Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/docs/en/architecture/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -260,6 +260,7 @@ Location: `api-server/conf/application.yaml`
| casdoor.organization-name | | organization name in Casdoor |
| casdoor.application-name | | application name in Casdoor |
| casdoor.redirect-url | | doplhinscheduler login url |
| api.session-timeout | 2h | login session lifetime measured from login time; accepts a Duration (e.g. 30m, 12h, 1d) |
| api.traffic.control.global.switch | false | traffic control global switch |
| api.traffic.control.max-global-qps-rate | 300 | global max request number per second |
| api.traffic.control.tenant-switch | false | traffic control tenant switch |
Expand Down
1 change: 1 addition & 0 deletions docs/docs/zh/architecture/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -260,6 +260,7 @@ common.properties配置文件目前主要是配置hadoop/s3/yarn/applicationId
| casdoor.organization-name | | Casdoor中的组织名称 |
| casdoor.application-name | | Casdoor中的应用名称 |
| casdoor.redirect-url | | dolphinscheduler登录URL |
| api.session-timeout | 2h | 登录会话有效期,从登录时刻开始计算,支持 Duration 格式(如 30m、12h、1d) |
| api.traffic.control.global.switch | false | 流量控制全局开关 |
| api.traffic.control.max-global-qps-rate | 300 | 全局最大请求数/秒 |
| api.traffic.control.tenant-switch | false | 流量控制租户开关 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@

import org.apache.commons.lang3.StringUtils;

import java.time.Duration;
import java.util.HashMap;
import java.util.Map;

Expand All @@ -44,6 +45,7 @@ public class ApiConfig implements Validator {
private String baseUrl;
private String uiUrl;
private boolean auditEnable = false;
private Duration sessionTimeout = Duration.ofHours(2);

private TrafficConfiguration trafficControl = new TrafficConfiguration();

Expand All @@ -57,6 +59,7 @@ public boolean supports(Class<?> clazz) {
@Override
public void validate(Object target, Errors errors) {
validatePythonGateway(errors);
validateSessionTimeout(errors);
printConfig();
}

Expand All @@ -66,10 +69,17 @@ private void validatePythonGateway(Errors errors) {
}
}

private void validateSessionTimeout(Errors errors) {
if (sessionTimeout.isZero() || sessionTimeout.isNegative()) {
errors.rejectValue("sessionTimeout", null, "should be positive");
}
}

private void printConfig() {
log.info("API config: baseUrl -> {} ", baseUrl);
log.info("API config: uiUrl -> {} ", uiUrl);
log.info("API config: auditEnable -> {} ", auditEnable);
log.info("API config: sessionTimeout -> {} ", sessionTimeout);
log.info("API config: trafficControl -> {} ", trafficControl);
log.info("API config: pythonGateway -> {} ", pythonGateway);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@

package org.apache.dolphinscheduler.api.service.impl;

import org.apache.dolphinscheduler.api.configuration.ApiConfig;
import org.apache.dolphinscheduler.api.service.SessionService;
import org.apache.dolphinscheduler.common.constants.Constants;
import org.apache.dolphinscheduler.dao.entity.Session;
import org.apache.dolphinscheduler.dao.entity.User;
import org.apache.dolphinscheduler.dao.repository.SessionDao;
Expand Down Expand Up @@ -46,6 +46,9 @@ public class SessionServiceImpl extends BaseServiceImpl implements SessionServic
@Autowired
private SessionDao sessionDao;

@Autowired
private ApiConfig apiConfig;

@Override
public Session getSession(String sessionId) {
if (StringUtils.isBlank(sessionId)) {
Expand Down Expand Up @@ -94,7 +97,8 @@ public void expireSession(Integer userId) {

@Override
public boolean isSessionExpire(Session session) {
return System.currentTimeMillis() - session.getLastLoginTime().getTime() >= Constants.SESSION_TIME_OUT * 1000;
return System.currentTimeMillis() - session.getLastLoginTime().getTime() >= apiConfig.getSessionTimeout()
.toMillis();
}

