Skip to content

Commit bd43c1f

Browse files
author
Steve Riesenberg
committed
Merge branch '5.8.x'
# Conflicts: # web/src/main/java/org/springframework/security/web/context/HttpSessionSecurityContextRepository.java # web/src/test/java/org/springframework/security/web/context/SecurityContextRepositoryTests.java
2 parents 36ac7b3 + acc35ae commit bd43c1f

File tree

13 files changed

+445
-23
lines changed

13 files changed

+445
-23
lines changed

config/src/test/java/org/springframework/security/config/http/MiscHttpConfigTests.java

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,7 @@
7575
import org.springframework.security.core.GrantedAuthority;
7676
import org.springframework.security.core.annotation.AuthenticationPrincipal;
7777
import org.springframework.security.core.authority.AuthorityUtils;
78+
import org.springframework.security.core.context.DeferredSecurityContext;
7879
import org.springframework.security.core.context.SecurityContext;
7980
import org.springframework.security.core.context.SecurityContextHolder;
8081
import org.springframework.security.core.context.SecurityContextHolderStrategy;
@@ -487,7 +488,8 @@ public void getWhenExplicitSaveAndRepositoryAndAuthenticatingThenConsultsCustomS
487488
this.spring.configLocations(xml("ExplicitSaveAndExplicitRepository")).autowire();
488489
SecurityContextRepository repository = this.spring.getContext().getBean(SecurityContextRepository.class);
489490
SecurityContext context = new SecurityContextImpl(new TestingAuthenticationToken("user", "password"));
490-
given(repository.loadContext(any(HttpServletRequest.class))).willReturn(() -> context);
491+
given(repository.loadDeferredContext(any(HttpServletRequest.class)))
492+
.willReturn(new TestDeferredSecurityContext(context, false));
491493
// @formatter:off
492494
MvcResult result = this.mvc.perform(formLogin())
493495
.andExpect(status().is3xxRedirection())
@@ -1037,4 +1039,27 @@ public String encodeRedirectUrl(String url) {
10371039

