spring-projects / spring-projects/spring-data-rest
Security Issue - @PreAuthorize not respected from parent repo method declaration for save() [DATAREST-1134]
@odrotbohm is already working on this.
Since Dec 31, 2020.
- Dominant language
- Java
- Stars
- 958
- Forks
- 568
- PR merge metrics
- No merged PRs in 30d
Description
Joseph Valerio opened DATAREST-1134 and commented
@PreAuthorize not respected from parent repo method declaration for save()
If I create a parent Repo with @PreAuthorize annotations, all methods fire the SPEL function I have declared, except save(). If I re-declare the save method on the child Repo, then the SPEL function fires. I tried to debug this, but was eating way too much time. To me it seems that whatever is creating the Dynamic Proxies for the @PreAuthorize is missing the save().
here is a test project. Bar Repo works, and Foo Repo does not. The only difference is that Bar Repo re-declares the save method with its @PreAuthorize annotation.
Github instance for test:
https://github.com/joevalerio/DATAREST-1134.git
Created SPR-16103 to track the issue which is with the BridgeMethodResolver
Affects: 2.6.7 (Ingalls SR7)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.