spring-projects / spring-projects/spring-security

SEC-2906: RemoteAuthenticationException not being caught

Open
#3,122 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: remoting type: bug type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Philipp Nanz (Migrated from SEC-2906) said:

When using the RemoteAuthenticationProvider, on the server-side the AuthenticationException is repackaged into a less verbose RemoteAuthenticationException (see RemoteAuthenticationManagerImpl), presumbly in order not to accidentally expose any critical information.

Once the result has reached the client side, the exception is simply passed on though. Since the RemoteAuthenticationException is not a subclass of AuthenticationException it falls through in every following catch block, eventually hitting the uncaught exception handler of the servlet.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with RemoteAuthenticationManagerImpl and trace how the returned RemoteAuthenticationException is handled on the client side, especially the servlet exception path. Compare the existing AuthenticationException catch flow and identify the relevant tests or entry points; done means the client-side failure follows the normal authentication exception handling instead of reaching the uncaught servlet handler.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.