Repository navigation
feat(auth): 新增 auth-refresh-token 模块(可轮换的 Refresh Token 登录会话) - #25
Merged
Merged
Conversation
Charles7c
force-pushed
the
feat/auth-refresh-token
branch
11 times, most recently
from
October 3, 2026 16:04
8690381 to
82e28d7
Compare
- 新增 RegexpSingleline 规则:Javadoc 一律展开为多行,禁止单行写法 - 补齐 core / encrypt / json 模块存量单行 Javadoc - JavadocMethod 的 allowMissingParamTags、allowMissingReturnTag 暂保持 true,存量约 457 处待专项补齐后再收紧 Assisted-by: WorkBuddy
浏览器多标签页共用同一客户端 ID 时,默认 DAO 以 Key 为唯一维度、后建连接覆盖前者, 既无法按 Key 全量推送,也无法在撤销时全量关闭。 - WebSocketSessionDao 新增 listByKey 默认方法:单连接实现返回至多一条会话,多标签页实现返回全部存活连接 - WebSocketUtils 新增 sendMessageToAll,按客户端 Key 对全部存活连接逐一投递 - 不改动既有 sendMessage 语义,避免对存量使用方的破坏性变更 Assisted-by: WorkBuddy
Charles7c
force-pushed
the
feat/auth-refresh-token
branch
from
October 3, 2026 16:49
82e28d7 to
7469c0e
Compare
从 continew-admin#229 的 continew-auth-refresh 模块抽取,落地为 starter 认证家族新成员, 配合 continew-admin 4.2.0 发布(admin 侧后续 PR 删除自有模块并切换为依赖本模块)。 会话模型: - sessionId.secret 无状态令牌:服务端只存 secret 的 HMAC-SHA256 指纹并常量时间比对,Redis 泄露不暴露可用令牌 - HKDF-SHA256 分离指纹密钥与快照加密密钥;AES-256-GCM 加密轮换快照,崩溃后可恢复同一组令牌 - R0→R1 原子轮换由指纹门禁完成;宽限期(默认 30 秒,覆盖弱网重试)内并发/重复请求幂等返回首次结果 - 宽限期外的上一代令牌视为明确重放,撤销整个登录会话(OAuth 2.0 Security BCP / RFC 9700 §4.14) - 统一撤销收敛于「策略锁 → 会话锁」固定顺序,撤销后经 Redisson RTopic 广播关闭对应 WebSocket 连接(多标签页语义) - Cookie 模式强制 Origin/Referer 白名单校验(含子域通配),SameSite=None 必须配合 Secure - 刷新限流默认使用连接对端地址,仅显式配置可信代理后解析 X-Forwarded-For(配置错误 fail-safe) - RefreshTokenService.refresh() 固化四步安全契约(resolve → 限流 → 来源校验 → 轮换),避免业务方漏调用导致防护静默失效 抽取边界(零业务实体依赖):业务方提供 RefreshSessionPrincipal、RefreshAccessTokenIssuer、RefreshClientPolicy。 其它: - 新增 67 个单元测试(starter 仓库首批),并显式固定 maven-surefire-plugin 版本 - 模块登记于 auth 聚合器、BOM、PropertiesConstants(continew-starter.refresh-token.*) Assisted-by: WorkBuddy
Charles7c
force-pushed
the
feat/auth-refresh-token
branch
from
October 4, 2026 01:59
7469c0e to
3fafa77
Compare
|
2 of 8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



变更类型
破坏性变更
变更目的
从 continew-admin#229 的
continew-auth-refresh模块抽取,落地为 starter 认证家族的新成员continew-starter-auth-refresh-token,配合 continew-admin 4.2.0 发布(admin 侧将在后续 PR 中删除自有模块、切换为依赖本模块)。为 Web、App 与小程序提供可轮换的 Refresh Token 登录态:缩短 Access Token 生命周期,过期后由 Refresh Token 安全恢复原登录会话,并支持跨端会话统一失效(强退、顶下线、密码修改、租户/客户端禁用)。
解决方案
会话模型(延续 admin#229 已评审设计)
sessionId.secret无状态令牌:服务端只存 secret 的 HMAC-SHA256 指纹并常量时间比对,Redis 泄露不暴露可用令牌SameSite=None必须配合SecureRefreshTokenService.refresh()固化四步安全契约(resolve → 限流 → 来源校验 → 轮换),避免业务方漏调用导致防护静默失效抽取边界(本模块零业务实体依赖)
RefreshSessionPrincipalRefreshAccessTokenIssuerIssuedAccessTokenRefreshClientPolicy模块返回统一的
RefreshIssueResult(含轮换幂等回放结果),由业务方映射为实际响应体;登录/刷新 HTTP 端点保留在业务系统侧。Starter 化改造
continew-starter.refresh-token.*,经AuthRefreshAutoConfiguration自动装配,continew-starter.refresh-token.enabled可整体关闭;装配顺序显式声明after = RedissonAutoConfiguration(Redis 为硬性依赖,缺失时整体跳过而非启动失败)WebSocketSessionDao新增listByKey默认方法、WebSocketUtils新增sendMessageToAll,不改动既有sendMessage语义;认证模块以多标签页 DAO 接管默认实现,撤销时可全量关闭@author/@since 2.17.0与 LGPL License Header;模块登记于 auth 聚合器、BOM、PropertiesConstants测试情况
./mvnw -B verify全仓构建通过:Enforcer / Spotless / Checkstyle(0 violations)/ SpotBugs(0 BugInstance)四道门禁全绿Changelog
listByKey与sendMessageToAll提交前确认
./mvnw verify四道门禁全部通过(被 Spotless 拦截时使用-Pformat修复)Assisted-by: <智能体>标记