spring-projects / spring-projects/spring-security
SEC-2905: Concurrent Session Control does not work correctly within race condition
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Kazuki Shimizu (Migrated from SEC-2905) said:
When login at the same time(race condition) by multiple clients using same username, it can be login at the same time.
Security setting that not allowed to login at the same time by multiple sessions is follows:
<sec:concurrency-control
max-sessions="1"
error-if-maximum-exceeded="true" />
I think that need a synchronization mechanism by a username(authentication name) at the SessionAuthenticationStrategy processing.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the SessionAuthenticationStrategy processing described in the issue, focusing on concurrent logins for one authentication name. Reproduce the race with max-sessions="1" and error-if-maximum-exceeded="true"; done means concurrent clients cannot both establish sessions when the limit is one.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100