You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JHipster:邮箱密码登录缓存异常问题求助

JHipster v4.13.1: Duplicate Login Access After Email Update (Cache Issue)

Hey there, let's break down why both your old and new email addresses are working for login after updating the user's email, even though you've got cache eviction code in place.

First, Let's Recap Your Scenario

  • You're using JHipster v4.13.1 with JWT authentication, Ehcache for Spring caching, and H2 disk-persisted dev DB
  • Steps to reproduce:
    1. Log in as user@localhost
    2. Update email to user2@localhost via account settings
    3. Log out, then find both user@localhost and user2@localhost can still log in
  • You added temporary cache eviction code in DomainUserDetailsService.loadUserByUsername(), but the UserService.updateUser() already has cache clearing logic

Likely Root Cause: Missing Eviction for the Old Email in UserService

The most common issue here is that your updateUser() method is only clearing cache entries tied to the new email or the user's login, but not the old email that was replaced. Here's why that matters:

When you update the user's email from user@localhost to user2@localhost, the USERS_BY_EMAIL_CACHE still holds an entry mapping user@localhost to the user record. When you try to log in with the old email, the system pulls that stale cache entry instead of checking the updated DB record.

Check Your UserService.updateUser() Code

Chances are your current code looks something like this (only evicting the new email and login):

// Current (incomplete) code
cacheManager.getCache(UserRepository.USERS_BY_LOGIN_CACHE).evict(user.getLogin());
cacheManager.getCache(UserRepository.USERS_BY_EMAIL_CACHE).evict(user.getEmail());

This misses clearing the old email's cache entry. You need to fetch the original user's data before updating, then evict the old email:

// Corrected code
// Fetch the existing user record to get the old email
User existingUser = userRepository.findOne(user.getId());

// Evict the old email from the email cache
cacheManager.getCache(UserRepository.USERS_BY_EMAIL_CACHE).evict(existingUser.getEmail());
// Evict the login from the login cache
cacheManager.getCache(UserRepository.USERS_BY_LOGIN_CACHE).evict(existingUser.getLogin());

// Optional: Evict the new email too, just in case there's any stale entry
cacheManager.getCache(UserRepository.USERS_BY_EMAIL_CACHE).evict(user.getEmail());

Other Possible Checks

  1. Verify Cache Name Consistency: Make sure the constants UserRepository.USERS_BY_LOGIN_CACHE and UserRepository.USERS_BY_EMAIL_CACHE exactly match the cache names defined in your Ehcache configuration file (e.g., ehcache.xml). A mismatch means your eviction calls are targeting non-existent caches.
  2. Check JWT Token Expiry: While you mentioned logging out, double-check that your JWT tokens are properly invalidated on logout. Though this is less likely to cause the post-logout login issue, it's worth ruling out.
  3. Cache Monitoring: Add debug logs in updateUser() to confirm that cache eviction is actually running. For example:
    Cache emailCache = cacheManager.getCache(UserRepository.USERS_BY_EMAIL_CACHE);
    if (emailCache != null) {
        emailCache.evict(existingUser.getEmail());
        log.debug("Evicted old email {} from USERS_BY_EMAIL_CACHE", existingUser.getEmail());
    } else {
        log.error("USERS_BY_EMAIL_CACHE not found!");
    }
    

Why Your Temporary Fix Works

Your code in DomainUserDetailsService.loadUserByUsername() evicts the cache entry for the login/email being used at authentication time. This clears the stale entry right before fetching the user, so the system pulls the fresh DB record instead. However, this is a band-aid—fixing the eviction in updateUser() addresses the problem at its source.

内容的提问来源于stack exchange,提问作者Paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:18:20