spring-projects / spring-projects/spring-security
SEC-3086: Override websocket Session object to provide Principal
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
zhouyanming (Migrated from SEC-3086) said:
please see JIRA SEC-2180
javax.websocket.Session.getUserPrincipal() should return same principal like UsernamePasswordAuthenticationToken with HttpServletRequest.getUserPrincipal(), It works fine with tomcat, but failed with jetty and wildfly.
Jetty's upgrade request doesn't respect filters in web.xml, the instance of HttpServletRequest is original request created by container not wrapped request by spring security filter.
Wildfly and other server should be the same problem with Jetty.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the referenced JIRA SEC-2180 and the websocket Session.getUserPrincipal() behavior described here. Compare the reported Tomcat behavior with Jetty and WildFly, and confirm that the websocket session exposes the same principal as HttpServletRequest.getUserPrincipal() without relying on the wrapped request.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100