From 9dd6a5eb8f02d334388fd5e538e5679cbdf36a93 Mon Sep 17 00:00:00 2001 From: Luke Taylor Date: Fri, 23 Jul 2010 16:27:57 +0100 Subject: [PATCH] SEC-1499: Added some Javadoc and doc on the problems of using session-fixation protection with attributes that implement HttpSessionBindingListener. --- docs/manual/src/docbook/session-mgmt.xml | 8 ++++++-- .../session/SessionFixationProtectionStrategy.java | 12 ++++++++++++ 2 files changed, 18 insertions(+), 2 deletions(-) diff --git a/docs/manual/src/docbook/session-mgmt.xml b/docs/manual/src/docbook/session-mgmt.xml index 3bbe239e9e..64a9264127 100644 --- a/docs/manual/src/docbook/session-mgmt.xml +++ b/docs/manual/src/docbook/session-mgmt.xml @@ -57,8 +57,12 @@ -]]> - +]]> + Note that the use of the default, SessionFixationProtectionStrategy + may cause issues if you are storing beans in the session which implement + HttpSessionBindingListener, including Spring session-scoped + beans. See the Javadoc for this class for more information. +
Concurrency Control diff --git a/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java b/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java index 1d84114528..9beb1ce0b6 100644 --- a/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java +++ b/web/src/main/java/org/springframework/security/web/authentication/session/SessionFixationProtectionStrategy.java @@ -27,6 +27,18 @@ import org.springframework.security.web.WebAttributes; * invalidated and a new session created by calling {@link HttpServletRequest#getSession()}. *

* If concurrent session control is in use, then a SessionRegistry must be injected. + *

+ *

Issues with HttpSessionBindingListener

+ *

+ * The migration of existing attributes to the newly-created session may cause problems if any of the objects + * implement the {@code HttpSessionBindingListener} interface in a way which makes assumptions about the life-cycle of + * the object. An example is the use of Spring session-scoped beans, where the initial removal of the bean from the + * session will cause the {@code DisposableBean} interface to be invoked, in the assumption that the bean is no longer + * required. + *

+ * We'd recommend that you take account of this when designing your application and do not store attributes which + * may not function correctly when they are removed and then placed back in the session. Alternatively, you should + * customize the {@code SessionAuthenticationStrategy} to deal with the issue in an application-specific way. * * @author Luke Taylor * @since 3.0