spring-projects / spring-projects/spring-security
SEC-2121: JdbcUserDetailsManager's changePassword should not populate the password
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Luke Taylor (Migrated from SEC-2121) said:
In order to be more consistent with the default behavior of the ProviderManager (which clears the password out) the JdbcUserDetailsManager's changePassword method should not populate the password on the Authentication set on the SecurityContextHolder.
Another option might be to populate the password conditionally (i.e. only if the credentials of the current Authentication are non-null).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with JdbcUserDetailsManager.changePassword and compare its SecurityContextHolder behavior with ProviderManager's credential-clearing behavior. Determine which expected behavior applies, including the issue's conditional-credentials alternative, then verify that the Authentication password state matches the chosen behavior after a password change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, backend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100