diff --git a/docs/manual/src/docbook/session-mgmt.xml b/docs/manual/src/docbook/session-mgmt.xml index 3bbe239e9e..64a9264127 100644 --- a/docs/manual/src/docbook/session-mgmt.xml +++ b/docs/manual/src/docbook/session-mgmt.xml @@ -57,8 +57,12 @@ -]]> - +]]> + Note that the use of the default, SessionFixationProtectionStrategy + may cause issues if you are storing beans in the session which implement + HttpSessionBindingListener, including Spring session-scoped + beans. See the Javadoc for this class for more information. +
Concurrency Control diff --git a/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java b/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java index 1d84114528..9beb1ce0b6 100644 --- a/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java +++ b/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java @@ -27,6 +27,18 @@ import org.springframework.security.web.WebAttributes; * invalidated and a new session created by calling {@link HttpServletRequest#getSession()}. *

* If concurrent session control is in use, then a SessionRegistry must be injected. + *

+ *

Issues with HttpSessionBindingListener

+ *

+ * The migration of existing attributes to the newly-created session may cause problems if any of the objects + * implement the {@code HttpSessionBindingListener} interface in a way which makes assumptions about the life-cycle of + * the object. An example is the use of Spring session-scoped beans, where the initial removal of the bean from the + * session will cause the {@code DisposableBean} interface to be invoked, in the assumption that the bean is no longer + * required. + *

+ * We'd recommend that you take account of this when designing your application and do not store attributes which + * may not function correctly when they are removed and then placed back in the session. Alternatively, you should + * customize the {@code SessionAuthenticationStrategy} to deal with the issue in an application-specific way. * * @author Luke Taylor * @since 3.0