Browse Source

fixed potential NPE exceptions

pull/9775/head
dashevchenko 3 years ago
parent
commit
8ba9c7d944
  1. 3
      application/src/main/java/org/thingsboard/server/exception/ThingsboardErrorResponseHandler.java
  2. 13
      application/src/main/java/org/thingsboard/server/service/security/system/DefaultSystemSecurityService.java

3
application/src/main/java/org/thingsboard/server/exception/ThingsboardErrorResponseHandler.java

@ -178,7 +178,8 @@ public class ThingsboardErrorResponseHandler extends ResponseEntityExceptionHand
private void handleAuthenticationException(AuthenticationException authenticationException, HttpServletResponse response) throws IOException { private void handleAuthenticationException(AuthenticationException authenticationException, HttpServletResponse response) throws IOException {
response.setStatus(HttpStatus.UNAUTHORIZED.value()); response.setStatus(HttpStatus.UNAUTHORIZED.value());
if (authenticationException instanceof BadCredentialsException || authenticationException instanceof UsernameNotFoundException) { if (authenticationException instanceof BadCredentialsException || authenticationException instanceof UsernameNotFoundException) {
JacksonUtil.writeValue(response.getWriter(), ThingsboardErrorResponse.of(authenticationException.getMessage().isEmpty() ? "Invalid username or password" : authenticationException.getMessage(), ThingsboardErrorCode.AUTHENTICATION, HttpStatus.UNAUTHORIZED)); String message = (authenticationException.getMessage() == null || authenticationException.getMessage().isEmpty()) ? "Invalid username or password" : authenticationException.getMessage();
JacksonUtil.writeValue(response.getWriter(), ThingsboardErrorResponse.of(message, ThingsboardErrorCode.AUTHENTICATION, HttpStatus.UNAUTHORIZED));
} else if (authenticationException instanceof DisabledException) { } else if (authenticationException instanceof DisabledException) {
JacksonUtil.writeValue(response.getWriter(), ThingsboardErrorResponse.of("User account is not active", ThingsboardErrorCode.AUTHENTICATION, HttpStatus.UNAUTHORIZED)); JacksonUtil.writeValue(response.getWriter(), ThingsboardErrorResponse.of("User account is not active", ThingsboardErrorCode.AUTHENTICATION, HttpStatus.UNAUTHORIZED));
} else if (authenticationException instanceof LockedException) { } else if (authenticationException instanceof LockedException) {

13
application/src/main/java/org/thingsboard/server/service/security/system/DefaultSystemSecurityService.java

@ -135,11 +135,11 @@ public class DefaultSystemSecurityService implements SystemSecurityService {
SecuritySettings securitySettings = self.getSecuritySettings(tenantId); SecuritySettings securitySettings = self.getSecuritySettings(tenantId);
UserPasswordPolicy passwordPolicy = securitySettings.getPasswordPolicy(); UserPasswordPolicy passwordPolicy = securitySettings.getPasswordPolicy();
if (passwordPolicy.getForceUserToResetPasswordIfNotValid()) { if (Boolean.TRUE.equals(passwordPolicy.getForceUserToResetPasswordIfNotValid())) {
try { try {
validatePasswordByPolicy(password, passwordPolicy); validatePasswordByPolicy(password, passwordPolicy);
} catch (DataValidationException e) { } catch (DataValidationException e) {
throw new BadCredentialsException("Password does not pass validation. Please try again or reset password to valid one."); throw new BadCredentialsException("The entered password violates our policies. If this is your real password, please reset it.");
} }
} }
if (!encoder.matches(password, userCredentials.getPassword())) { if (!encoder.matches(password, userCredentials.getPassword())) {
@ -150,7 +150,7 @@ public class DefaultSystemSecurityService implements SystemSecurityService {
throw new LockedException("Authentication Failed. Username was locked due to security policy."); throw new LockedException("Authentication Failed. Username was locked due to security policy.");
} }
} }
throw new BadCredentialsException("Authentication Failed. Username or Password not valid."); throw new BadCredentialsException("Invalid username or Password.");
} }
if (!userCredentials.isEnabled()) { if (!userCredentials.isEnabled()) {
@ -227,7 +227,12 @@ public class DefaultSystemSecurityService implements SystemSecurityService {
private void validatePasswordByPolicy(String password, UserPasswordPolicy passwordPolicy) { private void validatePasswordByPolicy(String password, UserPasswordPolicy passwordPolicy) {
List<Rule> passwordRules = new ArrayList<>(); List<Rule> passwordRules = new ArrayList<>();
passwordRules.add(new LengthRule(passwordPolicy.getMinimumLength(), passwordPolicy.getMaximumLength()));
Integer maximumLength = passwordPolicy.getMaximumLength();
Integer minLengthBound = passwordPolicy.getMinimumLength();
int maxLengthBound = (maximumLength != null && maximumLength > passwordPolicy.getMinimumLength()) ? maximumLength : Integer.MAX_VALUE;
passwordRules.add(new LengthRule(minLengthBound, maxLengthBound));
if (isPositiveInteger(passwordPolicy.getMinimumUppercaseLetters())) { if (isPositiveInteger(passwordPolicy.getMinimumUppercaseLetters())) {
passwordRules.add(new CharacterRule(EnglishCharacterData.UpperCase, passwordPolicy.getMinimumUppercaseLetters())); passwordRules.add(new CharacterRule(EnglishCharacterData.UpperCase, passwordPolicy.getMinimumUppercaseLetters()));
} }

Loading…
Cancel
Save