}
3 changes: 3 additions & 0 deletions dolphinscheduler-api/src/main/resources/application.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,9 @@ api:
base-url: http://127.0.0.1:12345/dolphinscheduler
ui-url: http://127.0.0.1:5173
audit-enable: false
# The lifetime of a login session, measured from the moment the user logs in.
# Accepts a Duration, e.g. 30m, 12h, 1d. Defaults to 2h when unset.
session-timeout: 2h
# Traffic control, if you turn on this config, the maximum number of request/s will be limited.
# global max request number per second
# default tenant-level max request number
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,9 @@ public class LoginControllerTest extends AbstractControllerTest {
@Autowired
private SessionDao sessionDao;

@Autowired
private ApiConfig apiConfig;

@Test
public void testLogin() throws Exception {
MultiValueMap<String, String> paramsMap = new LinkedMultiValueMap<>();
Expand Down Expand Up @@ -143,7 +146,7 @@ public void testSignOut() throws Exception {
@Test
void testSignOutWithExpireSession() throws Exception {
final Session session = sessionDao.queryById(sessionId);
session.setLastLoginTime(new Date(System.currentTimeMillis() - Constants.SESSION_TIME_OUT * 1000 - 1));
session.setLastLoginTime(new Date(System.currentTimeMillis() - apiConfig.getSessionTimeout().toMillis() - 1));
sessionDao.updateById(session);

mockMvc.perform(post("/signOut")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,15 @@

package org.apache.dolphinscheduler.api.service;

import org.apache.dolphinscheduler.api.configuration.ApiConfig;
import org.apache.dolphinscheduler.api.service.impl.SessionServiceImpl;
import org.apache.dolphinscheduler.common.enums.UserType;
import org.apache.dolphinscheduler.common.utils.DateUtils;
import org.apache.dolphinscheduler.dao.entity.Session;
import org.apache.dolphinscheduler.dao.entity.User;
import org.apache.dolphinscheduler.dao.repository.SessionDao;

import java.time.Duration;
import java.util.ArrayList;
import java.util.Calendar;
import java.util.Date;
Expand All @@ -37,6 +39,7 @@
import org.mockito.InjectMocks;
import org.mockito.Mock;
import org.mockito.Mockito;
import org.mockito.Spy;
import org.mockito.junit.jupiter.MockitoExtension;

@ExtendWith(MockitoExtension.class)
Expand All @@ -48,10 +51,14 @@ public class SessionServiceTest {
@Mock
private SessionDao sessionDao;

@Spy
private ApiConfig apiConfig = new ApiConfig();

private String sessionId = "aaaaaaaaaaaaaaaaaa";

@BeforeEach
public void setUp() {
apiConfig.setSessionTimeout(Duration.ofHours(2));
}

@AfterEach
Expand Down Expand Up @@ -100,6 +107,19 @@ public void testExpireSession() {

}

@Test
public void testIsSessionExpireUsesConfiguredTimeout() {
apiConfig.setSessionTimeout(Duration.ofHours(1));

Session stillAlive = getSession();
stillAlive.setLastLoginTime(new Date(System.currentTimeMillis() - Duration.ofMinutes(30).toMillis()));
Assertions.assertFalse(sessionService.isSessionExpire(stillAlive));

Session expired = getSession();
expired.setLastLoginTime(new Date(System.currentTimeMillis() - Duration.ofMinutes(90).toMillis()));
Assertions.assertTrue(sessionService.isSessionExpire(expired));
}

private Session getSession() {
Session session = new Session();
session.setId(sessionId);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -248,8 +248,6 @@ public final class Constants {
*/
public static final String LOCALE_LANGUAGE = "language";

public static final int SESSION_TIME_OUT = 7200;

public static final int AUTHORIZE_WRITABLE_PERM = 7;

public static final String START_TIME = "start time";
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -260,6 +260,9 @@ alert:

api:
audit-enable: false
# The lifetime of a login session, measured from the moment the user logs in.
# Accepts a Duration, e.g. 30m, 12h, 1d. Defaults to 2h when unset.
session-timeout: 2h
# Traffic control, if you turn on this config, the maximum number of request/s will be limited.
# global max request number per second
# default tenant-level max request number
Expand Down
Loading