SEC-1396: Implement eager saving of SecurityContext in SessionManagementFilter on authentication.
The user is then seen as being authenticated to further (re-entrant) requests which occur before the existing request has completed. The saving logic is contained with the SecurityContextRepository implementation.
This commit is contained in:
+3
-3
@@ -98,7 +98,7 @@ public class HttpSessionSecurityContextRepository implements SecurityContextRepo
|
||||
}
|
||||
|
||||
public void saveContext(SecurityContext context, HttpServletRequest request, HttpServletResponse response) {
|
||||
SaveToSessionResponseWrapper responseWrapper = (SaveToSessionResponseWrapper)response;
|
||||
SaveContextOnUpdateOrErrorResponseWrapper responseWrapper = (SaveContextOnUpdateOrErrorResponseWrapper)response;
|
||||
// saveContext() might already be called by the response wrapper
|
||||
// if something in the chain called sendError() or sendRedirect(). This ensures we only call it
|
||||
// once per request.
|
||||
@@ -289,7 +289,7 @@ public class HttpSessionSecurityContextRepository implements SecurityContextRepo
|
||||
* Stores the necessary state from the start of the request in order to make a decision about whether
|
||||
* the security context has changed before saving it.
|
||||
*/
|
||||
class SaveToSessionResponseWrapper extends SaveContextOnUpdateOrErrorResponseWrapper {
|
||||
final class SaveToSessionResponseWrapper extends SaveContextOnUpdateOrErrorResponseWrapper {
|
||||
|
||||
private HttpServletRequest request;
|
||||
private boolean httpSessionExistedAtStartOfRequest;
|
||||
@@ -327,7 +327,7 @@ public class HttpSessionSecurityContextRepository implements SecurityContextRepo
|
||||
*
|
||||
*/
|
||||
@Override
|
||||
void saveContext(SecurityContext context) {
|
||||
protected void saveContext(SecurityContext context) {
|
||||
// See SEC-776
|
||||
if (authenticationTrustResolver.isAnonymous(context.getAuthentication())) {
|
||||
if (logger.isDebugEnabled()) {
|
||||
|
||||
+1
-1
@@ -42,7 +42,7 @@ public abstract class SaveContextOnUpdateOrErrorResponseWrapper extends HttpServ
|
||||
*
|
||||
* @param context the <tt>SecurityContext</tt> instance to store
|
||||
*/
|
||||
abstract void saveContext(SecurityContext context);
|
||||
protected abstract void saveContext(SecurityContext context);
|
||||
|
||||
/**
|
||||
* Makes sure the session is updated before calling the
|
||||
|
||||
+3
@@ -78,6 +78,9 @@ public class SessionManagementFilter extends GenericFilterBean {
|
||||
|
||||
return;
|
||||
}
|
||||
// Eagerly save the security context to make it available for any possible re-entrant
|
||||
// requests which may occur before the current request completes. SEC-1396.
|
||||
securityContextRepository.saveContext(SecurityContextHolder.getContext(), request, response);
|
||||
} else {
|
||||
// No security context or authentication present. Check for a session timeout
|
||||
if (request.getRequestedSessionId() != null && !request.isRequestedSessionIdValid()) {
|
||||
|
||||
Reference in New Issue
Block a user