spring-projects / spring-projects/spring-security
SEC-2582: Storing configurers in AbstractConfiguredSecurityBuilder as a has against their concrete class can cause issues
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Dave Syer (Migrated from SEC-2582) said:
In this sample (https://github.com/dsyer/spring-oauth2-integration-tests/blob/master/multi/src/main/java/demo/Application.java#L39) want to have 2 ResourceServerConfiguration @Beans. They are WebSecurityConfigurerAdapters and it only works if they are different concrete classes because of the way they are stored internally.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with AbstractConfiguredSecurityBuilder and the linked sample at multi/src/main/java/demo/Application.java around line 39. Reproduce the case with two ResourceServerConfiguration beans and inspect how WebSecurityConfigurerAdapters are stored. Done means distinct concrete configurations work without relying on different classes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100