spring-projects / spring-projects/spring-security
SEC-3165: Get domain object instance based on runtime class in voters
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Olivier Ailloud (Migrated from SEC-3165) said:
The method getDomainObjectInstance in AbstractAclVoter loops through the parameters and looks for any parameter whose +declared+ class is assignable from the processDomainObjectClass.
But when the parameter's type is an interface, this is annoying as the voter will throw an AuthorizationServiceException even if implementations are eligible for this voter.
It seems to me that it should rather be based on the +runtime+ class.
The patch seems fairly easy, I may provide it.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating AbstractAclVoter and its getDomainObjectInstance method, then read how it examines voter parameters and determines eligible domain objects. Done means an interface-typed parameter is evaluated using its runtime class when an implementation is eligible, without the voter throwing an AuthorizationServiceException.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 38/100