Set Secure and SameSite on SSO JWT cookie; apply spotless formatting
This commit is contained in:
@@ -60,7 +60,8 @@ public interface MultipartFile {
|
||||
|
||||
default void transferTo(Path dest) throws IOException {
|
||||
try (InputStream in = getInputStream()) {
|
||||
// Spring's MultipartFile#transferTo overwrites an existing destination. Callers commonly
|
||||
// Spring's MultipartFile#transferTo overwrites an existing destination. Callers
|
||||
// commonly
|
||||
// pass a path from Files.createTempFile(...) (which has already created an empty file),
|
||||
// so REPLACE_EXISTING is required - a plain Files.copy would throw FileAlreadyExists.
|
||||
Files.copy(in, dest, java.nio.file.StandardCopyOption.REPLACE_EXISTING);
|
||||
|
||||
+12
-4
@@ -111,10 +111,7 @@ public class OAuth2CallbackServlet extends HttpServlet {
|
||||
Map.of(
|
||||
"authType", AuthenticationType.OAUTH2.toString(),
|
||||
"role", user.getRolesAsString()));
|
||||
Cookie cookie = new Cookie("stirling_jwt", jwt);
|
||||
cookie.setPath("/");
|
||||
cookie.setHttpOnly(true);
|
||||
response.addCookie(cookie);
|
||||
response.addCookie(jwtCookie(jwt, request));
|
||||
response.sendRedirect(baseUrl(request) + "/");
|
||||
} catch (Exception e) {
|
||||
log.error("OAuth2 callback failed", e);
|
||||
@@ -203,6 +200,17 @@ public class OAuth2CallbackServlet extends HttpServlet {
|
||||
return baseUrl(request) + "/login/oauth2/code/" + REG_ID;
|
||||
}
|
||||
|
||||
private Cookie jwtCookie(String jwt, HttpServletRequest request) {
|
||||
Cookie cookie = new Cookie("stirling_jwt", jwt);
|
||||
cookie.setPath("/");
|
||||
cookie.setHttpOnly(true);
|
||||
// Secure when the request arrived over HTTPS (production); left off for the http localhost
|
||||
// test deployments so the SSO cookie round-trips there.
|
||||
cookie.setSecure(request.isSecure());
|
||||
cookie.setAttribute("SameSite", "Lax");
|
||||
return cookie;
|
||||
}
|
||||
|
||||
private String baseUrl(HttpServletRequest request) {
|
||||
String backendUrl = applicationProperties.getSystem().getBackendUrl();
|
||||
if (backendUrl != null && !backendUrl.isBlank()) {
|
||||
|
||||
+12
-4
@@ -81,10 +81,7 @@ public class SamlSpServlet extends HttpServlet {
|
||||
Map.of(
|
||||
"authType", AuthenticationType.SSO.toString(),
|
||||
"role", user.getRolesAsString()));
|
||||
Cookie cookie = new Cookie("stirling_jwt", jwt);
|
||||
cookie.setPath("/");
|
||||
cookie.setHttpOnly(true);
|
||||
response.addCookie(cookie);
|
||||
response.addCookie(jwtCookie(jwt, request));
|
||||
response.sendRedirect(baseUrl(request) + "/");
|
||||
} catch (Exception e) {
|
||||
log.error("SAML ACS validation failed", e);
|
||||
@@ -117,6 +114,17 @@ public class SamlSpServlet extends HttpServlet {
|
||||
}
|
||||
}
|
||||
|
||||
private Cookie jwtCookie(String jwt, HttpServletRequest request) {
|
||||
Cookie cookie = new Cookie("stirling_jwt", jwt);
|
||||
cookie.setPath("/");
|
||||
cookie.setHttpOnly(true);
|
||||
// Secure when the request arrived over HTTPS (production); left off for the http localhost
|
||||
// test deployments so the SSO cookie round-trips there.
|
||||
cookie.setSecure(request.isSecure());
|
||||
cookie.setAttribute("SameSite", "Lax");
|
||||
return cookie;
|
||||
}
|
||||
|
||||
private String baseUrl(HttpServletRequest request) {
|
||||
String backendUrl = applicationProperties.getSystem().getBackendUrl();
|
||||
if (backendUrl != null && !backendUrl.isBlank()) {
|
||||
|
||||
Reference in New Issue
Block a user