10381040
}
10391041

1042+
static class TestDeferredSecurityContext implements DeferredSecurityContext {
1043+
1044+
private SecurityContext securityContext;
1045+
1046+
private boolean isGenerated;
1047+
1048+
TestDeferredSecurityContext(SecurityContext securityContext, boolean isGenerated) {
1049+
this.securityContext = securityContext;
1050+
this.isGenerated = isGenerated;
1051+
}
1052+
1053+
@Override
1054+
public SecurityContext get() {
1055+
return this.securityContext;
1056+
}
1057+
1058+
@Override
1059+
public boolean isGenerated() {
1060+
return this.isGenerated;
1061+
}
1062+
1063+
}
1064+
10401065
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
/*
2+
* Copyright 2002-2022 the original author or authors.
3+
*
4+
* Licensed under the Apache License, Version 2.0 (the "License");
5+
* you may not use this file except in compliance with the License.
6+
* You may obtain a copy of the License at
7+
*
8+
* https://www.apache.org/licenses/LICENSE-2.0
9+
*
10+
* Unless required by applicable law or agreed to in writing, software
11+
* distributed under the License is distributed on an "AS IS" BASIS,
12+
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13+
* See the License for the specific language governing permissions and
14+
* limitations under the License.
15+
*/
16+
17+
package org.springframework.security.core.context;
18+
19+
import java.util.function.Supplier;
20+
21+
/**
22+
* An interface that allows delayed access to a {@link SecurityContext} that may be
23+
* generated.
24+
*
25+
* @author Steve Riesenberg
26+
* @since 5.8
27+
*/
28+
public interface DeferredSecurityContext extends Supplier<SecurityContext> {
29+
30+
/**
31+
* Returns true if {@link #get()} refers to a generated {@link SecurityContext} or
32+
* false if it already existed.
33+
* @return true if {@link #get()} refers to a generated {@link SecurityContext} or
34+
* false if it already existed
35+
*/
36+
boolean isGenerated();
37+
38+
}
Lines changed: 111 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,111 @@
1+
/*
2+
* Copyright 2002-2022 the original author or authors.
3+
*
4+
* Licensed under the Apache License, Version 2.0 (the "License");
5+
* you may not use this file except in compliance with the License.
6+
* You may obtain a copy of the License at
7+
*
8+
* https://www.apache.org/licenses/LICENSE-2.0
9+
*
10+
* Unless required by applicable law or agreed to in writing, software
11+
* distributed under the License is distributed on an "AS IS" BASIS,
12+
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13+
* See the License for the specific language governing permissions and
14+
* limitations under the License.
15+
*/
16+
17+
package org.springframework.security.web.context;
18+
19+
import java.util.Arrays;
20+
import java.util.List;
21+
22+
import javax.servlet.http.HttpServletRequest;
23+
import javax.servlet.http.HttpServletResponse;
24+
25+
import org.springframework.security.core.context.DeferredSecurityContext;
26+
import org.springframework.security.core.context.SecurityContext;
27+
import org.springframework.util.Assert;
28+
29+
/**
30+
* @author Steve Riesenberg
31+
* @author Josh Cummings
32+
* @since 5.8
33+
*/
34+
public final class DelegatingSecurityContextRepository implements SecurityContextRepository {
35+
36+
private final List<SecurityContextRepository> delegates;
37+
38+
public DelegatingSecurityContextRepository(SecurityContextRepository... delegates) {
39+
this(Arrays.asList(delegates));
40+
}
41+
42+
public DelegatingSecurityContextRepository(List<SecurityContextRepository> delegates) {
43+
Assert.notEmpty(delegates, "delegates cannot be empty");
44+
this.delegates = delegates;
45+
}
46+
47+
@Override
48+
public SecurityContext loadContext(HttpRequestResponseHolder requestResponseHolder) {
49+
return loadContext(requestResponseHolder.getRequest()).get();
50+
}
51+
52+
@Override
53+
public DeferredSecurityContext loadDeferredContext(HttpServletRequest request) {
54+
DeferredSecurityContext deferredSecurityContext = null;
55+
for (SecurityContextRepository delegate : this.delegates) {
56+
if (deferredSecurityContext == null) {
57+
deferredSecurityContext = delegate.loadDeferredContext(request);
58+
}
59+
else {
60+
DeferredSecurityContext next = delegate.loadDeferredContext(request);
61+
deferredSecurityContext = new DelegatingDeferredSecurityContext(deferredSecurityContext, next);
62+
}
63+
}
64+
return deferredSecurityContext;
65+
}
66+
67+
@Override
68+
public void saveContext(SecurityContext context, HttpServletRequest request, HttpServletResponse response) {
69+
for (SecurityContextRepository delegate : this.delegates) {
70+
delegate.saveContext(context, request, response);
71+
}
72+
}
73+
74+
@Override
75+
public boolean containsContext(HttpServletRequest request) {
76+
for (SecurityContextRepository delegate : this.delegates) {
77+
if (delegate.containsContext(request)) {
78+
return true;
79+
}
80+
}
81+
return false;
82+
}
83+
84+
static final class DelegatingDeferredSecurityContext implements DeferredSecurityContext {
85+
86+
private final DeferredSecurityContext previous;
87+
88+
private final DeferredSecurityContext next;
89+
90+
DelegatingDeferredSecurityContext(DeferredSecurityContext previous, DeferredSecurityContext next) {
91+
this.previous = previous;
92+
this.next = next;
93+
}
94+
95+
@Override
96+
public SecurityContext get() {
97+
SecurityContext securityContext = this.previous.get();
98+
if (!this.previous.isGenerated()) {
99+
return securityContext;
100+
}
101+
return this.next.get();
102+
}
103+
104+
@Override
105+
public boolean isGenerated() {
106+
return this.previous.isGenerated() && this.next.isGenerated();
107+
}
108+
109+
}
110+
111+
}

web/src/main/java/org/springframework/security/web/context/HttpRequestResponseHolder.java

