diff --git a/AGENTS.md b/AGENTS.md index b27fdf1..66c97b8 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -4,11 +4,12 @@ - 默认中文维护项目文档、commit、issue 和 PR;代码与上游 API 名称保留英文。 - 项目使用 Java 与 Spring;Native 是交付约束,不是可选优化,不引入 Kotlin。 - 日常变更先通过适用的 JVM 测试,不要求每轮执行耗时的 Native 编译与测试;Native 仍为交付目标,在阶段性验收或兼容性风险变化时集中验证。未执行的验证明确报告。 -- 按 DDD 组织 authentication 上下文:领域拥有 User/UserRepository 与认证事务规则,应用层编排,基础设施实现 AD 仓储,Web 仅处理传输与会话;领域和应用层不依赖 Spring/Servlet/LDAP。 +- 按 DDD 组织 authentication 上下文:领域拥有 User/UserRepository,应用层编排目录认证与读取,基础设施实现 AD 仓储与 Security Provider,Web 仅渲染页面;领域和应用层不依赖 Spring/Servlet/LDAP。 - 用户仓储复用本次用户 bind 的连接,不新增只读服务账号;连接限于当前用例,不保留密码或连接在 HTTP session 中。 - 选型演示在真实接入后删除,不将演示入口、状态机、验证码或开关保留为应用功能。 - 只实现当前任务范围。Hydra 负责签发,首轮 AD 负责身份和组,本服务独立于 Ayatori。 -- 不把 LDAP 密码成功当成完整 MFA 成功;所有因素绑定同一主体与认证事务。 +- React 只替换 Spring Security 默认登录 UI;表单认证、SecurityContext、因素状态、会话轮换与退出交给框架,不自建登录状态机。 +- LDAP 密码成功可以建立仅含密码因素的 SecurityContext,但不等于完整 MFA 或 Hydra 授权;受保护操作必须检查所需因素。 - 不提交凭据、MFA secret、生产配置秘密或包含上述内容的测试输出。 - 生产部署配置属于 homelab-infra;本仓库初始化不授权切换现役登录入口。 - 文档区分计划、实现、Native 实测和人类验收,禁止将代码存在当成部署证据。 diff --git a/README.md b/README.md index cb074d6..a278a2c 100644 --- a/README.md +++ b/README.md @@ -75,27 +75,30 @@ JVM、AOT、Native 测试及原生应用 HTTP 检查已通过,实测范围与 当前限界上下文为 `authentication`,使用 DDD 分层,依赖向领域内部收敛: ```text -interfaces/web → application → domain +interfaces/web → infrastructure/security(principal)+ domain +infrastructure/security → application → domain infrastructure/ad → application/port + domain configuration → 装配上述实现 ``` -- `authentication/domain`:`User`、`UserRepository`、`LoginTransaction`;稳定主体、组成员关系、 - 登录步骤与期限属于领域模型,不依赖 Spring、Servlet、LDAP 或持久化注解。 -- `authentication/application`:登录用例,编排密码认证、用户仓储查询与事务推进; +- `authentication/domain`:`User`、`UserRepository`;稳定主体与组成员关系属于领域模型,不依赖 Spring、Servlet、LDAP 或持久化注解。 +- `authentication/application`:`VerifyPassword` 用例,编排密码认证与同连接用户仓储查询; `port` 描述密码认证及其用户仓储会话,不暴露 `DirContext`。 - `authentication/infrastructure/ad`:AD bind、Spring Data LDAP 用户仓储、LDAP 实体与领域映射。 使用同一次用户 bind 的连接,查询结束关闭,不新增服务账号,不保存用户密码。 -- `authentication/interfaces/web`:HTTP、CSRF、会话存取和页面数据转换;不定义认证状态规则。 +- `authentication/infrastructure/security`:Provider 将目录用户转换为仅含密码因素的认证结果。 +- `authentication/interfaces/web`:登录页面与上下文转换;不处理密码 POST、认证会话或退出。 - `configuration`:Spring 组件装配、安全链、静态资源和 Native hints。 - `frontend/src`:入口、页面、表单组件和页面数据契约分别维护,只包含真实登录流程。 -测试分别覆盖领域规则、应用用例、AD 仓储和 Web 行为,LDAP 夹具集中在测试 `support` 包。 +测试覆盖应用用例、AD 仓储和完整 Spring Security 过滤器链,LDAP 夹具集中在测试 `support` 包。 界面采用 React + Vite,Spring 在 HTML 中内联当前步骤上下文,浏览器原生表单 POST, -由服务端决定下一页。不增加前端路由器、模板引擎或 Node 运行服务。 +表单由 Spring Security `formLogin` 处理,框架维护因素、SecurityContext、会话轮换和退出。 +React 只替换默认登录 UI,不增加前端路由器、模板引擎或 Node 运行服务。 ## AD 第一因素接入 真实入口为 `/signin`,默认关闭且要求 HTTPS。密码验证通过后显示 AD 身份与直接所属组, -停在等待 MFA 状态,不建立完整登录身份或接受 Hydra challenge。 +保存仅含 `FACTOR_PASSWORD` 的认证结果,停在等待 MFA 状态。待 MFA 页要求十分钟内的密码因素; +其他应用入口暂时全部拒绝,不能凭密码因素接受 Hydra challenge。监控 Basic 认证使用独立无状态安全链。 配置、组语义、HTTPS 与验收边界见 [AD 接入](docs/ad-login.md)。 diff --git a/docs/ad-login.md b/docs/ad-login.md index 37771f9..21e1327 100644 --- a/docs/ad-login.md +++ b/docs/ad-login.md @@ -4,14 +4,15 @@ 随后由 Spring Data LDAP 仓储复用这条已认证连接查询用户与组。 不使用额外目录服务账号,不写入 AD,不复制 Authelia 的绑定密码。 -领域仓储接口为 `UserRepository`,`User` 与 `LoginTransaction` 为领域模型。应用层以 +领域仓储接口为 `UserRepository`,`User` 为领域模型。`VerifyPassword` 应用用例以 try-with-resources 管理已认证用户仓储会话;基础设施的 `AdUserRepository` 通过 `SimpleLdapRepository`、`LdapTemplate`、ODM 实现读取与转换,关闭后不可继续查询。 `AdUserEntry` 的 LDAP 注解不会进入领域对象。 成功后重定向到 `/signin/mfa`,显示目录账号、objectGUID、邮箱、直接所属组及组 DN。 -**这是密码因素验收页面,MFA 尚未接入,不是完整登录成功。** 不创建 Spring Security -认证上下文,不调用 Hydra,不替换现役 Go/Authelia/Gitea 登录链路。 +**这是密码因素验收页面,MFA 尚未接入,不是完整登录成功。** Spring Security 保存 +仅含 `FACTOR_PASSWORD` 的认证结果;其余应用请求使用 `denyAll`,不调用 Hydra, +不替换现役 Go/Authelia/Gitea 登录链路。 ## 目录和组语义 @@ -82,13 +83,20 @@ AD 根范围查询可能返回 DomainDnsZones/ForestDnsZones 等分区 referral ## 状态与操作 -原生表单 POST 带 Spring CSRF token;服务端决定下一页。密码成功后轮换 session ID, -只保存目录身份快照和十分钟期限,不保存密码;重启或“退出并重新验证”清除事务。 -页面禁止缓存,内联 JSON 转义 HTML 结束标记。失败页面不披露目录内部异常。 +React 只渲染登录页面与待 MFA 页面,原生表单 POST 由 Spring Security `formLogin` +接收。`DirectoryAuthenticationProvider` 调用目录用例并返回不含密码的 principal 和 +带签发时间的 `FACTOR_PASSWORD`;目录组只保留在身份快照中,不映射为本服务权限。 +框架负责 CSRF、成功/失败跳转、SecurityContext 持久化、session ID 轮换以及 POST logout。 +`/signin/restart` 是框架 logout 地址;不再维护 LoginTransaction 或另一份浏览器认证状态。 -当前每个 session 只保留一份事务,多标签页会共享状态。两秒提交间隔仅用于同事务的 -重复提交,不是账号/IP 限流;此 PoC 仅供受控 LAN/Tailscale 验收,生产发布前仍需完善 -入口限流、审计、MFA、Hydra 事务和恢复策略。 +待 MFA 页通过框架的 `validDuration` 要求密码因素在十分钟内完成,过期后需要重新认证。 +这不是完整登录会话的过期策略。MFA 与 Hydra 尚未实现,其余应用入口当前拒绝所有访问。 +`/actuator/**` 使用独立无状态 Basic 安全链,人类密码因素不能用于读取监控端点, +监控账号也不能借 Basic 进入人类登录流程。 + +移除原来事务内的两秒提交间隔;它不是有效的账号/IP 限流。此 PoC 仍仅供受控 +LAN/Tailscale 验收,生产发布前需完善入口限流、审计、MFA、Hydra challenge 和恢复策略。 +页面禁止缓存,内联 JSON 转义 HTML 结束标记。错误页面只显示统一消息。 基础存活检查使用 `/actuator/health/liveness`。Boot 自动配置的 LDAP 健康项并未连接这里 按用户 bind 创建的仓储连接,不能把该项当作此认证路径的可用性验证。 @@ -96,18 +104,18 @@ AD 根范围查询可能返回 DomainDnsZones/ForestDnsZones 等分区 referral ## 本轮验证边界 隔离测试使用真实 TLS、LDAP bind 和搜索,校验正确/错误密码、未知账号、AD 账号状态 -子码、GUID 字节序、组名、错误 TLS 主机名、CSRF、HTTPS、会话轮换、超时和密码成功后 -仍未完整认证。UnboundID 的 UPN bind 与 AD 子码由测试拦截器模拟,不能替代 Samba AD。 +子码、GUID 字节序、组名、错误 TLS 主机名、CSRF、HTTPS、会话轮换、因素过期和密码成功后 +仍不能访问受保护应用入口。UnboundID 的 UPN bind 与 AD 子码由测试拦截器模拟,不能替代 Samba AD。 测试证书、私钥与账号全为虚构夹具,不用于实际部署。 -2026-09-25:DDD/Spring Data LDAP 版本通过 20 项 JVM 测试和 `bootJar` 构建, -包含同一次 bind 连接完成仓储查询、用例结束关闭连接、领域规则及监控集成。 -开发 HTTPS 实例已更新为该版本。