);
throw new JwtExpiredTokenException(token, "JWT Token expired", expiredEx); throw new JwtExpiredTokenException(token, "JWT Token expired", expiredEx);
} }

Loading…
Cancel
Save