fix(security): handle session invalidation IllegalStateException as 401

Catches IllegalStateException with "Session was invalidated" message and
returns 401 instead of letting it fall through to the generic 500 handler.
Non-session IllegalStateExceptions are re-thrown to the catch-all handler.
Closes #360 (part 2/2)
This commit is contained in:
xiose 2026-04-30 10:20:41 +08:00
parent e8affab78a
commit efdcd1ce0d

View file

@ -95,6 +95,17 @@ public class GlobalExceptionHandler {
apiResponseFactory.error(403, "error.forbidden"));
}
@ExceptionHandler(IllegalStateException.class)
public ResponseEntity<ApiResponse<Void>> handleSessionInvalidated(
IllegalStateException ex, HttpServletRequest request) {
if (ex.getMessage() != null && ex.getMessage().contains("Session was invalidated")) {
logHandledException(HttpStatus.UNAUTHORIZED, "error.session.expired", request);
return ResponseEntity.status(HttpStatus.UNAUTHORIZED)
.body(apiResponseFactory.error(401, "error.session.expired"));
}
throw ex;
}
@ExceptionHandler(StorageAccessException.class)
public ResponseEntity<ApiResponse<Void>> handleStorageAccess(StorageAccessException ex, HttpServletRequest request) {
metrics.incrementStorageAccessFailure(ex.getOperation());