spring-projects / spring-projects/spring-security
SEC-2333: Support argument index variables in SpEL expression security restrictions
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Nick Williams (Migrated from SEC-2333) said:
See the discussion in SPR-9643. You cannot always rely on parameter name discovery. Spring Security should support argument indexes in SpEL expression security restrictions, just like Spring Framework caching features, so that developers can write code that will always work, whether parameter name discovery is available or not. Arguments should always be referencable in these security expressions using #p0, #p1, etc.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file or test is named. Start by tracing Spring Security's SpEL expression security restrictions, then compare the behavior with the Spring Framework caching features and the SPR-9643 discussion. Done means security expressions can reference arguments as #p0, #p1, and similar indexes even when parameter-name discovery is unavailable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100