Browse Source

Send user password as payload field rather than url parameter.

pull/442/head
Igor Kulikov 9 years ago
parent
commit
bfec91567f
  1. 21
      application/src/main/java/org/thingsboard/server/controller/AuthController.java
  2. 5
      application/src/test/java/org/thingsboard/server/controller/AbstractControllerTest.java
  3. 21
      application/src/test/java/org/thingsboard/server/controller/BaseUserControllerTest.java
  4. 16
      ui/src/app/api/login.service.js

21
application/src/main/java/org/thingsboard/server/controller/AuthController.java

@ -19,8 +19,6 @@ import com.fasterxml.jackson.databind.JsonNode;
import com.fasterxml.jackson.databind.ObjectMapper; import com.fasterxml.jackson.databind.ObjectMapper;
import com.fasterxml.jackson.databind.node.ObjectNode; import com.fasterxml.jackson.databind.node.ObjectNode;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpHeaders; import org.springframework.http.HttpHeaders;
import org.springframework.http.HttpStatus; import org.springframework.http.HttpStatus;
@ -30,7 +28,6 @@ import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.web.bind.annotation.*; import org.springframework.web.bind.annotation.*;
import org.thingsboard.server.common.data.User; import org.thingsboard.server.common.data.User;
import org.thingsboard.server.common.data.security.UserCredentials; import org.thingsboard.server.common.data.security.UserCredentials;
import org.thingsboard.server.dao.user.UserService;
import org.thingsboard.server.exception.ThingsboardErrorCode; import org.thingsboard.server.exception.ThingsboardErrorCode;
import org.thingsboard.server.exception.ThingsboardException; import org.thingsboard.server.exception.ThingsboardException;
import org.thingsboard.server.service.mail.MailService; import org.thingsboard.server.service.mail.MailService;
@ -78,9 +75,10 @@ public class AuthController extends BaseController {
@RequestMapping(value = "/auth/changePassword", method = RequestMethod.POST) @RequestMapping(value = "/auth/changePassword", method = RequestMethod.POST)
@ResponseStatus(value = HttpStatus.OK) @ResponseStatus(value = HttpStatus.OK)
public void changePassword ( public void changePassword (
@RequestParam(value = "currentPassword") String currentPassword, @RequestBody JsonNode changePasswordRequest) throws ThingsboardException {
@RequestParam(value = "newPassword") String newPassword) throws ThingsboardException {
try { try {
String currentPassword = changePasswordRequest.get("currentPassword").asText();
String newPassword = changePasswordRequest.get("newPassword").asText();
SecurityUser securityUser = getCurrentUser(); SecurityUser securityUser = getCurrentUser();
UserCredentials userCredentials = userService.findUserCredentialsByUserId(securityUser.getId()); UserCredentials userCredentials = userService.findUserCredentialsByUserId(securityUser.getId());
if (!passwordEncoder.matches(currentPassword, userCredentials.getPassword())) { if (!passwordEncoder.matches(currentPassword, userCredentials.getPassword())) {
@ -118,9 +116,10 @@ public class AuthController extends BaseController {
@RequestMapping(value = "/noauth/resetPasswordByEmail", method = RequestMethod.POST) @RequestMapping(value = "/noauth/resetPasswordByEmail", method = RequestMethod.POST)
@ResponseStatus(value = HttpStatus.OK) @ResponseStatus(value = HttpStatus.OK)
public void requestResetPasswordByEmail ( public void requestResetPasswordByEmail (
@RequestParam(value = "email") String email, @RequestBody JsonNode resetPasswordByEmailRequest,
HttpServletRequest request) throws ThingsboardException { HttpServletRequest request) throws ThingsboardException {
try { try {
String email = resetPasswordByEmailRequest.get("email").asText();
UserCredentials userCredentials = userService.requestPasswordReset(email); UserCredentials userCredentials = userService.requestPasswordReset(email);
String baseUrl = constructBaseUrl(request); String baseUrl = constructBaseUrl(request);
String resetUrl = String.format("%s/api/noauth/resetPassword?resetToken=%s", baseUrl, String resetUrl = String.format("%s/api/noauth/resetPassword?resetToken=%s", baseUrl,
@ -158,10 +157,11 @@ public class AuthController extends BaseController {
@ResponseStatus(value = HttpStatus.OK) @ResponseStatus(value = HttpStatus.OK)
@ResponseBody @ResponseBody
public JsonNode activateUser( public JsonNode activateUser(
@RequestParam(value = "activateToken") String activateToken, @RequestBody JsonNode activateRequest,
@RequestParam(value = "password") String password,
HttpServletRequest request) throws ThingsboardException { HttpServletRequest request) throws ThingsboardException {
try { try {
String activateToken = activateRequest.get("activateToken").asText();
String password = activateRequest.get("password").asText();
String encodedPassword = passwordEncoder.encode(password); String encodedPassword = passwordEncoder.encode(password);
UserCredentials credentials = userService.activateUserCredentials(activateToken, encodedPassword); UserCredentials credentials = userService.activateUserCredentials(activateToken, encodedPassword);
User user = userService.findUserById(credentials.getUserId()); User user = userService.findUserById(credentials.getUserId());
@ -194,10 +194,11 @@ public class AuthController extends BaseController {
@ResponseStatus(value = HttpStatus.OK) @ResponseStatus(value = HttpStatus.OK)
@ResponseBody @ResponseBody
public JsonNode resetPassword( public JsonNode resetPassword(
@RequestParam(value = "resetToken") String resetToken, @RequestBody JsonNode resetPasswordRequest,
@RequestParam(value = "password") String password,
HttpServletRequest request) throws ThingsboardException { HttpServletRequest request) throws ThingsboardException {
try { try {
String resetToken = resetPasswordRequest.get("resetToken").asText();
String password = resetPasswordRequest.get("password").asText();
UserCredentials userCredentials = userService.findUserCredentialsByResetToken(resetToken); UserCredentials userCredentials = userService.findUserCredentialsByResetToken(resetToken);
if (userCredentials != null) { if (userCredentials != null) {
String encodedPassword = passwordEncoder.encode(password); String encodedPassword = passwordEncoder.encode(password);

