Added additional logging for client auth signature validation failures. Also made sure to log this api call.

This commit is contained in:
Jeremy-Z 2026-05-26 11:17:33 -04:00
parent 98f0197b47
commit d0910cd1b5
2 changed files with 17 additions and 7 deletions

View file

@ -45,13 +45,7 @@ export default {
showIssLoadingModal(false);
return;
}
// Populate all the ISS Config values from the service call returns.
this.populateISSConfigValues(clientData);
// Session should only be created / validated on successful client tag validation to avoid unnecessary sessions for unauthorized users.
await analyticsMixin.methods.validateSession();
try {
// Check cookie
const issCookie = getISSCookie();
@ -119,6 +113,7 @@ export default {
return { isAuthorized: false };
}
// Set the client tag on thes store here so we can use it for logging if need be.
this.mainStore.issConfig.clientTag = clientTag;
const resp = await validateISSClientTag(clientTag);
@ -126,6 +121,12 @@ export default {
return { isAuthorized: false };
}
// Populate all the ISS Config values from the service call returns.
this.populateISSConfigValues(resp);
// Session should only be created / validated on successful client tag validation to avoid unnecessary sessions for unauthorized users.
await analyticsMixin.methods.validateSession();
let isAuthorized = false;
let clientData = null;
const decryptedParams = {};
@ -143,6 +144,11 @@ export default {
isAuthorized = vsigResp?.valid ?? false;
this.mainStore.issConfig.isAuthenticated = isAuthorized;
// Log the signature validation failure so we can monitor/alert on it.
if ( !isAuthorized ) {
global.$logger.logError(`[Entry Page] Client signature validation failed for Client Tag: ${clientTag} - Reason: ${vsigResp?.failureReason ?? ''} - Token: ${token} - Signature: ${signature}`);
}
} else {
isAuthorized = true;
}

View file

@ -2942,6 +2942,8 @@ export const useMainStore = defineStore({
issConfig.billToAccountNumber = billToInfo.toString();
},
// Do not log API call failure here since this is a validation call that can be spammy.
// Do not bailout because this is a fatal error here.
async validateClientTag(clientTag) {
return globalMethods.callHttpClient({
method: endpoints.ValidateClientTag.method,
@ -2958,11 +2960,13 @@ export const useMainStore = defineStore({
signature
};
// Log API call failure so we can monitor / alert on failed signature validations.
// Do not bailout because this is a fatal error here.
return await globalMethods.callHttpClient({
method: endpoints.ValidateClientSignature.method,
endpoint: endpoints.ValidateClientSignature.url,
payload,
logApiCall: false,
logApiCall: true,
bailoutOnError: false
});
},