feat: improved handling and logging of access denied errors
This commit is contained in:
@@ -3,6 +3,7 @@ monolog:
|
|||||||
- deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists
|
- deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists
|
||||||
- bpn
|
- bpn
|
||||||
- core
|
- core
|
||||||
|
- auth
|
||||||
|
|
||||||
when@dev:
|
when@dev:
|
||||||
monolog:
|
monolog:
|
||||||
@@ -10,12 +11,17 @@ when@dev:
|
|||||||
database:
|
database:
|
||||||
type: service
|
type: service
|
||||||
id: App\Logger\DatabaseHandler
|
id: App\Logger\DatabaseHandler
|
||||||
channels: ["core", "bpn"]
|
channels: ["core", "bpn", "auth"]
|
||||||
bpn:
|
bpn:
|
||||||
type: stream
|
type: stream
|
||||||
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
|
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
|
||||||
level: debug
|
level: debug
|
||||||
channels: ["bpn"]
|
channels: ["bpn"]
|
||||||
|
auth:
|
||||||
|
type: stream
|
||||||
|
path: "%kernel.logs_dir%/%kernel.environment%.auth.log"
|
||||||
|
level: debug
|
||||||
|
channels: ["auth"]
|
||||||
core:
|
core:
|
||||||
type: stream
|
type: stream
|
||||||
path: "%kernel.logs_dir%/%kernel.environment%.core.log"
|
path: "%kernel.logs_dir%/%kernel.environment%.core.log"
|
||||||
@@ -25,7 +31,7 @@ when@dev:
|
|||||||
type: stream
|
type: stream
|
||||||
path: "%kernel.logs_dir%/%kernel.environment%.log"
|
path: "%kernel.logs_dir%/%kernel.environment%.log"
|
||||||
level: debug
|
level: debug
|
||||||
channels: ["!event", "!bpn", "!core"]
|
channels: ["!event", "!bpn", "!core", "!auth"]
|
||||||
# uncomment to get logging in your browser
|
# uncomment to get logging in your browser
|
||||||
# you may have to allow bigger header sizes in your Web server configuration
|
# you may have to allow bigger header sizes in your Web server configuration
|
||||||
#firephp:
|
#firephp:
|
||||||
@@ -59,13 +65,18 @@ when@prod:
|
|||||||
database:
|
database:
|
||||||
type: service
|
type: service
|
||||||
id: App\Logger\DatabaseHandler
|
id: App\Logger\DatabaseHandler
|
||||||
channels: ["core", "bpn"]
|
channels: ["core", "bpn", "auth"]
|
||||||
bpn:
|
bpn:
|
||||||
type: rotating_file
|
type: rotating_file
|
||||||
max_files: 7
|
max_files: 7
|
||||||
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
|
path: "%kernel.logs_dir%/%kernel.environment%.bpn.log"
|
||||||
level: info
|
level: info
|
||||||
channels: ["bpn"]
|
channels: ["bpn"]
|
||||||
|
auth:
|
||||||
|
type: stream
|
||||||
|
path: "%kernel.logs_dir%/%kernel.environment%.auth.log"
|
||||||
|
level: debug
|
||||||
|
channels: ["auth"]
|
||||||
core:
|
core:
|
||||||
type: rotating_file
|
type: rotating_file
|
||||||
max_files: 7
|
max_files: 7
|
||||||
@@ -78,7 +89,7 @@ when@prod:
|
|||||||
handler: nested
|
handler: nested
|
||||||
excluded_http_codes: [404, 405]
|
excluded_http_codes: [404, 405]
|
||||||
buffer_size: 50 # How many messages should be saved? Prevent memory leaks
|
buffer_size: 50 # How many messages should be saved? Prevent memory leaks
|
||||||
channels: ["!bpn", "!core"]
|
channels: ["!bpn", "!core", "!auth"]
|
||||||
nested:
|
nested:
|
||||||
type: rotating_file
|
type: rotating_file
|
||||||
path: "%kernel.logs_dir%/%kernel.environment%.framework.log"
|
path: "%kernel.logs_dir%/%kernel.environment%.framework.log"
|
||||||
|
|||||||
@@ -4,20 +4,26 @@ namespace App\EventListener;
|
|||||||
|
|
||||||
use Psr\Log\LoggerInterface;
|
use Psr\Log\LoggerInterface;
|
||||||
use Symfony\Bundle\SecurityBundle\Security;
|
