Additional event when user not found. Contributed by Karel Miarka.
This commit is contained in:
@@ -20,12 +20,14 @@ import net.sf.acegisecurity.AuthenticationException;
|
||||
import net.sf.acegisecurity.AuthenticationServiceException;
|
||||
import net.sf.acegisecurity.BadCredentialsException;
|
||||
import net.sf.acegisecurity.DisabledException;
|
||||
import net.sf.acegisecurity.GrantedAuthority;
|
||||
import net.sf.acegisecurity.UserDetails;
|
||||
import net.sf.acegisecurity.providers.AuthenticationProvider;
|
||||
import net.sf.acegisecurity.providers.UsernamePasswordAuthenticationToken;
|
||||
import net.sf.acegisecurity.providers.dao.cache.NullUserCache;
|
||||
import net.sf.acegisecurity.providers.dao.event.AuthenticationFailureDisabledEvent;
|
||||
import net.sf.acegisecurity.providers.dao.event.AuthenticationFailurePasswordEvent;
|
||||
import net.sf.acegisecurity.providers.dao.event.AuthenticationFailureUsernameNotFoundEvent;
|
||||
import net.sf.acegisecurity.providers.dao.event.AuthenticationSuccessEvent;
|
||||
import net.sf.acegisecurity.providers.encoding.PasswordEncoder;
|
||||
import net.sf.acegisecurity.providers.encoding.PlaintextPasswordEncoder;
|
||||
@@ -190,7 +192,19 @@ public class DaoAuthenticationProvider implements AuthenticationProvider,
|
||||
|
||||
if (user == null) {
|
||||
cacheWasUsed = false;
|
||||
user = getUserFromBackend(username);
|
||||
|
||||
try {
|
||||
user = getUserFromBackend(username);
|
||||
} catch (BadCredentialsException ex) {
|
||||
if (this.context != null) {
|
||||
context.publishEvent(new AuthenticationFailureUsernameNotFoundEvent(
|
||||
authentication,
|
||||
new User(username, "*****", false,
|
||||
new GrantedAuthority[0])));
|
||||
}
|
||||
|
||||
throw ex;
|
||||
}
|
||||
}
|
||||
|
||||
if (!user.isEnabled()) {
|
||||
|
||||
+40
@@ -0,0 +1,40 @@
|
||||
/* Copyright 2004 Acegi Technology Pty Limited
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
package net.sf.acegisecurity.providers.dao.event;
|
||||
|
||||
import net.sf.acegisecurity.Authentication;
|
||||
import net.sf.acegisecurity.UserDetails;
|
||||
|
||||
|
||||
/**
|
||||
* Application event which indicates authentication failure due to nonexistent
|
||||
* username. <code>AuthenticationFailureUsernameNotFoundEvent.getUser()</code>
|
||||
* returns an instance of <code>User</code>, where the username is filled by
|
||||
* the <code>String</code> provided at login attempt. The other properties are
|
||||
* set to non-<code>null</code> values without any meaning.
|
||||
*
|
||||
* @author Karel Miarka
|
||||
*/
|
||||
public class AuthenticationFailureUsernameNotFoundEvent
|
||||
extends AuthenticationEvent {
|
||||
//~ Constructors ===========================================================
|
||||
|
||||
// ~ Constructors ===========================================================
|
||||
public AuthenticationFailureUsernameNotFoundEvent(
|
||||
Authentication authentication, UserDetails user) {
|
||||
super(authentication, user);
|
||||
}
|
||||
}
|
||||
@@ -45,7 +45,8 @@ public class LoggerListener implements ApplicationListener {
|
||||
AuthenticationFailurePasswordEvent authEvent = (AuthenticationFailurePasswordEvent) event;
|
||||
|
||||
if (logger.isWarnEnabled()) {
|
||||
logger.warn("Authentication failed due to incorrect password for user: "
|
||||
logger.warn(
|
||||
"Authentication failed due to incorrect password for user: "
|
||||
+ authEvent.getUser().getUsername() + "; details: "
|
||||
+ authEvent.getAuthentication().getDetails());
|
||||
}
|
||||
@@ -62,6 +63,17 @@ public class LoggerListener implements ApplicationListener {
|
||||
}
|
||||
}
|
||||
|
||||
if (event instanceof AuthenticationFailureUsernameNotFoundEvent) {
|
||||
AuthenticationFailureUsernameNotFoundEvent authEvent = (AuthenticationFailureUsernameNotFoundEvent) event;
|
||||
|
||||
if (logger.isWarnEnabled()) {
|
||||
logger.warn(
|
||||
"Authentication failed due to nonexistent username: "
|
||||
+ authEvent.getUser().getUsername() + "; details: "
|
||||
+ authEvent.getAuthentication().getDetails());
|
||||
}
|
||||
}
|
||||
|
||||
if (event instanceof AuthenticationSuccessEvent) {
|
||||
AuthenticationSuccessEvent authEvent = (AuthenticationSuccessEvent) event;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user