diff --git a/app/common/src/main/java/stirling/software/common/model/MultipartFile.java b/app/common/src/main/java/stirling/software/common/model/MultipartFile.java index eb20c92ddf..0e1cd4966a 100644 --- a/app/common/src/main/java/stirling/software/common/model/MultipartFile.java +++ b/app/common/src/main/java/stirling/software/common/model/MultipartFile.java @@ -60,7 +60,8 @@ public interface MultipartFile { default void transferTo(Path dest) throws IOException { try (InputStream in = getInputStream()) { - // Spring's MultipartFile#transferTo overwrites an existing destination. Callers commonly + // Spring's MultipartFile#transferTo overwrites an existing destination. Callers + // commonly // pass a path from Files.createTempFile(...) (which has already created an empty file), // so REPLACE_EXISTING is required - a plain Files.copy would throw FileAlreadyExists. Files.copy(in, dest, java.nio.file.StandardCopyOption.REPLACE_EXISTING); diff --git a/app/proprietary/src/main/java/stirling/software/proprietary/security/oauth2/OAuth2CallbackServlet.java b/app/proprietary/src/main/java/stirling/software/proprietary/security/oauth2/OAuth2CallbackServlet.java index 6737cf73cd..52a04d3d43 100644 --- a/app/proprietary/src/main/java/stirling/software/proprietary/security/oauth2/OAuth2CallbackServlet.java +++ b/app/proprietary/src/main/java/stirling/software/proprietary/security/oauth2/OAuth2CallbackServlet.java @@ -111,10 +111,7 @@ public class OAuth2CallbackServlet extends HttpServlet { Map.of( "authType", AuthenticationType.OAUTH2.toString(), "role", user.getRolesAsString())); - Cookie cookie = new Cookie("stirling_jwt", jwt); - cookie.setPath("/"); - cookie.setHttpOnly(true); - response.addCookie(cookie); + response.addCookie(jwtCookie(jwt, request)); response.sendRedirect(baseUrl(request) + "/"); } catch (Exception e) { log.error("OAuth2 callback failed", e); @@ -203,6 +200,17 @@ public class OAuth2CallbackServlet extends HttpServlet { return baseUrl(request) + "/login/oauth2/code/" + REG_ID; } + private Cookie jwtCookie(String jwt, HttpServletRequest request) { + Cookie cookie = new Cookie("stirling_jwt", jwt); + cookie.setPath("/"); + cookie.setHttpOnly(true); + // Secure when the request arrived over HTTPS (production); left off for the http localhost + // test deployments so the SSO cookie round-trips there. + cookie.setSecure(request.isSecure()); + cookie.setAttribute("SameSite", "Lax"); + return cookie; + } + private String baseUrl(HttpServletRequest request) { String backendUrl = applicationProperties.getSystem().getBackendUrl(); if (backendUrl != null && !backendUrl.isBlank()) { diff --git a/app/proprietary/src/main/java/stirling/software/proprietary/security/saml2/SamlSpServlet.java b/app/proprietary/src/main/java/stirling/software/proprietary/security/saml2/SamlSpServlet.java index f10d5b81b5..3faa773691 100644 --- a/app/proprietary/src/main/java/stirling/software/proprietary/security/saml2/SamlSpServlet.java +++ b/app/proprietary/src/main/java/stirling/software/proprietary/security/saml2/SamlSpServlet.java @@ -81,10 +81,7 @@ public class SamlSpServlet extends HttpServlet { Map.of( "authType", AuthenticationType.SSO.toString(), "role", user.getRolesAsString())); - Cookie cookie = new Cookie("stirling_jwt", jwt); - cookie.setPath("/"); - cookie.setHttpOnly(true); - response.addCookie(cookie); + response.addCookie(jwtCookie(jwt, request)); response.sendRedirect(baseUrl(request) + "/"); } catch (Exception e) { log.error("SAML ACS validation failed", e); @@ -117,6 +114,17 @@ public class SamlSpServlet extends HttpServlet { } } + private Cookie jwtCookie(String jwt, HttpServletRequest request) { + Cookie cookie = new Cookie("stirling_jwt", jwt); + cookie.setPath("/"); + cookie.setHttpOnly(true); + // Secure when the request arrived over HTTPS (production); left off for the http localhost + // test deployments so the SSO cookie round-trips there. + cookie.setSecure(request.isSecure()); + cookie.setAttribute("SameSite", "Lax"); + return cookie; + } + private String baseUrl(HttpServletRequest request) { String backendUrl = applicationProperties.getSystem().getBackendUrl(); if (backendUrl != null && !backendUrl.isBlank()) {