5
application/src/test/java/org/thingsboard/server/controller/AbstractControllerTest.java

@ -221,7 +221,10 @@ public abstract class AbstractControllerTest {
doGet("/api/noauth/activate?activateToken={activateToken}", TestMailService.currentActivateToken) doGet("/api/noauth/activate?activateToken={activateToken}", TestMailService.currentActivateToken)
.andExpect(status().isSeeOther()) .andExpect(status().isSeeOther())
.andExpect(header().string(HttpHeaders.LOCATION, "/login/createPassword?activateToken=" + TestMailService.currentActivateToken)); .andExpect(header().string(HttpHeaders.LOCATION, "/login/createPassword?activateToken=" + TestMailService.currentActivateToken));
JsonNode tokenInfo = readResponse(doPost("/api/noauth/activate", "activateToken", TestMailService.currentActivateToken, "password", password).andExpect(status().isOk()), JsonNode.class); JsonNode activateRequest = new ObjectMapper().createObjectNode()
.put("activateToken", TestMailService.currentActivateToken)
.put("password", password);
JsonNode tokenInfo = readResponse(doPost("/api/noauth/activate", activateRequest).andExpect(status().isOk()), JsonNode.class);
validateAndSetJwtToken(tokenInfo, user.getEmail()); validateAndSetJwtToken(tokenInfo, user.getEmail());
return savedUser; return savedUser;
} }

21
application/src/test/java/org/thingsboard/server/controller/BaseUserControllerTest.java

