保誠-保戶業務員媒合平台
wayne
2021-11-29 cc752b0680d6f4975b14a3cdc2b8922e8d3bf0ee
[update] Otp認證錯誤代碼規格調整

修改4個檔案
新增2個檔案
66 ■■■■■ 已變更過的檔案
pamapi/src/doc/登入API/客戶認證OTP並登入.txt 7 ●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/main/java/com/pollex/pam/security/provider/OtpAuthenticationProvider.java 6 ●●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/main/java/com/pollex/pam/service/OtpUtilService.java 31 ●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/main/java/com/pollex/pam/web/rest/OtpResource.java 3 ●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/main/java/com/pollex/pam/web/rest/errors/CustomerNotRegisteredException.java 8 ●●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/main/java/com/pollex/pam/web/rest/errors/OtpLoginFailException.java 11 ●●●●● 修補檔 | 檢視 | 原始 | 究查 | 歷程
pamapi/src/doc/µn¤JAPI/«È¤á»{ÃÒOTP¨Ãµn¤J.txt
@@ -8,10 +8,13 @@
    "otpCode": "123" // ç”±æ‰‹æ©Ÿæˆ–信箱收到的認證碼
}
目前dev中客戶帳號可用自己Teams的email信箱做登入 (各個前後端工程師及QA帳號已經開好)。
而indexKey及otpCode在dev是不會做任何驗證,可以直接登入
response body:
response body: è‹¥Otp認證通過、該帳號已註冊此系統
{
    "id_token": "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJ3YXluZUBwb2xsZXguY29tLnR3IiwiYXV0aCI6IlJPTEVfVVNFUiIsImRldGFpbHMiOnsiQ3VzdG9tZXJBY2NvdW50Ijoid2F5bmVAcG9sbGV4LmNvbS50dyIsIkN1c3RvbWVySWQiOiI2IiwiQ3VzdG9tZXJOYW1lIjoiV2F5bmUifSwiZXhwIjoxNjM3NjQ5NzUzfQ.6xqkWG7kQPUHOys8vPdx6ebgH1wgZ4gysFEa1t1jCnKB44VsFZ8PjtUlN2mvroBdGtPwpOynoTHU7HvAQ3_mnQ"
}
若Otp認證錯誤會回 401,detail會有該次Otp系統回的錯誤訊息
若Otp認證通過,但該account尚未註冊則回 403
若有其他系統錯誤統一回500
pamapi/src/main/java/com/pollex/pam/security/provider/OtpAuthenticationProvider.java
@@ -1,16 +1,14 @@
package com.pollex.pam.security.provider;
import com.pollex.pam.web.rest.errors.CustomerNotRegisteredException;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.authentication.AuthenticationCredentialsNotFoundException;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.AuthenticationException;
import org.springframework.stereotype.Component;
import com.pollex.pam.domain.Customer;
import com.pollex.pam.domain.OtpTmp;
import com.pollex.pam.enums.OtpTmpStatusEnum;
import com.pollex.pam.repository.CustomerRepository;
import com.pollex.pam.security.token.OtpAuthenticationToken;
import com.pollex.pam.service.CustomerAuthService;
@@ -46,7 +44,7 @@
                            .orElse(null);
        if (customer == null) {
            throw new AuthenticationCredentialsNotFoundException("");
            throw new CustomerNotRegisteredException();
        }
        return customerAuthService.buildCustomerAuthToken(customer, otpCode, indexKey);
pamapi/src/main/java/com/pollex/pam/service/OtpUtilService.java
@@ -2,6 +2,7 @@
import com.pollex.pam.domain.OtpTmp;
import com.pollex.pam.enums.OtpTmpStatusEnum;
import com.pollex.pam.web.rest.errors.OtpLoginFailException;
import com.pollex.pam.web.rest.vm.VerifyOtpVM;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
@@ -37,25 +38,21 @@
    @Transactional
    public void verifyOtp(String account, String indexKey, String otpCode) {
        try {
            if(applicationProperty.isMockLogin()){
                loginRecordService.saveOTPLoginSuccessRecord(account);
                log.debug("Do MockLogin");
            } else {  // otp logon
                OtpResponseDTO otpResponseDTO = otpWebService.verifyOTP(indexKey, otpCode);
                if (otpResponseDTO.isSuccess()) {
                    loginRecordService.saveOTPLoginSuccessRecord(account);
                }
                else {
                    loginRecordService.saveOTPLoginFailRecord(account, otpResponseDTO.getFailReason());
                    throw new AuthenticationCredentialsNotFoundException("");
                }
        if (applicationProperty.isMockLogin()) {
            log.debug("Do MockLogin");
        } else {  // otp logon
            OtpResponseDTO otpResponseDTO = otpWebService.verifyOTP(indexKey, otpCode);
            if (otpResponseDTO.isSuccess()) {
                log.info("otp login success!");
            }
            setVerrifiedOtpTmp(account, indexKey);
        } catch (Exception e) {
            log.error("Exception: ", e);
            throw new AuthenticationCredentialsNotFoundException("");
            else {
                log.info("otp login fail... , account = {}, failReason = {}", account, otpResponseDTO.getFailReason());
                loginRecordService.saveOTPLoginFailRecord(account, otpResponseDTO.getFailReason());
                throw new OtpLoginFailException(otpResponseDTO.getFailReason());
            }
        }
        loginRecordService.saveOTPLoginSuccessRecord(account);
        setVerrifiedOtpTmp(account, indexKey);
    }
    private void setVerrifiedOtpTmp(String account, String indexKey) {
pamapi/src/main/java/com/pollex/pam/web/rest/OtpResource.java
@@ -3,6 +3,7 @@
import java.util.Arrays;
import java.util.UUID;
import com.pollex.pam.web.rest.errors.CustomerNotRegisteredException;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.beans.factory.annotation.Autowired;
@@ -90,7 +91,7 @@
                            .orElse(null);
        if (customer == null) {
            return ResponseEntity.status(HttpStatus.UNAUTHORIZED).build();
            return ResponseEntity.status(HttpStatus.FORBIDDEN).build();
        }
        String jwt = customerAuthService.authorize(customer, verifyOtpParam.getIndexKey(), verifyOtpParam.getOtpCode());
pamapi/src/main/java/com/pollex/pam/web/rest/errors/CustomerNotRegisteredException.java
¤ñ¹ï·sÀÉ®×
@@ -0,0 +1,8 @@
package com.pollex.pam.web.rest.errors;
import org.springframework.http.HttpStatus;
import org.springframework.web.bind.annotation.ResponseStatus;
@ResponseStatus(code = HttpStatus.FORBIDDEN, reason = "CustomerNotRegistered")
public class CustomerNotRegisteredException extends RuntimeException{
}
pamapi/src/main/java/com/pollex/pam/web/rest/errors/OtpLoginFailException.java
¤ñ¹ï·sÀÉ®×
@@ -0,0 +1,11 @@
package com.pollex.pam.web.rest.errors;
import org.springframework.http.HttpStatus;
import org.springframework.web.bind.annotation.ResponseStatus;
@ResponseStatus(code = HttpStatus.UNAUTHORIZED)
public class OtpLoginFailException extends RuntimeException{
    public OtpLoginFailException(String message) {
        super(message);
    }
}