此前 JVM 使用受信 CA 完成 Samba AD RootDSE 查询。 +2026-09-27:Spring Security 重构通过 18 项 JVM 测试和 `bootJar` 构建,覆盖 +密码因素的保存与有效期、会话轮换、退出、未完成 MFA 的访问限制,以及监控安全链隔离。 +此前 JVM 使用受信 CA 完成 Samba AD RootDSE 查询。 浏览器已检查登录表单渲染、真实 CSRF 原生 POST 和失败后清空密码;只使用在访问 AD 前 即拒绝的合成外域用户名,不尝试猜测人类密码。浏览器回归共 1 项通过,包含移动端布局。 复现:`IAM_AD_URL=https://验收域名:端口 npm --prefix frontend run test:browser -- ad-login.spec.ts`。 重构前,维护者已在 HTTPS 页面完成真实密码验证,成功到达待 MFA 页面,并反馈目录标识、邮箱与 六个直接所属组的查询结果。该验收覆盖 Samba AD 第一因素与属性读取,不表示 MFA、 -嵌套组/主组等价性或 Hydra 登录已完成。Spring Data LDAP 重构后的真实人类复验仍待反馈。 +嵌套组/主组等价性或 Hydra 登录已完成。Spring Security 重构后的真实人类复验仍待反馈。 不在聊天、命令行或日志中传递人类密码。 新增 AD 路径尚未进行 Native 测试,不能复用旧 UI 原型的 Native 结论。 diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/SignInService.java b/src/main/java/top/ddupan/iam/login/authentication/application/SignInService.java deleted file mode 100644 index c3985e6..0000000 --- a/src/main/java/top/ddupan/iam/login/authentication/application/SignInService.java +++ /dev/null @@ -1,50 +0,0 @@ -package top.ddupan.iam.login.authentication.application; - -import java.time.Clock; -import java.util.UUID; -import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; -import top.ddupan.iam.login.authentication.domain.UserRepository; -import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; -import top.ddupan.iam.login.authentication.domain.LoginTransaction; - -/** Coordinates the first-factor use case. HTTP/session/LDAP details stay in adapters. */ -public final class SignInService { - public enum PasswordResult { ACCEPTED, REJECTED, EXPIRED, WRONG_STEP, RETRY_LATER } - private final PasswordAuthenticator authenticator; - private final Clock clock; - private final boolean enabled; - - public SignInService(PasswordAuthenticator authenticator, Clock clock, boolean enabled) { - this.authenticator = authenticator; - this.clock = clock; - this.enabled = enabled; - } - - public boolean enabled() { return enabled; } - public LoginTransaction start() { return LoginTransaction.start(UUID.randomUUID(), clock.instant()); } - public boolean expired(LoginTransaction transaction) { return transaction.expiredAt(clock.instant()); } - - public PasswordResult submitPassword(LoginTransaction transaction, String username, String password) { - if (!enabled) throw new IllegalStateException("Human sign-in is disabled"); - var attempt = transaction.beginPasswordAttempt(clock.instant()); - if (attempt != LoginTransaction.Attempt.ALLOWED) { - return switch (attempt) { - case EXPIRED -> PasswordResult.EXPIRED; - case WRONG_STEP -> PasswordResult.WRONG_STEP; - case RETRY_LATER -> PasswordResult.RETRY_LATER; - case ALLOWED -> throw new IllegalStateException("Unexpected attempt result"); - }; - } - try (var session = authenticator.authenticate(username, password)) { - var identity = session.users().findByLoginName(session.loginName()); - if (identity.isEmpty()) return PasswordResult.REJECTED; - // A slow directory response must not revive an expired transaction. - var verifiedAt = clock.instant(); - if (transaction.expiredAt(verifiedAt)) return PasswordResult.EXPIRED; - transaction.passwordVerified(identity.orElseThrow(), verifiedAt); - return PasswordResult.ACCEPTED; - } catch (PasswordVerificationException | UserRepository.AccessFailure ex) { - return PasswordResult.REJECTED; - } - } -} diff --git a/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java b/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java new file mode 100644 index 0000000..c4363fa --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/application/VerifyPassword.java @@ -0,0 +1,22 @@ +package top.ddupan.iam.login.authentication.application; + +import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException.Reason; +import top.ddupan.iam.login.authentication.domain.User; + +/** Resolves the user through the same authenticated directory connection. */ +public final class VerifyPassword { + private final PasswordAuthenticator authenticator; + + public VerifyPassword(PasswordAuthenticator authenticator) { + this.authenticator = authenticator; + } + + public User verify(String username, String password) { + try (var session = authenticator.authenticate(username, password)) { + return session.users().findByLoginName(session.loginName()) + .orElseThrow(() -> new PasswordVerificationException(Reason.REJECTED)); + } + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/domain/LoginTransaction.java b/src/main/java/top/ddupan/iam/login/authentication/domain/LoginTransaction.java deleted file mode 100644 index 5048b81..0000000 --- a/src/main/java/top/ddupan/iam/login/authentication/domain/LoginTransaction.java +++ /dev/null @@ -1,56 +0,0 @@ -package top.ddupan.iam.login.authentication.domain; - -import java.time.Duration; -import java.time.Instant; -import java.util.Objects; -import java.util.UUID; - -/** Owns first-factor ordering, lifetime and the identity to which further factors must bind. */ -public final class LoginTransaction { - private static final Duration LIFETIME = Duration.ofMinutes(10); - private static final Duration ATTEMPT_INTERVAL = Duration.ofSeconds(2); - - public enum Step { PASSWORD_REQUIRED, MFA_REQUIRED } - public enum Attempt { ALLOWED, EXPIRED, WRONG_STEP, RETRY_LATER } - - private final UUID id; - private Step step = Step.PASSWORD_REQUIRED; - private Instant expiresAt; - private Instant retryAfter = Instant.MIN; - private User identity; - - private