spring-projects / spring-projects/spring-security

SEC-2962: Fire an event when SessionFixationProtectionStrategy migrates a session

Open
#3,171 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

in: web type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Scott Rossillo (Migrated from SEC-2962) said:

It would be useful to have SessionFixationProtectionStrategy fire an event with the old session id and new session id immediately after migrating a session. This would allow applications that rely on an external authentication mechanism to track the relationship between the old session id and the new one or to notify an SSO provider that the session id changed.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating SessionFixationProtectionStrategy and tracing where it migrates a session. Define completion as emitting an event immediately after migration that exposes both the old and new session IDs; the issue does not name a test or file, so inspect the strategy's existing tests before determining coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
40/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.