Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ plugins {
}

group = 'com.flexcodelabs'
version = '0.0.77'
version = '0.0.78'
description = 'Flextuma App'

java {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
package com.flexcodelabs.flextuma.core.repositories;

import com.flexcodelabs.flextuma.core.entities.auth.PersonalAccessToken;
import org.springframework.data.jpa.repository.Query;
import org.springframework.data.repository.query.Param;
import org.springframework.stereotype.Repository;

import java.util.Optional;
Expand All @@ -9,5 +11,12 @@
@Repository
public interface PersonalAccessTokenRepository extends BaseRepository<PersonalAccessToken, UUID>,
org.springframework.data.jpa.repository.JpaSpecificationExecutor<PersonalAccessToken> {
Optional<PersonalAccessToken> findByToken(String token);

// Mirrors UserRepository#findByUsername's eager fetch: PatAuthenticationFilter walks
// pat.getUser().getRoles()...getPrivileges() outside any transaction, so roles/privileges
// must be loaded here, before this call's own short-lived session closes
// (spring.jpa.open-in-view=false) -- otherwise that walk throws
// "could not initialize proxy - no session".
@Query("SELECT p FROM PersonalAccessToken p LEFT JOIN FETCH p.user u LEFT JOIN FETCH u.roles LEFT JOIN FETCH u.roles.privileges WHERE p.token = :token")
Optional<PersonalAccessToken> findByToken(@Param("token") String token);
}
Original file line number Diff line number Diff line change
Expand Up @@ -255,13 +255,15 @@ public User updateProfile(String currentUsername, ProfileUpdateDto request) {
}

public User changePassword(User user, String newPassword) {
User managedUser = repository.findById(user.getId())
.orElseThrow(() -> new ResponseStatusException(HttpStatus.NOT_FOUND, "User not found"));
// Mutate the caller's already-loaded user rather than re-fetching via plain findById:
// that eager-loads roles/privileges (see UserRepository#findByUsername), while a plain
// findById would return a fresh instance with roles as an uninitialized lazy proxy --
// AuthController#changePassword serializes it via UserResponseDto.fromUser() right after
// this returns, outside any session (spring.jpa.open-in-view=false), which would 500.
user.setPassword(passwordEncoder.encode(newPassword));
user.setChangePassword(false);

managedUser.setPassword(passwordEncoder.encode(newPassword));
managedUser.setChangePassword(false);

return repository.save(managedUser);
return repository.save(user);
}

}
Original file line number Diff line number Diff line change
Expand Up @@ -220,25 +220,27 @@ void delete_shouldThrowException_whenUserIsSystem() {
}

@Test
void changePassword_shouldEncodeAndSaveManagedUser() {
void changePassword_shouldEncodeAndSaveTheGivenUser_withoutRefetching() {
// The caller (AuthController) already loaded this user with roles/privileges eager-
// fetched (UserRepository#findByUsername) and serializes it right after this call
// returns, outside any transaction (spring.jpa.open-in-view=false). Re-fetching via a
// plain findById here would hand back a fresh instance with roles as an uninitialized
// lazy proxy, so this must mutate and save the given instance directly.
UUID id = UUID.randomUUID();
User detachedUser = new User();
detachedUser.setId(id);

User managedUser = new User();
managedUser.setId(id);
managedUser.setChangePassword(true);
User user = new User();
user.setId(id);
user.setChangePassword(true);

when(repository.findById(id)).thenReturn(Optional.of(managedUser));
when(passwordEncoder.encode("new-password")).thenReturn("encoded-password");
when(repository.save(managedUser)).thenReturn(managedUser);
when(repository.save(user)).thenReturn(user);

User result = service.changePassword(detachedUser, "new-password");
User result = service.changePassword(user, "new-password");

assertSame(managedUser, result);
assertEquals("encoded-password", managedUser.getPassword());
assertFalse(Boolean.TRUE.equals(managedUser.getChangePassword()));
verify(repository).save(managedUser);
assertSame(user, result);
assertEquals("encoded-password", user.getPassword());
assertFalse(Boolean.TRUE.equals(user.getChangePassword()));
verify(repository, never()).findById(any());
verify(repository).save(user);
}

private void mockPermissions(Set<String> permissions) {
Expand Down