mirror of
https://github.com/iflytek/skillhub.git
synced 2026-10-10 03:27:54 +00:00
fix(security): handle session invalidation IllegalStateException as 401
Catches IllegalStateException with "Session was invalidated" message and returns 401 instead of letting it fall through to the generic 500 handler. Non-session IllegalStateExceptions are re-thrown to the catch-all handler. Closes #360 (part 2/2)
This commit is contained in:
parent
e8affab78a
commit
efdcd1ce0d
1 changed files with 11 additions and 0 deletions
|
|
@ -95,6 +95,17 @@ public class GlobalExceptionHandler {
|
|||
apiResponseFactory.error(403, "error.forbidden"));
|
||||
}
|
||||
|
||||
@ExceptionHandler(IllegalStateException.class)
|
||||
public ResponseEntity<ApiResponse<Void>> handleSessionInvalidated(
|
||||
IllegalStateException ex, HttpServletRequest request) {
|
||||
if (ex.getMessage() != null && ex.getMessage().contains("Session was invalidated")) {
|
||||
logHandledException(HttpStatus.UNAUTHORIZED, "error.session.expired", request);
|
||||
return ResponseEntity.status(HttpStatus.UNAUTHORIZED)
|
||||
.body(apiResponseFactory.error(401, "error.session.expired"));
|
||||
}
|
||||
throw ex;
|
||||
}
|
||||
|
||||
@ExceptionHandler(StorageAccessException.class)
|
||||
public ResponseEntity<ApiResponse<Void>> handleStorageAccess(StorageAccessException ex, HttpServletRequest request) {
|
||||
metrics.incrementStorageAccessFailure(ex.getOperation());
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue