spring-projects / spring-projects/spring-security
OneTimeTokenAuthenticationProvider authenticate method setDetails call
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Describe the bug
OneTimeTokenAuthenticationProvider does not set Principal correctly
To Reproduce
Log in via OneTimeToken with custom UserDetails with i.e. email additional field
Expected behavior
OneTimeTokenAuthenticationToken should have email field present in Principal
Bug
By my opinion bug is in line:
authenticated.setDetails(otpAuthenticationToken.getDetails());
otpAuthenticationToken is unathenticated token and does not have details!
line should probably be:
authenticated.setDetails(user);
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at OneTimeTokenAuthenticationProvider.authenticate and inspect how the authenticated token's principal and details are populated. Reproduce the flow with a custom UserDetails containing an email field, then verify that the resulting OneTimeTokenAuthenticationToken exposes that field in its principal.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 58/100