spring-projects / spring-projects/spring-security

SEC-2333: Support argument index variables in SpEL expression security restrictions

Open
#2,558 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: core type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Nick Williams (Migrated from SEC-2333) said:

See the discussion in SPR-9643. You cannot always rely on parameter name discovery. Spring Security should support argument indexes in SpEL expression security restrictions, just like Spring Framework caching features, so that developers can write code that will always work, whether parameter name discovery is available or not. Arguments should always be referencable in these security expressions using #p0, #p1, etc.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. Start by tracing Spring Security's SpEL expression security restrictions, then compare the behavior with the Spring Framework caching features and the SPR-9643 discussion. Done means security expressions can reference arguments as #p0, #p1, and similar indexes even when parameter-name discovery is unavailable.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.