LoginTransaction(UUID id, Instant now) { - this.id = Objects.requireNonNull(id); - this.expiresAt = now.plus(LIFETIME); - } - - public static LoginTransaction start(UUID id, Instant now) { - return new LoginTransaction(id, now); - } - - public Attempt beginPasswordAttempt(Instant now) { - if (expiredAt(now)) return Attempt.EXPIRED; - if (step != Step.PASSWORD_REQUIRED) return Attempt.WRONG_STEP; - if (now.isBefore(retryAfter)) return Attempt.RETRY_LATER; - retryAfter = now.plus(ATTEMPT_INTERVAL); - return Attempt.ALLOWED; - } - - public void passwordVerified(User identity, Instant now) { - if (expiredAt(now) || step != Step.PASSWORD_REQUIRED) { - throw new IllegalStateException("Password verification is not allowed in this transaction state"); - } - this.identity = Objects.requireNonNull(identity); - this.step = Step.MFA_REQUIRED; - this.expiresAt = now.plus(LIFETIME); - } - - public UUID id() { return id; } - public Step step() { return step; } - public boolean expiredAt(Instant now) { return !now.isBefore(expiresAt); } - - public User identity() { - if (identity == null) throw new IllegalStateException("No verified identity yet"); - return identity; - } -} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java new file mode 100644 index 0000000..e177365 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryAuthenticationProvider.java @@ -0,0 +1,44 @@ +package top.ddupan.iam.login.authentication.infrastructure.security; + +import java.util.List; +import org.springframework.security.authentication.AuthenticationProvider; +import org.springframework.security.authentication.BadCredentialsException; +import org.springframework.security.authentication.InternalAuthenticationServiceException; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.Authentication; +import org.springframework.security.core.authority.FactorGrantedAuthority; +import top.ddupan.iam.login.authentication.application.VerifyPassword; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.domain.UserRepository; + +/** Bridges directory authentication into Spring Security's form-login lifecycle. */ +public final class DirectoryAuthenticationProvider implements AuthenticationProvider { + private final VerifyPassword passwords; + + public DirectoryAuthenticationProvider(VerifyPassword passwords) { + this.passwords = passwords; + } + + @Override + public Authentication authenticate(Authentication request) { + try { + var user = passwords.verify(request.getName(), + request.getCredentials() instanceof String password ? password : null); + // Directory groups remain profile data, not local application authorities. + return UsernamePasswordAuthenticationToken.authenticated(new DirectoryPrincipal(user), null, + List.of(FactorGrantedAuthority.fromAuthority(FactorGrantedAuthority.PASSWORD_AUTHORITY))); + } catch (PasswordVerificationException ex) { + if (ex.reason() == PasswordVerificationException.Reason.UNAVAILABLE) { + throw new InternalAuthenticationServiceException("Directory unavailable"); + } + throw new BadCredentialsException("Unable to verify credentials"); + } catch (UserRepository.AccessFailure ex) { + throw new InternalAuthenticationServiceException("Directory unavailable"); + } + } + + @Override + public boolean supports(Class authentication) { + return UsernamePasswordAuthenticationToken.class.equals(authentication); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java new file mode 100644 index 0000000..01e1ee4 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/infrastructure/security/DirectoryPrincipal.java @@ -0,0 +1,12 @@ +package top.ddupan.iam.login.authentication.infrastructure.security; + +import org.springframework.security.core.AuthenticatedPrincipal; +import top.ddupan.iam.login.authentication.domain.User; + +/** An immutable directory snapshot; never contains credentials or connections. */ +public record DirectoryPrincipal(User user) implements AuthenticatedPrincipal { + @Override + public String getName() { + return user.id().authority() + ":" + user.id().value(); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/BrowserSignInState.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/BrowserSignInState.java deleted file mode 100644 index 49ea262..0000000 --- a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/BrowserSignInState.java +++ /dev/null @@ -1,12 +0,0 @@ -package top.ddupan.iam.login.authentication.interfaces.web; - -import top.ddupan.iam.login.authentication.domain.LoginTransaction; - -/** HTTP-session storage plus presentation feedback. Authentication rules live in the aggregate. */ -final class BrowserSignInState { - final LoginTransaction transaction; - String username = ""; - String error = ""; - - BrowserSignInState(LoginTransaction transaction) { this.transaction = transaction; } -} diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java index e738fd6..d057063 100644 --- a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java +++ b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/PageRenderer.java @@ -27,6 +27,6 @@ public class PageRenderer { .replace(">", "\\u003e").replace("&", "\\u0026") .replace("\u2028", "\\u2028").replace("\u2029", "\\u2029"); return ResponseEntity.ok().header("Cache-Control", "no-store") - .contentType(MediaType.TEXT_HTML).body(shell.replace(SLOT, safe)); + .contentType(new MediaType(MediaType.TEXT_HTML, StandardCharsets.UTF_8)).body(shell.replace(SLOT, safe)); } } diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInAvailabilityFilter.