spring-projects / spring-projects/spring-security

credentialsNotFound thrown in highly concurrent environment when one thread logs out

Open
#3,769 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

In a highly concurrent environment, if one thread logs out (and clears the authentication object) another thread may throw the credentialsNotFound from AbstractSecurityInterceptor line 222, if the associated request started before the logout request completed.

The cause is both the threads share the same SecurityContext. The logout thread sets the authentication to null, which causes the other thread to throw credentialsNotFound as it's authentication object is now null.

The workaround seems to be to disable clearAuthentication in the LogoutHandler. Are there any unintended side effects we should be aware of if we disable clearAuthentication?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read AbstractSecurityInterceptor line 222 and the LogoutHandler clearAuthentication path first. Trace how the shared SecurityContext changes when one concurrent request logs out, then determine the side effects of disabling clearAuthentication. Done means the concurrent behavior and workaround implications are clearly established.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.