fix: PSK 请求恢复 X-Email 头用于身份识别
- X-Email 参与身份查找但不参与签名 - 已注册邮箱:对应该账户 accountId/trustLevel - 未注册邮箱:accountId=0, trustLevel=TRUSTED - audit 日志通过 authEmail attribute 追踪
This commit is contained in:
@@ -62,12 +62,17 @@ public class HmacAuthInterceptor implements HandlerInterceptor {
|
|||||||
// 方式 2:PSK 签名
|
// 方式 2:PSK 签名
|
||||||
String sig = request.getHeader(HEADER_SIGNATURE);
|
String sig = request.getHeader(HEADER_SIGNATURE);
|
||||||
String ts = request.getHeader(HEADER_TIMESTAMP);
|
String ts = request.getHeader(HEADER_TIMESTAMP);
|
||||||
if (sig != null && ts != null) {
|
String email = request.getHeader(HEADER_EMAIL);
|
||||||
|
if (sig != null && ts != null && email != null) {
|
||||||
try {
|
try {
|
||||||
if (pskService.verify(request.getMethod(), request.getRequestURI(),
|
if (pskService.verify(request.getMethod(), request.getRequestURI(),
|
||||||
Long.parseLong(ts), sig) != null) {
|
Long.parseLong(ts), sig) != null) {
|
||||||
request.setAttribute("accountId", 0L);
|
// X-Email 仅标识身份,不参与签名
|
||||||
request.setAttribute("trustLevel", com.par.core.enums.TrustLevel.TRUSTED);
|
Account account = accountService.findByAnyEmail(email);
|
||||||
|
request.setAttribute("accountId", account != null ? account.getId() : 0L);
|
||||||
|
request.setAttribute("trustLevel", account != null ? account.getTrustLevel()
|
||||||
|
: com.par.core.enums.TrustLevel.TRUSTED);
|
||||||
|
request.setAttribute("authEmail", email);
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
} catch (NumberFormatException ignored) {}
|
} catch (NumberFormatException ignored) {}
|
||||||
|
|||||||
Reference in New Issue
Block a user