Commit a3bcb277 authored by Madhura Bhave's avatar Madhura Bhave

Add message to response body for Cloud Foundry security error

See gh-7108
parent 8e160d7f
...@@ -24,6 +24,7 @@ import org.apache.commons.logging.LogFactory; ...@@ -24,6 +24,7 @@ import org.apache.commons.logging.LogFactory;
import org.springframework.boot.actuate.cloudfoundry.CloudFoundryAuthorizationException.Reason; import org.springframework.boot.actuate.cloudfoundry.CloudFoundryAuthorizationException.Reason;
import org.springframework.boot.actuate.endpoint.mvc.MvcEndpoint; import org.springframework.boot.actuate.endpoint.mvc.MvcEndpoint;
import org.springframework.http.MediaType;
import org.springframework.util.StringUtils; import org.springframework.util.StringUtils;
import org.springframework.web.cors.CorsUtils; import org.springframework.web.cors.CorsUtils;
import org.springframework.web.method.HandlerMethod; import org.springframework.web.method.HandlerMethod;
...@@ -74,6 +75,9 @@ class CloudFoundrySecurityInterceptor extends HandlerInterceptorAdapter { ...@@ -74,6 +75,9 @@ class CloudFoundrySecurityInterceptor extends HandlerInterceptorAdapter {
} }
catch (CloudFoundryAuthorizationException ex) { catch (CloudFoundryAuthorizationException ex) {
this.logger.error(ex); this.logger.error(ex);
response.setContentType(MediaType.APPLICATION_JSON.toString());
response.getWriter()
.write("{\"security_error\":\"" + ex.getMessage() + "\"}");
response.setStatus(ex.getStatusCode().value()); response.setStatus(ex.getStatusCode().value());
return false; return false;
} }
......
...@@ -28,6 +28,7 @@ import org.springframework.boot.actuate.endpoint.AbstractEndpoint; ...@@ -28,6 +28,7 @@ import org.springframework.boot.actuate.endpoint.AbstractEndpoint;
import org.springframework.boot.actuate.endpoint.mvc.EndpointMvcAdapter; import org.springframework.boot.actuate.endpoint.mvc.EndpointMvcAdapter;
import org.springframework.http.HttpHeaders; import org.springframework.http.HttpHeaders;
import org.springframework.http.HttpStatus; import org.springframework.http.HttpStatus;
import org.springframework.http.MediaType;
import org.springframework.mock.web.MockHttpServletRequest; import org.springframework.mock.web.MockHttpServletRequest;
import org.springframework.mock.web.MockHttpServletResponse; import org.springframework.mock.web.MockHttpServletResponse;
import org.springframework.util.Base64Utils; import org.springframework.util.Base64Utils;
...@@ -87,6 +88,9 @@ public class CloudFoundrySecurityInterceptorTests { ...@@ -87,6 +88,9 @@ public class CloudFoundrySecurityInterceptorTests {
assertThat(preHandle).isFalse(); assertThat(preHandle).isFalse();
assertThat(this.response.getStatus()) assertThat(this.response.getStatus())
.isEqualTo(Reason.MISSING_AUTHORIZATION.getStatus().value()); .isEqualTo(Reason.MISSING_AUTHORIZATION.getStatus().value());
assertThat(this.response.getContentAsString()).contains("security_error");
assertThat(this.response.getContentType())
.isEqualTo(MediaType.APPLICATION_JSON.toString());
} }
@Test @Test
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment