spring-projects / spring-projects/spring-security

SEC-2905: Concurrent Session Control does not work correctly within race condition

Open
#3,121 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: web type: bug type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Kazuki Shimizu (Migrated from SEC-2905) said:

When login at the same time(race condition) by multiple clients using same username, it can be login at the same time.

Security setting that not allowed to login at the same time by multiple sessions is follows:

<sec:concurrency-control
    max-sessions="1"
    error-if-maximum-exceeded="true" />

I think that need a synchronization mechanism by a username(authentication name) at the SessionAuthenticationStrategy processing.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the SessionAuthenticationStrategy processing described in the issue, focusing on concurrent logins for one authentication name. Reproduce the race with max-sessions="1" and error-if-maximum-exceeded="true"; done means concurrent clients cannot both establish sessions when the limit is one.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.