Set Secure and SameSite on SSO JWT cookie; apply spotless formatting

This commit is contained in:
a
2026-06-13 12:06:15 +01:00
parent 8cea88e963
commit 61feed02cb
3 changed files with 26 additions and 9 deletions
@@ -60,7 +60,8 @@ public interface MultipartFile {
default void transferTo(Path dest) throws IOException {
try (InputStream in = getInputStream()) {
// Spring's MultipartFile#transferTo overwrites an existing destination. Callers commonly
// Spring's MultipartFile#transferTo overwrites an existing destination. Callers
// commonly
// pass a path from Files.createTempFile(...) (which has already created an empty file),
// so REPLACE_EXISTING is required - a plain Files.copy would throw FileAlreadyExists.
Files.copy(in, dest, java.nio.file.StandardCopyOption.REPLACE_EXISTING);
@@ -111,10 +111,7 @@ public class OAuth2CallbackServlet extends HttpServlet {
Map.of(
"authType", AuthenticationType.OAUTH2.toString(),
"role", user.getRolesAsString()));
Cookie cookie = new Cookie("stirling_jwt", jwt);
cookie.setPath("/");
cookie.setHttpOnly(true);
response.addCookie(cookie);
response.addCookie(jwtCookie(jwt, request));
response.sendRedirect(baseUrl(request) + "/");
} catch (Exception e) {
log.error("OAuth2 callback failed", e);
@@ -203,6 +200,17 @@ public class OAuth2CallbackServlet extends HttpServlet {
return baseUrl(request) + "/login/oauth2/code/" + REG_ID;
}
private Cookie jwtCookie(String jwt, HttpServletRequest request) {
Cookie cookie = new Cookie("stirling_jwt", jwt);
cookie.setPath("/");
cookie.setHttpOnly(true);
// Secure when the request arrived over HTTPS (production); left off for the http localhost
// test deployments so the SSO cookie round-trips there.
cookie.setSecure(request.isSecure());
cookie.setAttribute("SameSite", "Lax");
return cookie;
}
private String baseUrl(HttpServletRequest request) {
String backendUrl = applicationProperties.getSystem().getBackendUrl();
if (backendUrl != null && !backendUrl.isBlank()) {
@@ -81,10 +81,7 @@ public class SamlSpServlet extends HttpServlet {
Map.of(
"authType", AuthenticationType.SSO.toString(),
"role", user.getRolesAsString()));
Cookie cookie = new Cookie("stirling_jwt", jwt);
cookie.setPath("/");
cookie.setHttpOnly(true);
response.addCookie(cookie);
response.addCookie(jwtCookie(jwt, request));
response.sendRedirect(baseUrl(request) + "/");
} catch (Exception e) {
log.error("SAML ACS validation failed", e);
@@ -117,6 +114,17 @@ public class SamlSpServlet extends HttpServlet {
}
}
private Cookie jwtCookie(String jwt, HttpServletRequest request) {
Cookie cookie = new Cookie("stirling_jwt", jwt);
cookie.setPath("/");
cookie.setHttpOnly(true);
// Secure when the request arrived over HTTPS (production); left off for the http localhost
// test deployments so the SSO cookie round-trips there.
cookie.setSecure(request.isSecure());
cookie.setAttribute("SameSite", "Lax");
return cookie;
}
private String baseUrl(HttpServletRequest request) {
String backendUrl = applicationProperties.getSystem().getBackendUrl();
if (backendUrl != null && !backendUrl.isBlank()) {