Skip to content

PD-6046 PD-6045 PD-6045 PD-6046 PD-6044 PD-6042 PD-6043 PD-5850 add 2FA recovery phone number - #7655

Merged
amontenegro merged 12 commits into
mainfrom
lmendoa/PD-6046-PD-6045-2fa-recovery-phone
Sep 18, 2026
Merged

amontenegro merged 12 commits into
mainfrom
lmendoa/PD-6046-PD-6045-2fa-recovery-phone

Conversation

@cryptalith

Copy link
Copy Markdown
Member

No description provided.

@amontenegro

Copy link
Copy Markdown
Member

RedisClient hardcoded .ssl(true). A plaintext Redis does not reject a TLS
handshake, it simply never answers, so every connect blocked until the
socket read timed out: 20 s for the two 10 s-timeout clients and 40 s for
the 20 s one. Four clients are built per startup because web.xml builds the
Spring context twice, which is 120 s of a 148 s deploy.

Add a ssl constructor argument defaulting to true, wired through all four
bean definitions as ${...ssl.enabled:true}. Production keeps TLS with no
configuration change. This mirrors SessionCacheConfig, which already reads
...cache.session.redis.ssl.enabled with the same shape and the same default.

Turning TLS off then exposed a second defect: a blank password was still
passed to the Jedis config, so the client sent AUTH "" and an unauthenticated
Redis answered

  ERR AUTH <password> called without any password configured for the default user

which meant the pool never came up and the cache stayed silently disabled --
set() returning false and get() returning null for every caller. Treat a
blank or null password as "no authentication". A configured password is
unaffected.

Measured on an isolated Tomcat against the real WAR, with the context still
built twice and the original timeouts: startup 148.5 s -> 44.9 s, and three
Redis clients now connect successfully where none did before.

(cherry picked from commit 57c6a37)
@cryptalith cryptalith changed the title PD-6046 PD-6045 add 2FA recovery phone number PD-6046 PD-6045 PD-6045 PD-6046 PD-6044 PD-6042 PD-6043 PD-5850 add 2FA recovery phone number Sep 18, 2026
}

@Override
@Transactional

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove the @transactional as the transaction will be handled by the transactionTemplate


@Override
@SuppressWarnings("unchecked")
public ProfileRecoveryPhoneEntity findByOrcid(String orcid) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With the hibernate/hikari upgrade, we now need to specify the read only transaction as well, so, plaese add this annotation:

@transactional(value = "transactionManagerReadOnly", readOnly = true)

@amontenegro
amontenegro merged commit b6d6007 into main Sep 18, 2026
21 checks passed
@amontenegro
amontenegro deleted the lmendoa/PD-6046-PD-6045-2fa-recovery-phone branch September 18, 2026 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants