feat: improved handling and logging of access denied errors

This commit is contained in:
Björn Fromme
2025-04-28 11:10:35 +02:00
parent aa708e491c
commit c37309b3c1
3 changed files with 29 additions and 12 deletions
+15 -4
View File
@@ -3,6 +3,7 @@ monolog:
- deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists - deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists
- bpn - bpn
- core - core
- auth
when@dev: when@dev:
monolog: monolog:
@@ -10,12 +11,17 @@ when@dev:
database: database:
type: service type: service
id: App\Logger\DatabaseHandler id: App\Logger\DatabaseHandler
channels: ["core", "bpn"] channels: ["core", "bpn", "auth"]
bpn: bpn:
type: stream type: stream
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log" path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
level: debug level: debug
channels: ["bpn"] channels: ["bpn"]
auth:
type: stream
path: "%kernel.logs_dir%/%kernel.environment%.auth.log"
level: debug
channels: ["auth"]
core: core:
type: stream type: stream
path: "%kernel.logs_dir%/%kernel.environment%.core.log" path: "%kernel.logs_dir%/%kernel.environment%.core.log"
@@ -25,7 +31,7 @@ when@dev:
type: stream type: stream
path: "%kernel.logs_dir%/%kernel.environment%.log" path: "%kernel.logs_dir%/%kernel.environment%.log"
level: debug level: debug
channels: ["!event", "!bpn", "!core"] channels: ["!event", "!bpn", "!core", "!auth"]
# uncomment to get logging in your browser # uncomment to get logging in your browser
# you may have to allow bigger header sizes in your Web server configuration # you may have to allow bigger header sizes in your Web server configuration
#firephp: #firephp:
@@ -59,13 +65,18 @@ when@prod:
database: database:
type: service type: service
id: App\Logger\DatabaseHandler id: App\Logger\DatabaseHandler
channels: ["core", "bpn"] channels: ["core", "bpn", "auth"]
bpn: bpn:
type: rotating_file type: rotating_file
max_files: 7 max_files: 7
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log" path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
level: info level: info
channels: ["bpn"] channels: ["bpn"]
auth:
type: stream
path: "%kernel.logs_dir%/%kernel.environment%.auth.log"
level: debug
channels: ["auth"]
core: core:
type: rotating_file type: rotating_file
max_files: 7 max_files: 7
@@ -78,7 +89,7 @@ when@prod:
handler: nested handler: nested
excluded_http_codes: [404, 405] excluded_http_codes: [404, 405]
buffer_size: 50 # How many messages should be saved? Prevent memory leaks buffer_size: 50 # How many messages should be saved? Prevent memory leaks
channels: ["!bpn", "!core"] channels: ["!bpn", "!core", "!auth"]
nested: nested:
type: rotating_file type: rotating_file
path: "%kernel.logs_dir%/%kernel.environment%.framework.log" path: "%kernel.logs_dir%/%kernel.environment%.framework.log"
+12 -6
View File
@@ -4,20 +4,26 @@ namespace App\EventListener;
use Psr\Log\LoggerInterface; use Psr\Log\LoggerInterface;
use Symfony\Bundle\SecurityBundle\Security; use Symfony\Bundle\SecurityBundle\Security;
use Symfony\Component\EventDispatcher\Attribute\AsEventListener; use Symfony\Component\EventDispatcher\EventSubscriberInterface;
use Symfony\Component\HttpKernel\Event\ExceptionEvent; use Symfony\Component\HttpKernel\Event\ExceptionEvent;
use Symfony\Component\HttpKernel\KernelEvents; use Symfony\Component\HttpKernel\KernelEvents;
use Symfony\Component\Security\Core\Exception\AccessDeniedException; use Symfony\Component\Security\Core\Exception\AccessDeniedException;
#[AsEventListener(event: KernelEvents::EXCEPTION, method: 'onKernelException', priority: 2)] class AccessDeniedListener implements EventSubscriberInterface
class AccessDeniedListener
{ {
public function __construct( public function __construct(
private readonly Security $security, private readonly Security $security,
private readonly LoggerInterface $logger, private readonly LoggerInterface $authLogger,
) { ) {
} }
public static function getSubscribedEvents(): array
{
return [
KernelEvents::EXCEPTION => ['onKernelException', 2],
];
}
public function onKernelException(ExceptionEvent $event): void public function onKernelException(ExceptionEvent $event): void
{ {
$exception = $event->getThrowable(); $exception = $event->getThrowable();
@@ -33,7 +39,7 @@ class AccessDeniedListener
if (in_array($route, ['oauth2_authorize', 'oauth2_token'])) { if (in_array($route, ['oauth2_authorize', 'oauth2_token'])) {
$request->getSession()->getFlashBag()->add('info', 'Bitte melde dich an.'); $request->getSession()->getFlashBag()->add('info', 'Bitte melde dich an.');
$this->logger->info('OAuth2 authorization request', [ $this->authLogger->info('OAuth2 authorization request', [
'uri' => $request->getRequestUri(), 'uri' => $request->getRequestUri(),
]); ]);
@@ -48,7 +54,7 @@ class AccessDeniedListener
$request->getSession()->remove('_security.main.target_path'); $request->getSession()->remove('_security.main.target_path');
} }
$this->logger->warning('Access denied', [ $this->authLogger->warning('Access denied', [
'uri' => $request->getRequestUri(), 'uri' => $request->getRequestUri(),
]); ]);
} }
+2 -2
View File
@@ -33,7 +33,7 @@ class BpnAuthenticator extends AbstractLoginFormAuthenticator implements Authent
private readonly ApiClient $apiClient, private readonly ApiClient $apiClient,
private readonly EntityManagerInterface $entityManager, private readonly EntityManagerInterface $entityManager,
private readonly Crypt $crypt, private readonly Crypt $crypt,
private readonly LoggerInterface $logger, private readonly LoggerInterface $authLogger,
) { ) {
} }
@@ -106,7 +106,7 @@ class BpnAuthenticator extends AbstractLoginFormAuthenticator implements Authent
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
{ {
$this->logger->info('Login', [ $this->authLogger->info('Login', [
'email' => $token->getUserIdentifier(), 'email' => $token->getUserIdentifier(),
]); ]);