spring-projects / spring-projects/spring-security
The RunAsUserToken built by RunAsManager replaces the original authentication token in the SecurityContextRepository
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Summary
The Authentication token built by RunAsManager replaces the original authentication token in the SecurityContextRepository.
Actual Behavior
- For each request, build a runAsToken
- when there are concurrent requests, the original authentication token might be replaced by the RunAsUserToken in the SecurityContextRepository.
Expected Behavior
RunAsUserToken should be temporarily, and must not be persisted in the SecurityContextRepository.
Version
4.1.1 and old versions
Root Cause
It happens when the response is committed before the context in SecurityContextHolder is set back to the original SecurityContext.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how RunAsManager creates the RunAsUserToken and how SecurityContextRepository persists the SecurityContext, focusing on concurrent requests and responses committed before restoration. Reproduce the early-commit case and add a regression test showing that the original authentication remains persisted while the run-as token is temporary.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100