spring-projects / spring-projects/spring-security

SEC-3165: Get domain object instance based on runtime class in voters

Open
#3,374 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: acl type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Olivier Ailloud (Migrated from SEC-3165) said:

The method getDomainObjectInstance in AbstractAclVoter loops through the parameters and looks for any parameter whose +declared+ class is assignable from the processDomainObjectClass.
But when the parameter's type is an interface, this is annoying as the voter will throw an AuthorizationServiceException even if implementations are eligible for this voter.
It seems to me that it should rather be based on the +runtime+ class.

The patch seems fairly easy, I may provide it.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating AbstractAclVoter and its getDomainObjectInstance method, then read how it examines voter parameters and determines eligible domain objects. Done means an interface-typed parameter is evaluated using its runtime class when an implementation is eligible, without the voter throwing an AuthorizationServiceException.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authorization
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.