diff --git a/lib/private/User/Session.php b/lib/private/User/Session.php index 672c8935efc6c..77ed5ccd098d6 100644 --- a/lib/private/User/Session.php +++ b/lib/private/User/Session.php @@ -455,7 +455,7 @@ public function logClientIn($user, } private function handleLoginFailed(IThrottler $throttler, int $currentDelay, string $remoteAddress, string $user, ?string $password) { - $this->logger->warning("Login failed: '" . $user . "' (Remote IP: '" . $remoteAddress . "')", ['app' => 'core']); + $this->logger->warning("Login failed: '" . $user . "' (Remote IP: '" . $remoteAddress . "')", ['app' => 'core', 'exception' => new \Exception()]); $throttler->registerAttempt('login', $remoteAddress, ['user' => $user]); $this->dispatcher->dispatchTyped(new OC\Authentication\Events\LoginFailed($user, $password)); @@ -702,7 +702,7 @@ private function getPassword($password) { * @param string $token * @return boolean */ - private function checkTokenCredentials(IToken $dbToken, $token) { + private function checkTokenCredentials(IToken $dbToken, $token, array &$reason) { // Check whether login credentials are still valid and the user was not disabled // This check is performed each 5 minutes $lastCheck = $dbToken->getLastCheck() ? : 0; @@ -715,12 +715,19 @@ private function checkTokenCredentials(IToken $dbToken, $token) { try { $pwd = $this->tokenProvider->getPassword($dbToken, $token); } catch (InvalidTokenException $ex) { + $reason = [ + 'exception' => $ex, + ]; + // An invalid token password was used -> log user out return false; } catch (PasswordlessTokenException $ex) { // Token has no password - if (!is_null($this->activeUser) && !$this->activeUser->isEnabled()) { + $reason = [ + 'exception' => $ex, + 'message' => 'Paswordless token exception with no active or disabled user', + ]; $this->tokenProvider->invalidateToken($token); return false; } @@ -731,12 +738,18 @@ private function checkTokenCredentials(IToken $dbToken, $token) { // Invalidate token if the user is no longer active if (!is_null($this->activeUser) && !$this->activeUser->isEnabled()) { $this->tokenProvider->invalidateToken($token); + $reason = [ + 'message' => 'Invalidate token as the user is no longer active', + ]; return false; } // If the token password is no longer valid mark it as such if ($this->manager->checkPassword($dbToken->getLoginName(), $pwd) === false) { $this->tokenProvider->markPasswordInvalid($dbToken, $token); + $reason = [ + 'message' => 'The token password is no longer valid', + ]; // User is logged out return false; } @@ -754,11 +767,9 @@ private function checkTokenCredentials(IToken $dbToken, $token) { * * Invalidates the token if checks fail * - * @param string $token - * @param string $user login name - * @return boolean + * @param ?string $user The login name */ - private function validateToken($token, $user = null) { + private function validateToken(string $token, ?string $user = null): bool { try { $dbToken = $this->tokenProvider->getToken($token); } catch (InvalidTokenException $ex) { @@ -774,11 +785,12 @@ private function validateToken($token, $user = null) { return false; } - if (!$this->checkTokenCredentials($dbToken, $token)) { - $this->logger->warning('Session token credentials are invalid', [ + $reason = []; + if (!$this->checkTokenCredentials($dbToken, $token, $reason)) { + $this->logger->warning('Session token credentials are invalid', array_merge($reason, [ 'app' => 'core', 'user' => $user, - ]); + ])); return false; }