diff --git a/server/skillhub-auth/src/main/java/com/iflytek/skillhub/auth/local/LocalAuthService.java b/server/skillhub-auth/src/main/java/com/iflytek/skillhub/auth/local/LocalAuthService.java index 49743328..b64a3028 100644 --- a/server/skillhub-auth/src/main/java/com/iflytek/skillhub/auth/local/LocalAuthService.java +++ b/server/skillhub-auth/src/main/java/com/iflytek/skillhub/auth/local/LocalAuthService.java @@ -132,7 +132,7 @@ public class LocalAuthService { ensureNotLocked(credential); if (!passwordEncoder.matches(password, credential.getPasswordHash())) { - localAuthFailedService.handleFailedLogin(credential); + localAuthFailedService.handleFailedLogin(credential.getId()); throw invalidCredentials(); } diff --git a/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java b/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java index d1ef144f..896b0758 100644 --- a/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java +++ b/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java @@ -122,21 +122,12 @@ class LocalAuthServiceTest { given(userAccountRepository.findById("usr_1")).willReturn(Optional.of(user)); given(passwordEncoder.matches("bad", "encoded")).willReturn(false); - // Mock handleFailedLogin to increment failedAttempts - doAnswer(invocation -> { - LocalCredential cred = invocation.getArgument(0); - cred.setFailedAttempts(cred.getFailedAttempts() + 1); - credentialRepository.save(cred); - return null; - }).when(localAuthFailedService).handleFailedLogin(any(LocalCredential.class)); - assertThatThrownBy(() -> service.login("alice", "bad")) .isInstanceOf(AuthFlowException.class) .extracting("status") .isEqualTo(HttpStatus.UNAUTHORIZED); - assertThat(credential.getFailedAttempts()).isEqualTo(1); - verify(credentialRepository).save(credential); + verify(localAuthFailedService).handleFailedLogin(credential.getId()); } @Test @@ -149,23 +140,12 @@ class LocalAuthServiceTest { given(userAccountRepository.findById("usr_1")).willReturn(Optional.of(user)); given(passwordEncoder.matches("bad", "encoded")).willReturn(false); - // Mock handleFailedLogin to set lockedUntil using CLOCK - doAnswer(invocation -> { - LocalCredential cred = invocation.getArgument(0); - cred.setFailedAttempts(cred.getFailedAttempts() + 1); - cred.setLockedUntil(Instant.now(CLOCK).plus(java.time.Duration.ofMinutes(15))); - credentialRepository.save(cred); - return null; - }).when(localAuthFailedService).handleFailedLogin(any(LocalCredential.class)); - assertThatThrownBy(() -> service.login("alice", "bad")) .isInstanceOf(AuthFlowException.class) .extracting("status") .isEqualTo(HttpStatus.UNAUTHORIZED); - assertThat(credential.getFailedAttempts()).isEqualTo(5); - assertThat(credential.getLockedUntil()).isEqualTo(Instant.now(CLOCK).plusSeconds(15 * 60)); - verify(credentialRepository).save(credential); + verify(localAuthFailedService).handleFailedLogin(credential.getId()); } @Test