spring-projects / spring-projects/spring-security

Bad excpetion handling in JdbcMutableAclService.retrieveObjectIdentityPrimaryKey

Open
#3,755 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

spring-security-acl-4.0.3.RELEASE

currently all DataAccessException interpreted as primiry key is not found, but it is bad solution, some runtime sql exception will be skipped such as datatype converting and so on.

Better is to use EmptyResultDataAccessException and IncorrectResultSizeDataAccessException

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at JdbcMutableAclService.retrieveObjectIdentityPrimaryKey and inspect how DataAccessException is handled. Update the exception handling so only the specified empty-result and incorrect-result-size cases represent a missing primary key, while other SQL failures remain visible; verify the method's behavior with the relevant existing tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authorization, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.