use Symfony\Bundle\SecurityBundle\Security;
|
||||||
use Symfony\Component\EventDispatcher\Attribute\AsEventListener;
|
use Symfony\Component\EventDispatcher\EventSubscriberInterface;
|
||||||
use Symfony\Component\HttpKernel\Event\ExceptionEvent;
|
use Symfony\Component\HttpKernel\Event\ExceptionEvent;
|
||||||
use Symfony\Component\HttpKernel\KernelEvents;
|
use Symfony\Component\HttpKernel\KernelEvents;
|
||||||
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
|
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
|
||||||
|
|
||||||
#[AsEventListener(event: KernelEvents::EXCEPTION, method: 'onKernelException', priority: 2)]
|
class AccessDeniedListener implements EventSubscriberInterface
|
||||||
class AccessDeniedListener
|
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly Security $security,
|
private readonly Security $security,
|
||||||
private readonly LoggerInterface $logger,
|
private readonly LoggerInterface $authLogger,
|
||||||
) {
|
) {
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public static function getSubscribedEvents(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
KernelEvents::EXCEPTION => ['onKernelException', 2],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
public function onKernelException(ExceptionEvent $event): void
|
public function onKernelException(ExceptionEvent $event): void
|
||||||
{
|
{
|
||||||
$exception = $event->getThrowable();
|
$exception = $event->getThrowable();
|
||||||
@@ -33,7 +39,7 @@ class AccessDeniedListener
|
|||||||
if (in_array($route, ['oauth2_authorize', 'oauth2_token'])) {
|
if (in_array($route, ['oauth2_authorize', 'oauth2_token'])) {
|
||||||
$request->getSession()->getFlashBag()->add('info', 'Bitte melde dich an.');
|
$request->getSession()->getFlashBag()->add('info', 'Bitte melde dich an.');
|
||||||
|
|
||||||
$this->logger->info('OAuth2 authorization request', [
|
$this->authLogger->info('OAuth2 authorization request', [
|
||||||
'uri' => $request->getRequestUri(),
|
'uri' => $request->getRequestUri(),
|
||||||
]);
|
]);
|
||||||
|
|
||||||
@@ -48,7 +54,7 @@ class AccessDeniedListener
|
|||||||
$request->getSession()->remove('_security.main.target_path');
|
$request->getSession()->remove('_security.main.target_path');
|
||||||
}
|
}
|
||||||
|
|
||||||
$this->logger->warning('Access denied', [
|
$this->authLogger->warning('Access denied', [
|
||||||
'uri' => $request->getRequestUri(),
|
'uri' => $request->getRequestUri(),
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ class BpnAuthenticator extends AbstractLoginFormAuthenticator implements Authent
|
|||||||
private readonly ApiClient $apiClient,
|
private readonly ApiClient $apiClient,
|
||||||
private readonly EntityManagerInterface $entityManager,
|
private readonly EntityManagerInterface $entityManager,
|
||||||
private readonly Crypt $crypt,
|
private readonly Crypt $crypt,
|
||||||
private readonly LoggerInterface $logger,
|
private readonly LoggerInterface $authLogger,
|
||||||
) {
|
) {
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -106,7 +106,7 @@ class BpnAuthenticator extends AbstractLoginFormAuthenticator implements Authent
|
|||||||
|
|
||||||
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
|
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
|
||||||
{
|
{
|
||||||
$this->logger->info('Login', [
|
$this->authLogger->info('Login', [
|
||||||
'email' => $token->getUserIdentifier(),
|
'email' => $token->getUserIdentifier(),
|
||||||
]);
|
]);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user