Skip to content

Commit 9ef6ef9

Browse files
fix(slave-controller): add brute force protection and avoid saving token on debug log
Signed-off-by: Cristian Scheid <cristianscheid@gmail.com> fix(slave-controller): add brute force protection and avoid saving token on debug log Signed-off-by: Cristian Scheid <cristianscheid@gmail.com>
1 parent fa37aa2 commit 9ef6ef9

1 file changed

Lines changed: 19 additions & 14 deletions

File tree

‎lib/Controller/SlaveController.php‎

Lines changed: 19 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -121,11 +121,9 @@ public function __construct($appName,
121121
* @PublicPage
122122
* @NoCSRFRequired
123123
* @UseSession
124-
*
125-
* @param string $jwt
126-
* @return RedirectResponse
124+
* @BruteForceProtection(action=autoLogin)
127125
*/
128-
public function autoLogin($jwt) {
126+
public function autoLogin(string $jwt): RedirectResponse {
129127

130128
$masterUrl = $this->gss->getMasterUrl();
131129

@@ -134,7 +132,9 @@ public function autoLogin($jwt) {
134132
}
135133

136134
if ($jwt === '') {
137-
return new RedirectResponse($masterUrl);
135+
$response = new RedirectResponse($masterUrl);
136+
$response->throttle();
137+
return $response;
138138
}
139139

140140
try {
@@ -166,10 +166,14 @@ public function autoLogin($jwt) {
166166

167167
} catch (ExpiredException $e) {
168168
$this->logger->info('token expired', ['app' => 'globalsiteselector']);
169-
return new RedirectResponse($masterUrl);
169+
$response = new RedirectResponse($masterUrl);
170+
$response->throttle();
171+
return $response;
170172
} catch (\Exception $e) {
171173
$this->logger->logException($e, ['app' => 'globalsiteselector']);
172-
return new RedirectResponse($masterUrl);
174+
$response = new RedirectResponse($masterUrl);
175+
$response->throttle();
176+
return $response;
173177
}
174178

175179
$this->userSession->createSessionToken($this->request, $uid, $uid, null, IToken::REMEMBER);
@@ -179,17 +183,16 @@ public function autoLogin($jwt) {
179183
}
180184

181185
/**
182-
* Create app token
183-
*
184186
* @PublicPage
185187
* @NoAdminRequired
186-
*
187-
* @return DataResponse
188+
* @BruteForceProtection(action=createAppToken)
188189
*/
189-
public function createAppToken($jwt) {
190+
public function createAppToken($jwt): DataResponse {
190191

191192
if($this->gss->getMode() === 'master' || empty($jwt)) {
192-
return new DataResponse([], Http::STATUS_BAD_REQUEST);
193+
$response = new DataResponse([], Http::STATUS_BAD_REQUEST);
194+
$response->throttle();
195+
return $response;
193196
}
194197

195198
try {
@@ -217,7 +220,9 @@ public function createAppToken($jwt) {
217220
$this->logger->logException('Create app password: ' . $e, ['app' => 'globalsiteselector']);
218221
}
219222

220-
return new DataResponse([], Http::STATUS_BAD_REQUEST);
223+
$response = new DataResponse([], Http::STATUS_BAD_REQUEST);
224+
$response->throttle();
225+
return $response;
221226

222227
}
223228

0 commit comments

Comments
 (0)