Log token refresh

This commit is contained in:
René Pfeuffer
2018-11-30 17:25:53 +01:00
parent 58268f88db
commit 80ce5af12a

View File

@@ -1,6 +1,8 @@
package sonia.scm.web.security; package sonia.scm.web.security;
import org.apache.shiro.authc.AuthenticationToken; import org.apache.shiro.authc.AuthenticationToken;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import sonia.scm.Priority; import sonia.scm.Priority;
import sonia.scm.filter.Filters; import sonia.scm.filter.Filters;
import sonia.scm.filter.WebElement; import sonia.scm.filter.WebElement;
@@ -26,6 +28,8 @@ import java.util.Set;
morePatterns = { Filters.PATTERN_DEBUG }) morePatterns = { Filters.PATTERN_DEBUG })
public class TokenRefreshFilter extends HttpFilter { public class TokenRefreshFilter extends HttpFilter {
private static final Logger LOG = LoggerFactory.getLogger(TokenRefreshFilter.class);
private final Set<WebTokenGenerator> tokenGenerators; private final Set<WebTokenGenerator> tokenGenerators;
private final AccessTokenCookieIssuer cookieIssuer; private final AccessTokenCookieIssuer cookieIssuer;
private final JwtAccessTokenRefresher refresher; private final JwtAccessTokenRefresher refresher;
@@ -48,12 +52,17 @@ public class TokenRefreshFilter extends HttpFilter {
AccessToken accessToken = resolver.resolve((BearerToken) token); AccessToken accessToken = resolver.resolve((BearerToken) token);
if (accessToken instanceof JwtAccessToken) { if (accessToken instanceof JwtAccessToken) {
refresher.refresh((JwtAccessToken) accessToken) refresher.refresh((JwtAccessToken) accessToken)
.ifPresent(jwtAccessToken -> issuer.authenticate(request, response, jwtAccessToken)); .ifPresent(jwtAccessToken -> refreshToken(request, response, jwtAccessToken));
} }
} }
chain.doFilter(request, response); chain.doFilter(request, response);
} }
private void refreshToken(HttpServletRequest request, HttpServletResponse response, JwtAccessToken jwtAccessToken) {
LOG.debug("refreshing authentication token");
issuer.authenticate(request, response, jwtAccessToken);
}
private AuthenticationToken createToken(HttpServletRequest request) { private AuthenticationToken createToken(HttpServletRequest request) {
for (WebTokenGenerator generator : tokenGenerators) { for (WebTokenGenerator generator : tokenGenerators) {
AuthenticationToken token = generator.createToken(request); AuthenticationToken token = generator.createToken(request);