Merge branch 'main' into bug6105

This commit is contained in:
Axel Uhl
2025-05-05 11:08:25 +02:00
2 changed files with 23 additions and 9 deletions
@@ -124,9 +124,9 @@ public interface ReplicableSecurityService extends SecurityService {
LockingAndBanning internalFailedPasswordAuthentication(String username);
Void internalSuccessfulPasswordAuthentication(String username);
Boolean internalSuccessfulPasswordAuthentication(String username);
Void internalSuccessfulBearerTokenAuthentication(String clientIP);
Boolean internalSuccessfulBearerTokenAuthentication(String clientIP);
LockingAndBanning internalFailedBearerTokenAuthentication(String clientIP);
@@ -1300,18 +1300,25 @@ implements ReplicableSecurityService, ClearStateTestSupport {
@Override
public void successfulPasswordAuthentication(User user) {
apply(s->s.internalSuccessfulPasswordAuthentication(user.getName()));
// replicate only if this really implied a change
if (internalSuccessfulPasswordAuthentication(user.getName())) {
replicate(s->s.internalSuccessfulPasswordAuthentication(user.getName()));
}
}
@Override
public Void internalSuccessfulPasswordAuthentication(String username) {
public Boolean internalSuccessfulPasswordAuthentication(String username) {
final boolean changed;
final User user = getUserByName(username);
if (user != null) {
if (user.getLockingAndBanning().successfulPasswordAuthentication()) {
changed = user.getLockingAndBanning().successfulPasswordAuthentication();
if (changed) {
store.updateUser(user);
}
} else {
changed = false;
}
return null;
return changed;
}
@Override
@@ -1366,16 +1373,23 @@ implements ReplicableSecurityService, ClearStateTestSupport {
@Override
public void successfulBearerTokenAuthentication(String clientIP) {
apply(s->s.internalSuccessfulBearerTokenAuthentication(clientIP));
// replicate only if this truly caused a change in locking/banning:
if (internalSuccessfulBearerTokenAuthentication(clientIP)) {
replicate(s->s.internalSuccessfulBearerTokenAuthentication(clientIP));
}
}
@Override
public Void internalSuccessfulBearerTokenAuthentication(String clientIP) {
public Boolean internalSuccessfulBearerTokenAuthentication(String clientIP) {
final boolean changed;
final LockingAndBanning lockingAndBanning = clientIPBasedLockingAndBanningForBearerTokenAuthentication.remove(escapeNullClientIP(clientIP));
if (lockingAndBanning != null) {
logger.info("Unlocked bearer token authentication from "+clientIP+"; last locking state was "+lockingAndBanning);
changed = true;
} else {
changed = false;
}
return null;
return changed;
}
@Override