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInAvailabilityFilter.java new file mode 100644 index 0000000..9dd8b64 --- /dev/null +++ b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInAvailabilityFilter.java @@ -0,0 +1,35 @@ +package top.ddupan.iam.login.authentication.interfaces.web; + +import java.io.IOException; +import jakarta.servlet.FilterChain; +import jakarta.servlet.ServletException; +import jakarta.servlet.http.HttpServletRequest; +import jakarta.servlet.http.HttpServletResponse; +import org.springframework.web.filter.OncePerRequestFilter; + +/** Rejects disabled or plaintext sign-in before any credentials reach authentication. */ +public final class SignInAvailabilityFilter extends OncePerRequestFilter { + private final boolean enabled; + + public SignInAvailabilityFilter(boolean enabled) { + this.enabled = enabled; + } + + @Override + protected boolean shouldNotFilter(HttpServletRequest request) { + String path = request.getServletPath(); + if (path.isEmpty()) path = request.getRequestURI().substring(request.getContextPath().length()); + return !path.equals("/signin") && !path.startsWith("/signin/"); + } + + @Override + protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, + FilterChain chain) throws ServletException, IOException { + if (!enabled || !request.isSecure()) { + response.setHeader("Cache-Control", "no-store"); + response.setStatus(enabled ? 426 : 404); + return; + } + chain.doFilter(request, response); + } +} diff --git a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java index 576f7ee..5a8b411 100644 --- a/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java +++ b/src/main/java/top/ddupan/iam/login/authentication/interfaces/web/SignInController.java @@ -1,118 +1,44 @@ package top.ddupan.iam.login.authentication.interfaces.web; -import jakarta.servlet.http.HttpServletRequest; -import jakarta.servlet.http.HttpSession; import java.util.Map; -import org.springframework.http.HttpStatus; import org.springframework.http.MediaType; import org.springframework.http.ResponseEntity; +import org.springframework.security.core.annotation.AuthenticationPrincipal; import org.springframework.security.web.csrf.CsrfToken; import org.springframework.web.bind.annotation.GetMapping; -import org.springframework.web.bind.annotation.PostMapping; import org.springframework.web.bind.annotation.RequestParam; import org.springframework.web.bind.annotation.RestController; -import org.springframework.web.server.ResponseStatusException; -import top.ddupan.iam.login.authentication.application.SignInService; -import top.ddupan.iam.login.authentication.domain.LoginTransaction.Step; import top.ddupan.iam.login.authentication.domain.User.GroupMembership; +import top.ddupan.iam.login.authentication.infrastructure.security.DirectoryPrincipal; -/** Translates browser requests and use-case outcomes; no directory or authentication policy here. */ +/** Renders Spring Security's login pages; form processing belongs to the security filters. */ @RestController public class SignInController { - static final String STATE = SignInController.class.getName() + ".state"; - private final SignInService signIn; private final PageRenderer renderer; - public SignInController(SignInService signIn, PageRenderer renderer) { - this.signIn = signIn; + public SignInController(PageRenderer renderer) { this.renderer = renderer; } @GetMapping(value = "/signin", produces = MediaType.TEXT_HTML_VALUE) - ResponseEntity page(HttpServletRequest request, CsrfToken csrf) { - requireAvailable(request); - var session = request.getSession(); - synchronized (session) { - var state = state(session); - if (state.transaction.step() == Step.MFA_REQUIRED) return redirect("/signin/mfa"); - return renderer.render(Map.of("step", "password", "name", state.username, - "error", state.error, "action", "/signin/password", "csrf", csrf(csrf))); - } - } - - @PostMapping("/signin/password") - ResponseEntity password(HttpServletRequest request, - @RequestParam(defaultValue = "") String username, - @RequestParam(defaultValue = "") String password) { - requireAvailable(request); - var session = request.getSession(false); - if (session == null) throw new ResponseStatusException(HttpStatus.CONFLICT); - synchronized (session) { - var state = (BrowserSignInState) session.getAttribute(STATE); - if (state == null) return redirect("/signin"); - state.username = username.length() <= 256 ? username : ""; - return switch (signIn.submitPassword(state.transaction, username, password)) { - case ACCEPTED -> { - request.changeSessionId(); - state.error = ""; - yield redirect("/signin/mfa"); - } - case REJECTED -> { - state.error = "无法验证账号,请检查凭据与账号状态,或稍后重试。"