From d0910cd1b5ea27a5fe7c5cd58c40042383e662ba Mon Sep 17 00:00:00 2001 From: Jeremy-Z Date: Tue, 26 May 2026 11:17:33 -0400 Subject: [PATCH] Added additional logging for client auth signature validation failures. Also made sure to log this api call. --- src/layouts/entry-page/entry-page.vue | 18 ++++++++++++------ src/store/index.js | 6 +++++- 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/src/layouts/entry-page/entry-page.vue b/src/layouts/entry-page/entry-page.vue index 503827ac..7347e051 100644 --- a/src/layouts/entry-page/entry-page.vue +++ b/src/layouts/entry-page/entry-page.vue @@ -45,13 +45,7 @@ export default { showIssLoadingModal(false); return; } - - // Populate all the ISS Config values from the service call returns. - this.populateISSConfigValues(clientData); - // Session should only be created / validated on successful client tag validation to avoid unnecessary sessions for unauthorized users. - await analyticsMixin.methods.validateSession(); - try { // Check cookie const issCookie = getISSCookie(); @@ -119,6 +113,7 @@ export default { return { isAuthorized: false }; } + // Set the client tag on thes store here so we can use it for logging if need be. this.mainStore.issConfig.clientTag = clientTag; const resp = await validateISSClientTag(clientTag); @@ -126,6 +121,12 @@ export default { return { isAuthorized: false }; } + // Populate all the ISS Config values from the service call returns. + this.populateISSConfigValues(resp); + + // Session should only be created / validated on successful client tag validation to avoid unnecessary sessions for unauthorized users. + await analyticsMixin.methods.validateSession(); + let isAuthorized = false; let clientData = null; const decryptedParams = {}; @@ -143,6 +144,11 @@ export default { isAuthorized = vsigResp?.valid ?? false; this.mainStore.issConfig.isAuthenticated = isAuthorized; + + // Log the signature validation failure so we can monitor/alert on it. + if ( !isAuthorized ) { + global.$logger.logError(`[Entry Page] Client signature validation failed for Client Tag: ${clientTag} - Reason: ${vsigResp?.failureReason ?? ''} - Token: ${token} - Signature: ${signature}`); + } } else { isAuthorized = true; } diff --git a/src/store/index.js b/src/store/index.js index 6b6cd308..20bc7261 100644 --- a/src/store/index.js +++ b/src/store/index.js @@ -2942,6 +2942,8 @@ export const useMainStore = defineStore({ issConfig.billToAccountNumber = billToInfo.toString(); }, + // Do not log API call failure here since this is a validation call that can be spammy. + // Do not bailout because this is a fatal error here. async validateClientTag(clientTag) { return globalMethods.callHttpClient({ method: endpoints.ValidateClientTag.method, @@ -2958,11 +2960,13 @@ export const useMainStore = defineStore({ signature }; + // Log API call failure so we can monitor / alert on failed signature validations. + // Do not bailout because this is a fatal error here. return await globalMethods.callHttpClient({ method: endpoints.ValidateClientSignature.method, endpoint: endpoints.ValidateClientSignature.url, payload, - logApiCall: false, + logApiCall: true, bailoutOnError: false }); },