@ -17,6 +17,7 @@ package org.thingsboard.server.controller;
import com.fasterxml.jackson.core.type.TypeReference; import com.fasterxml.jackson.core.type.TypeReference;
import com.fasterxml.jackson.databind.JsonNode; import com.fasterxml.jackson.databind.JsonNode;
import com.fasterxml.jackson.databind.ObjectMapper;
import org.apache.commons.lang3.RandomStringUtils; import org.apache.commons.lang3.RandomStringUtils;
import org.junit.Assert; import org.junit.Assert;
import org.junit.Test; import org.junit.Test;
@ -73,7 +74,11 @@ public abstract class BaseUserControllerTest extends AbstractControllerTest {
.andExpect(status().isSeeOther()) .andExpect(status().isSeeOther())
.andExpect(header().string(HttpHeaders.LOCATION, "/login/createPassword?activateToken=" + TestMailService.currentActivateToken)); .andExpect(header().string(HttpHeaders.LOCATION, "/login/createPassword?activateToken=" + TestMailService.currentActivateToken));
JsonNode tokenInfo = readResponse(doPost("/api/noauth/activate", "activateToken", TestMailService.currentActivateToken, "password", "testPassword").andExpect(status().isOk()), JsonNode.class); JsonNode activateRequest = new ObjectMapper().createObjectNode()
.put("activateToken", TestMailService.currentActivateToken)
.put("password", "testPassword");
JsonNode tokenInfo = readResponse(doPost("/api/noauth/activate", activateRequest).andExpect(status().isOk()), JsonNode.class);
validateAndSetJwtToken(tokenInfo, email); validateAndSetJwtToken(tokenInfo, email);
doGet("/api/auth/user") doGet("/api/auth/user")
@ -117,13 +122,21 @@ public abstract class BaseUserControllerTest extends AbstractControllerTest {
User savedUser = createUserAndLogin(user, "testPassword1"); User savedUser = createUserAndLogin(user, "testPassword1");
logout(); logout();
doPost("/api/noauth/resetPasswordByEmail", "email", email)
JsonNode resetPasswordByEmailRequest = new ObjectMapper().createObjectNode()
.put("email", email);
doPost("/api/noauth/resetPasswordByEmail", resetPasswordByEmailRequest)
.andExpect(status().isOk()); .andExpect(status().isOk());
doGet("/api/noauth/resetPassword?resetToken={resetToken}", TestMailService.currentResetPasswordToken) doGet("/api/noauth/resetPassword?resetToken={resetToken}", TestMailService.currentResetPasswordToken)
.andExpect(status().isSeeOther()) .andExpect(status().isSeeOther())
.andExpect(header().string(HttpHeaders.LOCATION, "/login/resetPassword?resetToken=" + TestMailService.currentResetPasswordToken)); .andExpect(header().string(HttpHeaders.LOCATION, "/login/resetPassword?resetToken=" + TestMailService.currentResetPasswordToken));
JsonNode tokenInfo = readResponse(doPost("/api/noauth/resetPassword", "resetToken", TestMailService.currentResetPasswordToken, "password", "testPassword2").andExpect(status().isOk()), JsonNode.class); JsonNode resetPasswordRequest = new ObjectMapper().createObjectNode()
.put("resetToken", TestMailService.currentResetPasswordToken)
.put("password", "testPassword2");
JsonNode tokenInfo = readResponse(doPost("/api/noauth/resetPassword", resetPasswordRequest).andExpect(status().isOk()), JsonNode.class);
validateAndSetJwtToken(tokenInfo, email); validateAndSetJwtToken(tokenInfo, email);
doGet("/api/auth/user") doGet("/api/auth/user")

16
ui/src/app/api/login.service.js

@ -65,8 +65,8 @@ function LoginService($http, $q) {
function sendResetPasswordLink(email) { function sendResetPasswordLink(email) {
var deferred = $q.defer(); var deferred = $q.defer();
var url = '/api/noauth/resetPasswordByEmail?email=' + email; var url = '/api/noauth/resetPasswordByEmail';
$http.post(url, null).then(function success(response) { $http.post(url, {email: email}).then(function success(response) {
deferred.resolve(response); deferred.resolve(response);
}, function fail() { }, function fail() {
deferred.reject(); deferred.reject();
@ -76,8 +76,8 @@ function LoginService($http, $q) {
function resetPassword(resetToken, password) { function resetPassword(resetToken, password) {
var deferred = $q.defer(); var deferred = $q.defer();
var url = '/api/noauth/resetPassword?resetToken=' + resetToken + '&password=' + password; var url = '/api/noauth/resetPassword';
$http.post(url, null).then(function success(response) { $http.post(url, {resetToken: resetToken, password: password}).then(function success(response) {
deferred.resolve(response); deferred.resolve(response);
}, function fail() { }, function fail() {
deferred.reject(); deferred.reject();
@ -87,8 +87,8 @@ function LoginService($http, $q) {
function activate(activateToken, password) { function activate(activateToken, password) {
var deferred = $q.defer(); var deferred = $q.defer();
var url = '/api/noauth/activate?activateToken=' + activateToken + '&password=' + password; var url = '/api/noauth/activate';
$http.post(url, null).then(function success(response) { $http.post(url, {activateToken: activateToken, password: password}).then(function success(response) {
deferred.resolve(response); deferred.resolve(response);
}, function fail() { }, function fail() {
deferred.reject(); deferred.reject();
@ -98,8 +98,8 @@ function LoginService($http, $q) {
function changePassword(currentPassword, newPassword) { function changePassword(currentPassword, newPassword) {
var deferred = $q.defer(); var deferred = $q.defer();
var url = '/api/auth/changePassword?currentPassword=' + currentPassword + '&newPassword=' + newPassword; var url = '/api/auth/changePassword';
$http.post(url, null).then(function success(response) { $http.post(url, {currentPassword: currentPassword, newPassword: newPassword}).then(function success(response) {
deferred.resolve(response); deferred.resolve(response);
}, function fail() { }, function fail() {
deferred.reject(); deferred.reject();

Loading…
Cancel
Save