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,8 @@
2727
*
2828
* @author Luke Taylor
2929
* @since 3.0
30-
* @deprecated Use {@link SecurityContextRepository#loadContext(HttpServletRequest)}
30+
* @deprecated Use
31+
* {@link SecurityContextRepository#loadDeferredContext(HttpServletRequest)}
3132
*/
3233
@Deprecated
3334
public final class HttpRequestResponseHolder {

web/src/main/java/org/springframework/security/web/context/HttpSessionSecurityContextRepository.java

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,8 @@
1616

1717
package org.springframework.security.web.context;
1818

19+
import java.util.function.Supplier;
20+
1921
import jakarta.servlet.AsyncContext;
2022
import jakarta.servlet.ServletRequest;
2123
import jakarta.servlet.ServletResponse;
@@ -32,6 +34,7 @@
3234
import org.springframework.security.authentication.AuthenticationTrustResolverImpl;
3335
import org.springframework.security.core.Authentication;
3436
import org.springframework.security.core.Transient;
37+
import org.springframework.security.core.context.DeferredSecurityContext;
3538
import org.springframework.security.core.context.SecurityContext;
3639
import org.springframework.security.core.context.SecurityContextHolder;
3740
import org.springframework.security.core.context.SecurityContextHolderStrategy;
@@ -135,6 +138,12 @@ public SecurityContext loadContext(HttpRequestResponseHolder requestResponseHold
135138
return context;
136139
}
137140

141+
@Override
142+
public DeferredSecurityContext loadDeferredContext(HttpServletRequest request) {
143+
Supplier<SecurityContext> supplier = () -> readSecurityContextFromSession(request.getSession(false));
144+
return new SupplierDeferredSecurityContext(supplier, this.securityContextHolderStrategy);
145+
}
146+
138147
@Override
139148
public void saveContext(SecurityContext context, HttpServletRequest request, HttpServletResponse response) {
140149
SaveContextOnUpdateOrErrorResponseWrapper responseWrapper = WebUtils.getNativeResponse(response,

web/src/main/java/org/springframework/security/web/context/RequestAttributeSecurityContextRepository.java

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
import jakarta.servlet.http.HttpServletRequest;
2222
import jakarta.servlet.http.HttpServletResponse;
2323

24+
import org.springframework.security.core.context.DeferredSecurityContext;
2425
import org.springframework.security.core.context.SecurityContext;
2526
import org.springframework.security.core.context.SecurityContextHolder;
2627
import org.springframework.security.core.context.SecurityContextHolderStrategy;
@@ -76,17 +77,13 @@ public boolean containsContext(HttpServletRequest request) {
7677

7778
@Override
7879
public SecurityContext loadContext(HttpRequestResponseHolder requestResponseHolder) {
79-
return getContextOrEmpty(requestResponseHolder.getRequest());
80+
return loadDeferredContext(requestResponseHolder.getRequest()).get();
8081
}
8182

8283
@Override
83-
public Supplier<SecurityContext> loadContext(HttpServletRequest request) {
84-
return () -> getContextOrEmpty(request);
85-
}
86-
87-
private SecurityContext getContextOrEmpty(HttpServletRequest request) {
88-
SecurityContext context = getContext(request);
89-
return (context != null) ? context : this.securityContextHolderStrategy.createEmptyContext();
84+
public DeferredSecurityContext loadDeferredContext(HttpServletRequest request) {
85+
Supplier<SecurityContext> supplier = () -> getContext(request);
86+
return new SupplierDeferredSecurityContext(supplier, this.securityContextHolderStrategy);
9087
}
9188

