added security and fix edit profile

This commit is contained in:
SlimusMinus
2026-06-18 00:22:50 +03:00
parent 81e3e007e1
commit bafb636cbe
24 changed files with 418 additions and 56 deletions

View File

@@ -2,18 +2,20 @@ package com.krylov.refound.controller;
import com.krylov.refound.dto.AuthRequest;
import com.krylov.refound.dto.AuthResponse;
import com.krylov.refound.dto.CheckLoginDto;
import com.krylov.refound.dto.RegisterRequest;
import com.krylov.refound.dto.UserDto;
import com.krylov.refound.entity.User;
import com.krylov.refound.repository.UserRepository;
import com.krylov.refound.security.JwtService;
import java.util.Map;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
@RestController
@@ -23,6 +25,8 @@ import org.springframework.web.bind.annotation.RestController;
public class AuthController {
private final UserRepository userRepository;
private final PasswordEncoder passwordEncoder;
private final JwtService jwtService;
@PostMapping("/register")
public ResponseEntity<?> register(@RequestBody RegisterRequest request) {
@@ -38,18 +42,37 @@ public class AuthController {
User user = new User();
user.setName(request.getName());
user.setLogin(request.getLogin());
user.setPassword(request.getPassword()); // позже добавить BCrypt
user.setPassword(passwordEncoder.encode(request.getPassword()));
userRepository.save(user);
String token = "fake-jwt-token";
String token = jwtService.generateToken(user.getLogin());
return ResponseEntity.ok(new AuthResponse(token, user));
UserDto userDto = new UserDto(user.getId(), user.getName(), user.getLogin(), user.getEmail());
return ResponseEntity.ok(new AuthResponse(token, userDto));
}
@GetMapping("/check-login")
public ResponseEntity<?> checkLogin(@RequestParam String login) {
boolean exists = userRepository.existsByLogin(login);
@PostMapping("/login")
public ResponseEntity<?> login(@RequestBody AuthRequest request) {
User user = userRepository.findByLogin(request.getLogin())
.orElse(null);
if (user == null || !passwordEncoder.matches(request.getPassword(), user.getPassword())) {
return ResponseEntity
.badRequest()
.body(Map.of("message", "Неверный логин или пароль"));
}
String token = jwtService.generateToken(user.getLogin());
UserDto userDto = new UserDto(user.getId(), user.getName(), user.getLogin(), user.getEmail());
return ResponseEntity.ok(new AuthResponse(token, userDto));
}
@PostMapping("/check-login")
public ResponseEntity<?> checkLogin(@RequestBody CheckLoginDto request) {
boolean exists = userRepository.existsByLogin(request.getLogin());
return ResponseEntity.ok(Map.of("exists", exists));
}

View File

@@ -42,6 +42,11 @@ public class PostController {
return service.getFeed();
}
@GetMapping("/{id}")
public List<PostResponse> getById(@PathVariable Long id) {
return service.getById(id);
}
@PutMapping(value = "/{id}", consumes = MediaType.MULTIPART_FORM_DATA_VALUE)
public PostResponse update(
@PathVariable Long id,

View File

@@ -0,0 +1,30 @@
package com.krylov.refound.controller;
import com.krylov.refound.dto.UserResponseDto;
import com.krylov.refound.dto.UserUpdateDto;
import com.krylov.refound.service.UserService;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.ModelAttribute;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;
@RestController
@RequestMapping("/api/v1/users")
@Slf4j
@RequiredArgsConstructor
public class UserController {
private final UserService userService;
@PutMapping("/{id}")
public ResponseEntity<UserResponseDto> updateUser(@PathVariable Long id, @ModelAttribute UserUpdateDto userUpdateDto) {
log.info("updateUser, id={}", id);
UserResponseDto userResponseDto = userService.updateUser(id, userUpdateDto);
return ResponseEntity.ok(userResponseDto);
}
}

View File

@@ -9,5 +9,5 @@ import lombok.Data;
public class AuthResponse {
private String token;
private User user;
private UserDto user;
}

View File

@@ -0,0 +1,9 @@
package com.krylov.refound.dto;
import lombok.Data;
@Data
public class CheckLoginDto {
private String login;
private String password;
}

View File

@@ -22,4 +22,5 @@ public class PostResponse {
private String phone;
private List<String> images;
private boolean isFavorite;
private Long userId;
}

View File

@@ -0,0 +1,13 @@
package com.krylov.refound.dto;
import lombok.AllArgsConstructor;
import lombok.Data;
@Data
@AllArgsConstructor
public class UserDto {
private Long id;
private String name;
private String login;
private String email;
}

View File

@@ -0,0 +1,15 @@
package com.krylov.refound.dto;
import lombok.Builder;
import lombok.Data;
@Data
@Builder
public class UserResponseDto {
private Long id;
private String login;
private String name;
private String phone;
private String email;
private String avatar;
}

View File

@@ -0,0 +1,15 @@
package com.krylov.refound.dto;
import lombok.Data;
import org.springframework.web.multipart.MultipartFile;
@Data
public class UserUpdateDto {
private Long id;
private String login;
private String firstName;
private String lastName;
private String phone;
private String email;
private MultipartFile avatar;
}

View File

@@ -23,13 +23,16 @@ public class User {
@GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
private String name;
private String lastName;
@Column(unique = true)
private String login;
private String password;
private LocalDateTime createdAt;
private String email;
private String phone;
@Enumerated(EnumType.STRING)
private Role role = Role.USER;
private String avatarUrl;
@PrePersist
public void prePersist() {

View File

@@ -4,5 +4,7 @@ public enum ErrorCode {
VALIDATION_ERROR,
NOT_FOUND,
INTERNAL_ERROR,
BAD_REQUEST
BAD_REQUEST,
UNAUTHORIZED,
FORBIDDEN
}

View File

@@ -16,6 +16,7 @@ public interface PostMapper {
@Mapping(source = "category", target = "category", qualifiedByName = "stringToPostCategory")
Post toEntity(PostRequest request);
@Mapping(source = "user.id", target = "userId")
@Mapping(source = "user.login", target = "userEmail")
@Mapping(source = "images", target = "images", qualifiedByName = "imagesToUrls")
@Mapping(target = "category", expression = "java(post.getCategory().getDisplayName())")

View File

@@ -1,45 +1,12 @@
package com.krylov.refound.repository;
import com.krylov.refound.entity.Post;
import com.krylov.refound.enums.PostType;
import org.springframework.data.domain.Page;
import org.springframework.data.domain.Pageable;
import java.util.List;
import org.springframework.data.jpa.repository.JpaRepository;
import org.springframework.data.jpa.repository.JpaSpecificationExecutor;
import org.springframework.data.jpa.repository.Query;
import org.springframework.data.repository.query.Param;
public interface PostRepository extends JpaRepository<Post, Long>, JpaSpecificationExecutor<Post> {
Page<Post> findByType(PostType type, Pageable pageable);
@Query(value = """
SELECT * FROM Posts p
WHERE
(:type IS NULL OR p.type = :type)
AND (:city IS NULL OR p.city = :city)
AND (:category IS NULL OR p.category = :category)
AND (
:lat IS NULL OR :lng IS NULL OR :radius IS NULL OR
(
6371 * acos(
cos(radians(:lat)) * cos(radians(p.latitude)) *
cos(radians(p.longitude) - radians(:lng)) +
sin(radians(:lat)) * sin(radians(p.latitude))
)
) <= :radius
)
""",
countQuery = "SELECT count(*) FROM Posts p",
nativeQuery = true)
Page<Post> searchWithGeo(
@Param("type") String type,
@Param("city") String city,
@Param("category") String category,
@Param("lat") Double lat,
@Param("lng") Double lng,
@Param("radius") Double radius,
Pageable pageable
);
List<Post> findByUserId(Long userId);
}

View File

@@ -0,0 +1,50 @@
package com.krylov.refound.security;
import jakarta.servlet.FilterChain;
import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
import java.util.ArrayList;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.security.authentication.UsernamePasswordAuthenticationToken;
import org.springframework.security.core.context.SecurityContextHolder;
import org.springframework.security.web.authentication.WebAuthenticationDetailsSource;
import org.springframework.stereotype.Component;
import org.springframework.web.filter.OncePerRequestFilter;
@Component
@RequiredArgsConstructor
@Slf4j
public class JwtAuthenticationFilter extends OncePerRequestFilter {
private final JwtService jwtService;
@Override
protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException {
final String authHeader = request.getHeader("Authorization");
if (authHeader == null || !authHeader.startsWith("Bearer ")) {
filterChain.doFilter(request, response);
return;
}
final String token = authHeader.substring(7);
try {
if (jwtService.isTokenValid(token) && SecurityContextHolder.getContext().getAuthentication() == null) {
String login = jwtService.extractLogin(token);
UsernamePasswordAuthenticationToken authToken = new UsernamePasswordAuthenticationToken(login, null, new ArrayList<>());
authToken.setDetails(new WebAuthenticationDetailsSource().buildDetails(request));
SecurityContextHolder.getContext().setAuthentication(authToken);
}
} catch (Exception e) {
// Token invalid — continue as unauthenticated
}
filterChain.doFilter(request, response);
}
}

View File

@@ -0,0 +1,77 @@
package com.krylov.refound.security;
import io.jsonwebtoken.Claims;
import io.jsonwebtoken.Jwts;
import io.jsonwebtoken.security.Keys;
import java.nio.charset.StandardCharsets;
import java.util.Date;
import java.util.HashMap;
import java.util.Map;
import java.util.function.Function;
import javax.crypto.SecretKey;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.stereotype.Service;
@Service
public class JwtService {
@Value("${jwt.secret}")
private String secret;
@Value("${jwt.expiration}")
private long expiration;
public String generateToken(String login) {
Map<String, Object> claims = new HashMap<>();
return generateToken(claims, login);
}
public String generateToken(Map<String, Object> extraClaims, String login) {
return Jwts.builder()
.claims(extraClaims)
.subject(login)
.issuedAt(new Date(System.currentTimeMillis()))
.expiration(new Date(System.currentTimeMillis() + expiration))
.signWith(getSigningKey())
.compact();
}
public String extractLogin(String token) {
return extractClaim(token, Claims::getSubject);
}
public boolean isTokenValid(String token) {
try {
String login = extractLogin(token);
return login != null && !isTokenExpired(token);
} catch (Exception e) {
return false;
}
}
private boolean isTokenExpired(String token) {
return extractExpiration(token).before(new Date());
}
private Date extractExpiration(String token) {
return extractClaim(token, Claims::getExpiration);
}
private <T> T extractClaim(String token, Function<Claims, T> claimsResolver) {
final Claims claims = extractAllClaims(token);
return claimsResolver.apply(claims);
}
private Claims extractAllClaims(String token) {
return Jwts.parser()
.verifyWith(getSigningKey())
.build()
.parseSignedClaims(token)
.getPayload();
}
private SecretKey getSigningKey() {
byte[] keyBytes = secret.getBytes(StandardCharsets.UTF_8);
return Keys.hmacShaKeyFor(keyBytes);
}
}

View File

@@ -0,0 +1,45 @@
package com.krylov.refound.security;
import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configurers.AbstractHttpConfigurer;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter;
@Configuration
@EnableWebSecurity
@RequiredArgsConstructor
public class SecurityConfig {
private final JwtAuthenticationFilter jwtAuthenticationFilter;
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.csrf(AbstractHttpConfigurer::disable)
.sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.authorizeHttpRequests(auth -> auth
// Public endpoints
.requestMatchers("/api/v1/auth/**").permitAll()
.requestMatchers(org.springframework.http.HttpMethod.GET, "/api/v1/posts/**").permitAll()
.requestMatchers("/files/**", "/uploads/**").permitAll()
.requestMatchers("/ws/**").permitAll()
// All other endpoints require authentication
.anyRequest().authenticated()
)
.addFilterBefore(jwtAuthenticationFilter, UsernamePasswordAuthenticationFilter.class);
return http.build();
}
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
}

View File

@@ -0,0 +1,26 @@
package com.krylov.refound.service;
import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Path;
import java.nio.file.Paths;
import java.util.UUID;
import org.springframework.stereotype.Service;
import org.springframework.web.multipart.MultipartFile;
@Service
public class AvatarService {
private final Path uploadDir = Paths.get("uploads/avatars");
public String save(MultipartFile file) {
try {
Files.createDirectories(uploadDir);
String filename = UUID.randomUUID() + "_" + file.getOriginalFilename();
Path target = uploadDir.resolve(filename);
file.transferTo(target);
return "/uploads/avatars/" + filename; // или полный URL, если есть статик-сервер/CDN
} catch (IOException e) {
throw new RuntimeException("Failed to save avatar", e);
}
}
}

View File

@@ -36,7 +36,6 @@ public class PostService {
private final ImageRepository imageRepository;
private final NominatimService nominatimService;
@CacheEvict(value = "posts", allEntries = true)
public PostRequest create(PostRequest request, MultipartFile image) {
Post post = mapper.toEntity(request);
@@ -74,15 +73,10 @@ public class PostService {
}
@Cacheable(value = "post", key = "#id")
public PostResponse getById(Long id) {
Post post = repository.findById(id)
.orElseThrow(() -> new ApiException(ErrorCode.NOT_FOUND, "Post not found", HttpStatus.NOT_FOUND));
return mapper.toResponse(post);
public List <PostResponse> getById(Long id) {
return repository.findByUserId(id).stream().map(mapper::toResponse).toList();
}
@CacheEvict(value = {"posts", "post"}, allEntries = true)
public PostResponse update(Long id, PostRequest request, MultipartFile image) {
Post post = repository.findById(id)

View File

@@ -1,25 +1,80 @@
package com.krylov.refound.service;
import com.krylov.refound.dto.UserResponseDto;
import com.krylov.refound.dto.UserUpdateDto;
import com.krylov.refound.entity.User;
import com.krylov.refound.enums.ErrorCode;
import com.krylov.refound.exception.ApiException;
import com.krylov.refound.repository.UserRepository;
import jakarta.persistence.EntityNotFoundException;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.context.SecurityContextHolder;
import org.springframework.stereotype.Service;
import org.springframework.web.multipart.MultipartFile;
@Service
@Slf4j
@RequiredArgsConstructor
public class UserService {
private final UserRepository repository;
private final AvatarService avatarService;
public User getCurrentUser() {
Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
return repository.findByLogin("moscow_city231@rambler.ru")
if (authentication == null || authentication.getPrincipal() == null) {
throw new ApiException(
ErrorCode.UNAUTHORIZED,
"Пользователь не авторизован",
HttpStatus.UNAUTHORIZED
);
}
String login = (String) authentication.getPrincipal();
return repository.findByLogin(login)
.orElseThrow(() -> new ApiException(
ErrorCode.NOT_FOUND,
"User not found",
HttpStatus.NOT_FOUND
));
}
public UserResponseDto updateUser(Long id, UserUpdateDto dto) {
User user = repository.findById(id)
.orElseThrow(() -> new EntityNotFoundException("User not found"));
user.setName(dto.getFirstName());
user.setLogin(dto.getLastName());
user.setPhone(dto.getPhone());
user.setEmail(dto.getEmail());
user.setLogin(dto.getLogin());
MultipartFile avatar = dto.getAvatar();
if (avatar != null && !avatar.isEmpty()) {
String url = avatarService.save(avatar); // сохранение на диск/в S3/Yandex Object Storage
user.setAvatarUrl(url);
}
repository.save(user);
UserResponseDto userResponseDto = getUserResponseDto(user);
log.info("User updated: {}", userResponseDto);
return userResponseDto;
}
private static UserResponseDto getUserResponseDto(User user) {
return UserResponseDto.builder()
.id(user.getId())
.login(user.getLogin())
.name(user.getName())
.phone(user.getPhone())
.email(user.getEmail())
.avatar(user.getAvatarUrl())
.build();
}
}

View File

@@ -33,4 +33,8 @@ file:
upload-dir: uploads/
cache:
ttl: 300
ttl: 300
jwt:
secret: mySuperSecretKeyForJwtTokenGenerationThatIsLongEnough2024!ReFound
expiration: 86400000 # 24 hours in milliseconds

View File

@@ -0,0 +1,10 @@
databaseChangeLog:
- changeSet:
id: 004-add-lastName-phone
author: you
changes:
- addColumn:
tableName: users
columns:
- column: { name: last_name, type: VARCHAR(255) }
- column: { name: phone, type: VARCHAR(255) }

View File

@@ -0,0 +1,9 @@
databaseChangeLog:
- changeSet:
id: 005-add-user-avatarUrl
author: you
changes:
- addColumn:
tableName: users
columns:
- column: { name: avatar_url, type: VARCHAR(255) }

View File

@@ -11,4 +11,6 @@ databaseChangeLog:
- include: { file: db/changelog/alter/010-alter-user.yaml }
- include: { file: db/changelog/add/011-add-name-user.yaml }
- include: { file: db/changelog/add/012-add-email-role.yaml }
- include: { file: db/changelog/add/003-add-phone-posts.yaml }
- include: { file: db/changelog/add/003-add-phone-posts.yaml }
- include: { file: db/changelog/add/004-add-fields-user.yaml }
- include: { file: db/changelog/add/005-add-user-avatarUrl.yaml }