; - yield redirect("/signin"); - } - case EXPIRED, WRONG_STEP -> redirect("/signin"); - case RETRY_LATER -> throw new ResponseStatusException(HttpStatus.TOO_MANY_REQUESTS); - }; - } + ResponseEntity page(@RequestParam(required = false) String error, CsrfToken csrf) { + return renderer.render(Map.of("step", "password", "name", "", + "error", error == null ? "" : "无法验证账号,请检查凭据与账号状态,或稍后重试。", + "action", "/signin/password", "csrf", csrf(csrf))); } @GetMapping(value = "/signin/mfa", produces = MediaType.TEXT_HTML_VALUE) - ResponseEntity pending(HttpServletRequest request, CsrfToken csrf) { - requireAvailable(request); - var session = request.getSession(false); - if (session == null) return redirect("/signin"); - synchronized (session) { - var state = state(session); - if (state.transaction.step() != Step.MFA_REQUIRED) return redirect("/signin"); - var user = state.transaction.identity(); - return renderer.render(Map.of("step", "mfa-pending", "name", user.displayName(), - "error", "", "action", "/signin/restart", "csrf", csrf(csrf), - "identity", Map.of("username", user.username(), "subjectId", user.id().value(), - "email", user.email(), - "groups", user.memberships().stream().map(GroupMembership::name).toList(), - "groupDns", user.memberships().stream().map(GroupMembership::externalId).toList()))); - } - } - - @PostMapping("/signin/restart") - ResponseEntity restart(HttpServletRequest request) { - requireAvailable(request); - var session = request.getSession(false); - if (session != null) session.invalidate(); - return redirect("/signin"); - } - - private void requireAvailable(HttpServletRequest request) { - if (!signIn.enabled()) throw new ResponseStatusException(HttpStatus.NOT_FOUND); - if (!request.isSecure()) throw new ResponseStatusException(HttpStatus.UPGRADE_REQUIRED, "HTTPS required"); - } - - private BrowserSignInState state(HttpSession session) { - var state = (BrowserSignInState) session.getAttribute(STATE); - if (state == null || signIn.expired(state.transaction)) { - state = new BrowserSignInState(signIn.start()); - session.setAttribute(STATE, state); - } - return state; + ResponseEntity pending(@AuthenticationPrincipal DirectoryPrincipal principal, CsrfToken csrf) { + var user = principal.user(); + return renderer.render(Map.of("step", "mfa-pending", "name", user.displayName(), + "error", "", "action", "/signin/restart", "csrf", csrf(csrf), + "identity", Map.of("username", user.username(), "subjectId", user.id().value(), + "email", user.email(), + "groups", user.memberships().stream().map(GroupMembership::name).toList(), + "groupDns", user.memberships().stream().map(GroupMembership::externalId).toList()))); } private static Map csrf(CsrfToken token) { return Map.of("name", token.getParameterName(), "value", token.getToken()); } - - private static ResponseEntity redirect(String location) { - return ResponseEntity.status(HttpStatus.SEE_OTHER).header("Location", location) - .header("Cache-Control", "no-store").build(); - } } diff --git a/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java b/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java index a4369ad..0c432d2 100644 --- a/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java +++ b/src/main/java/top/ddupan/iam/login/configuration/AuthenticationConfiguration.java @@ -1,6 +1,5 @@ package top.ddupan.iam.login.configuration; -import java.time.Clock; import javax.naming.directory.DirContext; import javax.naming.ldap.LdapContext; import org.springframework.aot.hint.RuntimeHints; @@ -11,9 +10,8 @@ import org.springframework.ldap.core.DirContextProxy; import top.ddupan.iam.login.authentication.infrastructure.ad.AdUserEntry; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; -import top.ddupan.iam.login.authentication.application.SignInService; +import top.ddupan.iam.login.authentication.application.VerifyPassword; import top.ddupan.iam.login.authentication.application.port.PasswordAuthenticator; -import top.ddupan.iam.login.authentication.infrastructure.ad.AdProperties; /** Composition root: dependencies point inward, framework wiring stays outside the model. */ @Configuration(proxyBeanMethods = false) @@ -21,8 +19,8 @@ import top.ddupan.iam.login.authentication.infrastructure.ad.AdProperties; @ImportRuntimeHints(AuthenticationConfiguration.DirectoryHints.class) class AuthenticationConfiguration { @Bean - SignInService signInService(PasswordAuthenticator authenticator, AdProperties properties) { - return new SignInService(authenticator, Clock.systemUTC(), properties.enabled()); + VerifyPassword verifyPassword(PasswordAuthenticator authenticator) { + return new VerifyPassword(authenticator); } static class DirectoryHints implements RuntimeHintsRegistrar { @Override diff --git a/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java b/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java index 7375039..48d4241 100644 --- a/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java +++ b/src/main/java/top/ddupan/iam/login/configuration/SecurityConfiguration.java @@ -1,19 +1,68 @@ package top.ddupan.iam.login.configuration; +import java.time.Duration; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; +import org.springframework.core.annotation.Order; +import org.springframework.http.HttpStatus; +import org.springframework.security.authentication.ProviderManager; +import org.springframework.security.authorization.AuthorizationManagerFactories; import org.springframework.security.config.Customizer; import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.config.annotation.authorization.EnableMultiFactorAuthentication; import org.springframework.security.web.SecurityFilterChain; +import org.springframework.security.web.access.intercept.RequestAuthorizationContext; +import org.springframework.security.web.authentication.HttpStatusEntryPoint; +import org.springframework.security.web.authentication.LoginUrlAuthenticationEntryPoint; +import org.springframework.security.web.csrf.CsrfFilter; +import org.springframework.security.web.servlet.util.matcher.PathPatternRequestMatcher; +import top.ddupan.iam.login.authentication.application.VerifyPassword; +import top.ddupan.iam.login.authentication.infrastructure.ad.AdProperties; +import top.ddupan.iam.login.authentication.infrastructure.security.DirectoryAuthenticationProvider; +import top.ddupan.iam.login.authentication.interfaces.web.SignInAvailabilityFilter; @Configuration(proxyBeanMethods = false) +@EnableMultiFactorAuthentication(authorities = {}) class SecurityConfiguration { + // Operational Basic authentication is isolated from human first-factor authentication. @Bean - SecurityFilterChain security(HttpSecurity http) throws Exception { - return http.authorizeHttpRequests(auth -> auth - .requestMatchers("/error", "/signin", "/signin/**", "/assets/**", "/actuator/health/**").permitAll() + @Order(1) + SecurityFilterChain management(HttpSecurity http) throws Exception { + return http.securityMatcher("/actuator/**") + .authorizeHttpRequests(auth -> auth + .requestMatchers("/actuator/health/**").permitAll() .anyRequest().authenticated()) + .securityContext(context -> context.securityContextRepository( + new org.springframework.security.web.context.NullSecurityContextRepository())) + .sessionManagement(session -> session.sessionCreationPolicy( + org.springframework.security.config.http.SessionCreationPolicy.STATELESS)) .httpBasic(Customizer.withDefaults()) + .build(); + } + + @Bean + @Order(2) + SecurityFilterChain browser(HttpSecurity http, VerifyPassword passwords, AdProperties ad) throws Exception { + var passwordFactor = AuthorizationManagerFactories.multiFactor() + .requireFactor(factor -> factor.passwordAuthority().validDuration(Duration.ofMinutes(10))) + .build(); + return http + .authenticationManager(new ProviderManager(new DirectoryAuthenticationProvider(passwords))) + .addFilterBefore(new SignInAvailabilityFilter(ad.enabled()), CsrfFilter.class) + .authorizeHttpRequests(auth -> auth + .requestMatchers("/error", "/signin", "/signin/password", "/assets/**").permitAll() + .requestMatchers("/signin/mfa").access(passwordFactor.authenticated()) + // No complete MFA or Hydra acceptance exists yet. Fail closed until those are implemented. + .anyRequest().denyAll()) + .formLogin(form -> form.loginPage("/signin").loginProcessingUrl("/signin/password") + .defaultSuccessUrl("/signin/mfa", true).failureUrl("/signin?error")) + .logout(logout -> logout.logoutUrl("/signin/restart").logoutSuccessUrl("/signin")) + .exceptionHandling(exceptions -> exceptions + .defaultAuthenticationEntryPointFor(new LoginUrlAuthenticationEntryPoint("/signin"), + PathPatternRequestMatcher.withDefaults().matcher("/signin/**")) + .defaultAuthenticationEntryPointFor(new HttpStatusEntryPoint(HttpStatus.UNAUTHORIZED), + org.springframework.security.web.util.matcher.AnyRequestMatcher.INSTANCE)) + .requestCache(cache -> cache.disable()) .headers(headers -> headers.contentSecurityPolicy(csp -> csp.policyDirectives( "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; " + "object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'"))) diff --git a/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java b/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java index d97fc0e..fa16d00 100644 --- a/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java +++ b/src/test/java/top/ddupan/iam/login/IamLoginApplicationTests.java @@ -47,6 +47,9 @@ class IamLoginApplicationTests { @Test void signInIsDisabledUntilDirectoryIsConfigured() throws Exception { mvc.perform(get("/signin").secure(true)).andExpect(status().isNotFound()); + mvc.perform(org.springframework.test.web.servlet.request.MockMvcRequestBuilders.post("/signin/password") + .secure(true).with(org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestPostProcessors.csrf())) + .andExpect(status().isNotFound()); } @Test diff --git a/src/test/java/top/ddupan/iam/login/authentication/application/SignInServiceTests.java b/src/test/java/top/ddupan/iam/login/authentication/application/SignInServiceTests.java deleted file mode 100644 index fe58d75..0000000 --- a/src/test/java/top/ddupan/iam/login/authentication/application/SignInServiceTests.java +++ /dev/null @@ -1,107 +0,0 @@ -package top.ddupan.iam.login.authentication.application; - -import java.time.Clock; -import java.time.Instant; -import java.time.ZoneId; -import java.time.ZoneOffset; -import java.util.List; -import java.util.Optional; -import java.util.concurrent.atomic.AtomicInteger; -import org.junit.jupiter.api.Test; -import top.ddupan.iam.login.authentication.application.port.AuthenticatedUserSession; -import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; -import top.ddupan.iam.login.authentication.domain.LoginTransaction; -import top.ddupan.iam.login.authentication.domain.User; -import top.ddupan.iam.login.authentication.domain.UserRepository; -import static org.assertj.core.api.Assertions.*; - -class SignInServiceTests { - static final User ALICE = new User(new User.UserId("directory", "alice-id"), "alice", "Alice", "", List.of()); - - @Test - void verifiesPasswordThenReadsTheBoundUserAndClosesTheRepositoryScope() { - var scope = new Scope(name -> { - assertThat(name).isEqualTo("alice@directory"); - return Optional.of(ALICE); - }); - var service = new SignInService((username, password) -> scope, new TestClock(), true); - var transaction = service.start(); - assertThat(service.submitPassword(transaction, "alice", "secret")).isEqualTo(SignInService.PasswordResult.ACCEPTED); - assertThat(scope.closed).isTrue(); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.MFA_REQUIRED); - assertThat(transaction.identity()).isEqualTo(ALICE); - } - - @Test - void failedAuthenticationDoesNotAdvanceTheTransaction() { - var service = new SignInService((username, password) -> { - throw new PasswordVerificationException(PasswordVerificationException.Reason.REJECTED); - }, new TestClock(), true); - var transaction = service.start(); - assertThat(service.submitPassword(transaction, "alice", "wrong")).isEqualTo(SignInService.PasswordResult.REJECTED); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.PASSWORD_REQUIRED); - } - - @Test - void missingUserDoesNotAuthenticateAndStillClosesTheScope() { - var scope = new Scope(name -> Optional.empty()); - var service = new SignInService((username, password) -> scope, new TestClock(), true); - var transaction = service.start(); - assertThat(service.submitPassword(transaction, "alice", "secret")).isEqualTo(SignInService.PasswordResult.REJECTED); - assertThat(scope.closed).isTrue(); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.PASSWORD_REQUIRED); - } - - @Test - void expiredAndRepeatedAttemptsDoNotCallTheDirectory() { - var calls = new AtomicInteger(); - var clock = new TestClock(); - var service = new SignInService((username, password) -> { - calls.incrementAndGet(); - throw new PasswordVerificationException(PasswordVerificationException.Reason.REJECTED); - }, clock, true); - var transaction = service.start(); - service.submitPassword(transaction, "alice", "wrong"); - assertThat(service.submitPassword(transaction, "alice", "wrong")).isEqualTo(SignInService.PasswordResult.RETRY_LATER); - clock.now = clock.now.plusSeconds(600); - assertThat(service.submitPassword(transaction, "alice", "wrong")).isEqualTo(SignInService.PasswordResult.EXPIRED); - assertThat(calls.get()).isEqualTo(1); - } - - @Test - void aSlowRepositoryCannotReviveAnExpiredTransaction() { - var clock = new TestClock(); - var scope = new Scope(name -> { clock.now = clock.now.plusSeconds(600); return Optional.of(ALICE); }); - var service = new SignInService((username, password) -> scope, clock, true); - var transaction = service.start(); - assertThat(service.submitPassword(transaction, "alice", "secret")).isEqualTo(SignInService.PasswordResult.EXPIRED); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.PASSWORD_REQUIRED); - assertThat(scope.closed).isTrue(); - } - - @Test - void repositoryFailureClosesTheScopeWithoutPromotingIdentity() { - var scope = new Scope(name -> { throw new UserRepository.AccessFailure(); }); - var service = new SignInService((username, password) -> scope, new TestClock(), true); - var transaction = service.start(); - assertThat(service.submitPassword(transaction, "alice", "secret")).isEqualTo(SignInService.PasswordResult.REJECTED); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.PASSWORD_REQUIRED); - assertThat(scope.closed).isTrue(); - } - - private static final class Scope implements AuthenticatedUserSession { - private final UserRepository users; - boolean closed; - Scope(UserRepository users) { this.users = users; } - @Override public String loginName() { return "alice@directory"; } - @Override public UserRepository users() { return users; } - @Override public void close() { closed = true; } - } - - private static final class TestClock extends Clock { - Instant now = Instant.parse("2026-01-01T00:00:00Z"); - @Override public Instant instant() { return now; } - @Override public ZoneId getZone() { return ZoneOffset.UTC; } - @Override public Clock withZone(ZoneId zone) { return Clock.fixed(now, zone); } - } -} diff --git a/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java b/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java new file mode 100644 index 0000000..729b91c --- /dev/null +++ b/src/test/java/top/ddupan/iam/login/authentication/application/VerifyPasswordTests.java @@ -0,0 +1,49 @@ +package top.ddupan.iam.login.authentication.application; + +import java.util.List; +import java.util.Optional; +import org.junit.jupiter.api.Test; +import top.ddupan.iam.login.authentication.application.port.AuthenticatedUserSession; +import top.ddupan.iam.login.authentication.application.port.PasswordVerificationException; +import top.ddupan.iam.login.authentication.domain.User; +import top.ddupan.iam.login.authentication.domain.UserRepository; +import static org.assertj.core.api.Assertions.*; + +class VerifyPasswordTests { + static final User ALICE = new User(new User.UserId("directory", "alice-id"), "alice", "Alice", "", List.of()); + + @Test + void readsTheBoundUserAndClosesTheConnection() { + var scope = new Scope(name -> { + assertThat(name).isEqualTo("alice@directory"); + return Optional.of(ALICE); + }); + assertThat(new VerifyPassword((username, password) -> scope).verify("alice", "secret")).isEqualTo(ALICE); + assertThat(scope.closed).isTrue(); + } + + @Test + void missingUserClosesTheConnectionAndRejectsAuthentication() { + var scope = new Scope(name -> Optional.empty()); + assertThatThrownBy(() -> new VerifyPassword((u, p) -> scope).verify("alice", "secret")) + .isInstanceOf(PasswordVerificationException.class); + assertThat(scope.closed).isTrue(); + } + + @Test + void repositoryFailureStillClosesTheConnection() { + var scope = new Scope(name -> { throw new UserRepository.AccessFailure(); }); + assertThatThrownBy(() -> new VerifyPassword((u, p) -> scope).verify("alice", "secret")) + .isInstanceOf(UserRepository.AccessFailure.class); + assertThat(scope.closed).isTrue(); + } + + private static final class Scope implements AuthenticatedUserSession { + private final UserRepository users; + boolean closed; + Scope(UserRepository users) { this.users = users; } + @Override public String loginName() { return "alice@directory"; } + @Override public UserRepository users() { return users; } + @Override public void close() { closed = true; } + } +} diff --git a/src/test/java/top/ddupan/iam/login/authentication/domain/LoginTransactionTests.java b/src/test/java/top/ddupan/iam/login/authentication/domain/LoginTransactionTests.java deleted file mode 100644 index 1586e01..0000000 --- a/src/test/java/top/ddupan/iam/login/authentication/domain/LoginTransactionTests.java +++ /dev/null @@ -1,44 +0,0 @@ -package top.ddupan.iam.login.authentication.domain; - -import java.time.Instant; -import java.util.List; -import java.util.UUID; -import org.junit.jupiter.api.Test; -import static org.assertj.core.api.Assertions.*; - -class LoginTransactionTests { - static final Instant NOW = Instant.parse("2026-01-01T00:00:00Z"); - static final User ALICE = new User(new User.UserId("directory", "alice-id"), "alice", "Alice", "", List.of()); - - @Test - void passwordVerificationBindsIdentityAndOnlyAdvancesToMfa() { - var transaction = LoginTransaction.start(UUID.randomUUID(), NOW); - assertThat(transaction.beginPasswordAttempt(NOW)).isEqualTo(LoginTransaction.Attempt.ALLOWED); - transaction.passwordVerified(ALICE, NOW); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.MFA_REQUIRED); - assertThat(transaction.identity()).isEqualTo(ALICE); - assertThat(transaction.beginPasswordAttempt(NOW.plusSeconds(3))).isEqualTo(LoginTransaction.Attempt.WRONG_STEP); - var bob = new User(new User.UserId("directory", "bob-id"), "bob", "Bob", "", List.of()); - assertThatThrownBy(() -> transaction.passwordVerified(bob, NOW.plusSeconds(3))) - .isInstanceOf(IllegalStateException.class); - assertThat(transaction.identity()).isEqualTo(ALICE); - } - - @Test - void expiredTransactionsCannotAcceptAPasswordResult() { - var transaction = LoginTransaction.start(UUID.randomUUID(), NOW); - assertThat(transaction.beginPasswordAttempt(NOW.plusSeconds(600))).isEqualTo(LoginTransaction.Attempt.EXPIRED); - assertThatThrownBy(() -> transaction.passwordVerified(ALICE, NOW.plusSeconds(600))) - .isInstanceOf(IllegalStateException.class); - } - - @Test - void attemptsAreSeparatedWithoutAdvancingAuthentication() { - var transaction = LoginTransaction.start(UUID.randomUUID(), NOW); - assertThat(transaction.beginPasswordAttempt(NOW)).isEqualTo(LoginTransaction.Attempt.ALLOWED); - assertThat(transaction.beginPasswordAttempt(NOW.plusSeconds(1))).isEqualTo(LoginTransaction.Attempt.RETRY_LATER); - assertThat(transaction.beginPasswordAttempt(NOW.plusSeconds(2))).isEqualTo(LoginTransaction.Attempt.ALLOWED); - assertThat(transaction.step()).isEqualTo(LoginTransaction.Step.PASSWORD_REQUIRED); - assertThatThrownBy(transaction::identity).isInstanceOf(IllegalStateException.class); - } -} diff --git a/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java b/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java index 1463adf..7798312 100644 --- a/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java +++ b/src/test/java/top/ddupan/iam/login/authentication/interfaces/web/SignInIntegrationTests.java @@ -10,6 +10,11 @@ import org.springframework.beans.factory.annotation.Autowired; import org.springframework.boot.test.context.SpringBootTest; import org.springframework.boot.webmvc.test.autoconfigure.AutoConfigureMockMvc; import org.springframework.http.MediaType; +import java.time.Instant; +import java.util.List; +import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; +import org.springframework.security.core.authority.FactorGrantedAuthority; +import org.springframework.security.core.context.SecurityContext; import org.springframework.mock.web.MockHttpSession; import org.springframework.test.context.DynamicPropertyRegistry; import org.springframework.test.context.DynamicPropertySource; @@ -20,8 +25,10 @@ import static org.springframework.test.web.servlet.request.MockMvcRequestBuilder import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.*; /** Real LDAPS sockets and Spring Data LDAP; AD bind/subcode semantics are simulated. */ -@SpringBootTest(properties = {"iam.ad.enabled=true", "iam.ad.domain=example.test", "iam.ad.base-dn=dc=example,dc=test"}) +@SpringBootTest(properties = {"iam.ad.enabled=true", "iam.ad.domain=example.test", "iam.ad.base-dn=dc=example,dc=test", + "management.otlp.metrics.export.enabled=false", "spring.security.user.name=fixture-monitor", "spring.security.user.password=fixture-monitor-password"}) @AutoConfigureMockMvc +@org.springframework.boot.micrometer.metrics.test.autoconfigure.AutoConfigureMetrics @ImportRuntimeHints(SignInIntegrationTests.FixtureHints.class) class SignInIntegrationTests { static class FixtureHints implements RuntimeHintsRegistrar { @@ -67,9 +74,12 @@ class SignInIntegrationTests { .andReturn().getResponse().getContentAsString(); assertThat(html).contains("mfa-pending", "gitea-admins", "\\u003c/script\\u003e") .doesNotContain("fixture-password", "