spring-projects / spring-projects/spring-security
SEC-2906: RemoteAuthenticationException not being caught
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Philipp Nanz (Migrated from SEC-2906) said:
When using the RemoteAuthenticationProvider, on the server-side the AuthenticationException is repackaged into a less verbose RemoteAuthenticationException (see RemoteAuthenticationManagerImpl), presumbly in order not to accidentally expose any critical information.
Once the result has reached the client side, the exception is simply passed on though. Since the RemoteAuthenticationException is not a subclass of AuthenticationException it falls through in every following catch block, eventually hitting the uncaught exception handler of the servlet.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with RemoteAuthenticationManagerImpl and trace how the returned RemoteAuthenticationException is handled on the client side, especially the servlet exception path. Compare the existing AuthenticationException catch flow and identify the relevant tests or entry points; done means the client-side failure follows the normal authentication exception handling instead of reaching the uncaught servlet handler.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100