9289
private SecurityContext getContext(HttpServletRequest request) {

web/src/main/java/org/springframework/security/web/context/SaveContextOnUpdateOrErrorResponseWrapper.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,8 @@
4242
* @author Marten Algesten
4343
* @author Rob Winch
4444
* @since 3.0
45-
* @deprecated Use {@link SecurityContextRepository#loadContext(HttpServletRequest)}
46-
* instead.
45+
* @deprecated Use
46+
* {@link SecurityContextRepository#loadDeferredContext(HttpServletRequest)} instead.
4747
*/
4848
@Deprecated
4949
public abstract class SaveContextOnUpdateOrErrorResponseWrapper extends OnCommittedResponseWrapper {

web/src/main/java/org/springframework/security/web/context/SecurityContextHolderFilter.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ public SecurityContextHolderFilter(SecurityContextRepository securityContextRepo
6363
@Override
6464
protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
6565
throws ServletException, IOException {
66-
Supplier<SecurityContext> deferredContext = this.securityContextRepository.loadContext(request);
66+
Supplier<SecurityContext> deferredContext = this.securityContextRepository.loadDeferredContext(request);
6767
try {
6868
this.securityContextHolderStrategy.setDeferredContext(deferredContext);
6969
filterChain.doFilter(request, response);

web/src/main/java/org/springframework/security/web/context/SecurityContextRepository.java

Lines changed: 23 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright 2002-2016 the original author or authors.
2+
* Copyright 2002-2022 the original author or authors.
33
*
44
* Licensed under the Apache License, Version 2.0 (the "License");
55
* you may not use this file except in compliance with the License.
@@ -21,7 +21,9 @@
2121
import jakarta.servlet.http.HttpServletRequest;
2222
import jakarta.servlet.http.HttpServletResponse;
2323

24+
import org.springframework.security.core.context.DeferredSecurityContext;
2425
import org.springframework.security.core.context.SecurityContext;
26+
import org.springframework.security.core.context.SecurityContextHolder;
2527
import org.springframework.util.function.SingletonSupplier;
2628

2729
/**
@@ -61,7 +63,7 @@ public interface SecurityContextRepository {
6163
* the context should be loaded.
6264
* @return The security context which should be used for the current request, never
6365
* null.
64-
* @deprecated Use {@link #loadContext(HttpServletRequest)} instead.
66+
* @deprecated Use {@link #loadDeferredContext(HttpServletRequest)} instead.
6567
*/
6668
@Deprecated
6769
SecurityContext loadContext(HttpRequestResponseHolder requestResponseHolder);
@@ -75,9 +77,27 @@ public interface SecurityContextRepository {
7577
* @return a {@link Supplier} that returns the {@link SecurityContext} which cannot be
7678
* null.
7779
* @since 5.7
80+
* @deprecated Use
81+
* {@link SecurityContextRepository#loadDeferredContext(HttpServletRequest)} instead
7882
*/
83+
@Deprecated
7984
default Supplier<SecurityContext> loadContext(HttpServletRequest request) {
80-
return SingletonSupplier.of(() -> loadContext(new HttpRequestResponseHolder(request, null)));
85+
return loadDeferredContext(request);
86+
}
87+
88+
/**
89+
* Defers loading the {@link SecurityContext} using the {@link HttpServletRequest}
90+
* until it is needed by the application.
91+
* @param request the {@link HttpServletRequest} to load the {@link SecurityContext}
92+
* from
93+
* @return a {@link DeferredSecurityContext} that returns the {@link SecurityContext}
94+
* which cannot be null
95+
* @since 5.8
96+
*/
97+
default DeferredSecurityContext loadDeferredContext(HttpServletRequest request) {
98+
Supplier<SecurityContext> supplier = () -> loadContext(new HttpRequestResponseHolder(request, null));
99+
return new SupplierDeferredSecurityContext(SingletonSupplier.of(supplier),
100+
SecurityContextHolder.getContextHolderStrategy());
81101
}
82102

83103
/**

0 commit comments

Comments
 (0)