Repository navigation
fix: ensure jwt is not in deny list before further authentication #86
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,63 @@ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| package com.iemr.tm.utils; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import org.slf4j.Logger; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import org.slf4j.LoggerFactory; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import org.springframework.beans.factory.annotation.Autowired; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import org.springframework.data.redis.core.RedisTemplate; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import org.springframework.stereotype.Component; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| import java.util.concurrent.TimeUnit; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| @Component | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| public class TokenDenylist { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| private final Logger logger = LoggerFactory.getLogger(this.getClass().getName()); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| private static final String PREFIX = "denied_"; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| @Autowired | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| private RedisTemplate<String, Object> redisTemplate; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| private String getKey(String jti) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| return PREFIX + jti; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| // Add a token's jti to the denylist with expiration time | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| public void addTokenToDenylist(String jti, Long expirationTime) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if (jti == null || jti.trim().isEmpty()) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| return; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if (expirationTime == null || expirationTime <= 0) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| throw new IllegalArgumentException("Expiration time must be positive"); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| try { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| String key = getKey(jti); // Use helper method to get the key | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| redisTemplate.opsForValue().set(key, " ", expirationTime, TimeUnit.MILLISECONDS); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } catch (Exception e) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| throw new RuntimeException("Failed to denylist token", e); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+25
to
+39
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π οΈ Refactor suggestion Improve exception handling consistency. The method has good input validation but lacks error logging consistency compared to other methods in the class. Apply this diff to add consistent error logging: } catch (Exception e) {
+ logger.error("Failed to add token to denylist for jti: " + jti, e);
throw new RuntimeException("Failed to denylist token", e);
}π Committable suggestion
Suggested change
π€ Prompt for AI Agents |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| // Check if a token's jti is in the denylist | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| public boolean isTokenDenylisted(String jti) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if (jti == null || jti.trim().isEmpty()) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| return false; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| try { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| String key = getKey(jti); // Use helper method to get the key | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| return Boolean.TRUE.equals(redisTemplate.hasKey(key)); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } catch (Exception e) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| logger.error("Failed to check denylist status for jti: " + jti, e); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| // In case of Redis failure, consider the token as not denylisted to avoid blocking all requests | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| return false; | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| // Remove a token's jti from the denylist (Redis) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| public void removeTokenFromDenylist(String jti) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| if (jti != null && !jti.trim().isEmpty()) { | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| String key = getKey(jti); // Use helper method to get the key | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| redisTemplate.delete(key); | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. π οΈ Refactor suggestion Add exception handling for consistency. The remove method lacks exception handling unlike other Redis operations in this class. Apply this diff to add consistent exception handling: public void removeTokenFromDenylist(String jti) {
if (jti != null && !jti.trim().isEmpty()) {
- String key = getKey(jti); // Use helper method to get the key
- redisTemplate.delete(key);
+ try {
+ String key = getKey(jti); // Use helper method to get the key
+ redisTemplate.delete(key);
+ } catch (Exception e) {
+ logger.error("Failed to remove token from denylist for jti: " + jti, e);
+ // Don't throw exception to avoid breaking logout/token cleanup flows
+ }
}
}π Committable suggestion
Suggested change
π€ Prompt for AI Agents |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Uh oh!
There was an error while loading. Please reload this page.