spring-projects / spring-projects/spring-security
5.8.12: @Secured annotation on subclasses is not read by SecuredAuthorizationManager when method in superclass was called
Open
@jzheaux is already working on this.
Since May 21, 2024.
in: core
type: bug
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
If I have 2 classes,
public abstract class AbstractService {
public void doSmth() {...}
}
@Secured("SECURE")
@Service
public class Service extends AbstractService {
...
}
and when I call service.doSmth(), security is not applied, because method org.springframework.security.authorization.method.SecuredAuthorizationManager.SecuredAuthorizationManagerRegistry#findSecuredAnnotation will try to get annotation of AbstractService, not of Service.
See the 6 version of this method https://github.com/spring-projects/spring-security/blob/main/core/src/main/java/org/springframework/security/authorization/method/SecuredAuthorizationManager.java
This bug was fixed there.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.