spring-projects / spring-projects/spring-security

SEC-2437: Let the context be updated or let us define a custom strategy to detect change in security context

Open
#2,657 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: web type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Manuel EVENO (Migrated from SEC-2437) said:

The class org.springframework.security.web.context.HttpSessionSecurityContextRepository uses a response wrapper to check if the security context should be updated in http session.
The condition to determine a necessary update are defined in the following private method :
org.springframework.security.web.context.HttpSessionSecurityContextRepository.SaveToSessionResponseWrapper.contextChanged(SecurityContext)

You should define a custom strategy object we can change to allow us custom context change detection.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading org.springframework.security.web.context.HttpSessionSecurityContextRepository and its SaveToSessionResponseWrapper.contextChanged(SecurityContext) method. Trace how the response wrapper decides whether to update the HTTP session. Done means providing a configurable strategy object for custom security-context change detection and confirming the existing behavior remains supported.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.