mirror of
https://github.com/iflytek/skillhub.git
synced 2026-10-06 02:48:28 +00:00
fix(security): add invalidSessionStrategy to return 401 on expired session
Handles the case where Spring Security detects an invalid session cookie, returning a clean 401 JSON response instead of triggering cascading exceptions. Closes #360 (part 1/2)
This commit is contained in:
parent
a34ad49771
commit
e8affab78a
1 changed files with 7 additions and 0 deletions
|
|
@ -9,10 +9,12 @@ import com.iflytek.skillhub.auth.mock.MockAuthFilter;
|
|||
import com.iflytek.skillhub.auth.policy.RouteSecurityPolicyRegistry;
|
||||
import com.iflytek.skillhub.auth.token.ApiTokenAuthenticationFilter;
|
||||
import com.iflytek.skillhub.auth.token.ApiTokenScopeFilter;
|
||||
import jakarta.servlet.http.HttpServletResponse;
|
||||
import org.springframework.beans.factory.ObjectProvider;
|
||||
import org.springframework.context.annotation.Bean;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.MediaType;
|
||||
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
|
||||
import org.springframework.security.crypto.password.PasswordEncoder;
|
||||
import org.springframework.security.web.AuthenticationEntryPoint;
|
||||
|
|
@ -133,6 +135,11 @@ public class SecurityConfig {
|
|||
)
|
||||
.sessionManagement(session -> session
|
||||
.sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED)
|
||||
.invalidSessionStrategy((request, response) -> {
|
||||
response.setStatus(HttpServletResponse.SC_UNAUTHORIZED);
|
||||
response.setContentType(MediaType.APPLICATION_JSON_VALUE);
|
||||
response.getWriter().write("{\"code\":401,\"msg\":\"Session expired\"}");
|
||||
})
|
||||
)
|
||||
.exceptionHandling(exceptions -> exceptions
|
||||
.accessDeniedHandler(apiAccessDeniedHandler)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue