Skip to content
Snippets Groups Projects
Commit 963819a1 authored by Felix Sidokhine's avatar Felix Sidokhine
Browse files

fixed module dependency issue

parent 773520c6
No related branches found
No related tags found
No related merge requests found
......@@ -34,6 +34,11 @@
<artifactId>nimbus-jose-jwt</artifactId>
<version>${nimbus.jwt.version}</version>
</dependency>
<dependency>
<groupId>org.ow2.asm</groupId>
<artifactId>asm</artifactId>
<version>${asm.version}</version>
</dependency>
</dependencies>
<build>
......
......@@ -61,6 +61,11 @@
<artifactId>nimbus-jose-jwt</artifactId>
<version>${nimbus.jwt.version}</version>
</dependency>
<dependency>
<groupId>org.ow2.asm</groupId>
<artifactId>asm</artifactId>
<version>${asm.version}</version>
</dependency>
</dependencies>
<build>
......
......@@ -31,16 +31,18 @@ public class InstallFilter implements Filter {
boolean isLogin = false;
if(request.getServletPath().contains("start")) isLogin = true;
SignedJWT signedJWT = null;
try {
JWSVerifier jwsVerifier = new RSASSAVerifier(userAuthenticationModule.getAuthModulePubKey());
signedJWT = SignedJWT.parse(request.getHeader("Bearer"));
if(signedJWT.verify(jwsVerifier) && signedJWT.getJWTClaimsSet().getExpirationTime().compareTo(new Date()) > 0){
authsuccess = true;
request.setAttribute("username",signedJWT.getJWTClaimsSet().getSubject());
request.setAttribute("accessLevel",signedJWT.getJWTClaimsSet().getClaim("scope"));
if(request.getHeader("Bearer") != null) {
try {
JWSVerifier jwsVerifier = new RSASSAVerifier(userAuthenticationModule.getAuthModulePubKey());
signedJWT = SignedJWT.parse(request.getHeader("Bearer"));
if (signedJWT.verify(jwsVerifier) && signedJWT.getJWTClaimsSet().getExpirationTime().compareTo(new Date()) > 0) {
authsuccess = true;
request.setAttribute("username", signedJWT.getJWTClaimsSet().getSubject());
request.setAttribute("accessLevel", signedJWT.getJWTClaimsSet().getClaim("scope"));
}
} catch (Exception e) {
log.info("Received an invalid token, declining access...");
}
} catch (Exception e) {
log.info("Received an invalid token, declining access...");
}
if(authsuccess || isLogin) filterChain.doFilter(servletRequest,servletResponse);
else response.sendError(403,"You are not authorized to access this page!");
......
......@@ -45,6 +45,7 @@
<javax.servlet.version>4.0.1</javax.servlet.version>
<maven.clean.version>3.1.0</maven.clean.version>
<nimbus.jwt.version>8.17</nimbus.jwt.version>
<asm.version>8.0</asm.version>
</properties>
<dependencies>
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment