spring-projects / spring-projects/spring-security
credentialsNotFound thrown in highly concurrent environment when one thread logs out
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
In a highly concurrent environment, if one thread logs out (and clears the authentication object) another thread may throw the credentialsNotFound from AbstractSecurityInterceptor line 222, if the associated request started before the logout request completed.
The cause is both the threads share the same SecurityContext. The logout thread sets the authentication to null, which causes the other thread to throw credentialsNotFound as it's authentication object is now null.
The workaround seems to be to disable clearAuthentication in the LogoutHandler. Are there any unintended side effects we should be aware of if we disable clearAuthentication?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read AbstractSecurityInterceptor line 222 and the LogoutHandler clearAuthentication path first. Trace how the shared SecurityContext changes when one concurrent request logs out, then determine the side effects of disabling clearAuthentication. Done means the concurrent behavior and workaround implications are clearly established.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 28/100