spring-projects / spring-projects/spring-security-kerberos
KerberosServiceAuthenticationProvider should convert GSSException
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 199
- Forks
- 222
- PR merge metrics
- No merged PRs in 30d
Description
In KerberosServiceAuthenticationProvider the method authenticate may throw GSSException. As GSSException is not a AuthenticationException this causes the ProviderManager to skip other AuthenticationProviders and lead to a 500 response in a web appliction.
GSSException is checked but not declared. See KerberosValidateAction run method. The acceptSecContext generates sometimes a GSSException.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with KerberosServiceAuthenticationProvider.authenticate and KerberosValidateAction.run, then trace the acceptSecContext exception path. Confirm the failure is handled as an AuthenticationException so ProviderManager can continue to other providers instead of producing a 500 response.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, backend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100