apache / apache/grails-core

GrailsRememberMeAuthenticationFilter causes POST/PUT/DELETE requests to redirect to GET request.

Open
#15,879 0 comments 0 reactions 0 assignees View on GitHub
relates-to:spring-security
Dominant language
Groovy
Stars
2.9k
Forks
975
Avg merge
1d 22h
Merged PRs (30d)
92

Description

I was unable to reopen this issue (https://github.com/grails-plugins/grails-spring-security-core/issues/364) so I created a new one.

I had this problem in grails 2.x and after upgrading to grails 3.3.10 (spring security core 3.2.3) I noticed that it still exists.

Everything mentioned in the original issue is still relevant. I created a small sample app that reproduces the issue. The app also contains a Postman config file.

### Task List

- [x] Steps to reproduce provided
- [ ] Stacktrace (if present) provided
- [x] Example that reproduces the problem uploaded to Github
- [x] Full description of the issue provided (see below)

### Steps to Reproduce

1. Have a mysql server running on localhost. Create a database called 'bugdb'
2. Have redis running on localhost. Sample app will put session data in database index 1
2. Run the server.
3. Call test/login endpoint to create a session in redis and remember-me token in persistent_login table in mysql.
4. Call test/test and test/testMultipart actions to verify that they work and that they return the request body in the response.
5. Open redis-cli, select database 1, call flushdb to remove the session
6. Call test/test endpoint again.

### Expected Behaviour

The response contains the request body like it did in the previous run

### Actual Behaviour

The response only contains the id of the newly created session, but the request body was empty.

### Environment Information

- **Operating System**: Macos 10.14.5
- **GORM Version:** 6.1.12.RELEASE
- **Grails Version (if using Grails):** 3.3.10
- **JDK Version:** jdk1.8.0_152

### Example Application

https://github.com/Macoshark/GrailsSpringSecurityRememberMeBug

Contributor guide

Open the contributing guide

Research direction

Run the linked sample application with MySQL and Redis, following the steps through test/login, test/test, and test/testMultipart, including flushing Redis database 1. Start at GrailsRememberMeAuthenticationFilter and compare the request-body response before and after the session is removed; done means the POST/PUT/DELETE request still returns its body after remember-me authentication.

Written by the indexing model from the issue text.

Assessment

Tech stack
groovy, mysql, redis, spring
Domain
authentication, backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.