From efdcd1ce0d8afa915ecc25755a69f506bc5510e4 Mon Sep 17 00:00:00 2001 From: xiose Date: Thu, 30 Apr 2026 10:20:41 +0800 Subject: [PATCH] fix(security): handle session invalidation IllegalStateException as 401 Catches IllegalStateException with "Session was invalidated" message and returns 401 instead of letting it fall through to the generic 500 handler. Non-session IllegalStateExceptions are re-thrown to the catch-all handler. Closes #360 (part 2/2) --- .../skillhub/exception/GlobalExceptionHandler.java | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/server/skillhub-app/src/main/java/com/iflytek/skillhub/exception/GlobalExceptionHandler.java b/server/skillhub-app/src/main/java/com/iflytek/skillhub/exception/GlobalExceptionHandler.java index 851f6683..2d30bd54 100644 --- a/server/skillhub-app/src/main/java/com/iflytek/skillhub/exception/GlobalExceptionHandler.java +++ b/server/skillhub-app/src/main/java/com/iflytek/skillhub/exception/GlobalExceptionHandler.java @@ -95,6 +95,17 @@ public class GlobalExceptionHandler { apiResponseFactory.error(403, "error.forbidden")); } + @ExceptionHandler(IllegalStateException.class) + public ResponseEntity> handleSessionInvalidated( + IllegalStateException ex, HttpServletRequest request) { + if (ex.getMessage() != null && ex.getMessage().contains("Session was invalidated")) { + logHandledException(HttpStatus.UNAUTHORIZED, "error.session.expired", request); + return ResponseEntity.status(HttpStatus.UNAUTHORIZED) + .body(apiResponseFactory.error(401, "error.session.expired")); + } + throw ex; + } + @ExceptionHandler(StorageAccessException.class) public ResponseEntity> handleStorageAccess(StorageAccessException ex, HttpServletRequest request) { metrics.incrementStorageAccessFailure(ex.getOperation());