spring-projects / spring-projects/spring-data-rest

Security Issue - @PreAuthorize not respected from parent repo method declaration for save() [DATAREST-1134]

Open
#1,494 1 comment 0 reactions 1 assignee View on GitHub

@odrotbohm is already working on this.

Since Dec 31, 2020.

in: repository type: bug
Dominant language
Java
Stars
958
Forks
568
PR merge metrics
No merged PRs in 30d

Description

Joseph Valerio opened DATAREST-1134 and commented

@PreAuthorize not respected from parent repo method declaration for save()

If I create a parent Repo with @PreAuthorize annotations, all methods fire the SPEL function I have declared, except save(). If I re-declare the save method on the child Repo, then the SPEL function fires. I tried to debug this, but was eating way too much time. To me it seems that whatever is creating the Dynamic Proxies for the @PreAuthorize is missing the save().

here is a test project. Bar Repo works, and Foo Repo does not. The only difference is that Bar Repo re-declares the save method with its @PreAuthorize annotation.

Github instance for test:
https://github.com/joevalerio/DATAREST-1134.git

Created SPR-16103 to track the issue which is with the BridgeMethodResolver


Affects: 2.6.7 (Ingalls SR7)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.