소스 검색

SEC-112: Bug when SecurityEnforcementFilter used with disabled Authentication and remember-me services.

Ben Alex 20 년 전
부모
커밋
9ccaf05cc7
1개의 변경된 파일4개의 추가작업 그리고 0개의 파일을 삭제
  1. 4 0
      core/src/main/java/org/acegisecurity/intercept/web/SecurityEnforcementFilter.java

+ 4 - 0
core/src/main/java/org/acegisecurity/intercept/web/SecurityEnforcementFilter.java

@@ -278,6 +278,10 @@ public class SecurityEnforcementFilter implements Filter, InitializingBean {
             ((HttpServletRequest) request).getSession().setAttribute(AbstractProcessingFilter.ACEGI_SECURITY_TARGET_URL_KEY,
                 targetUrl);
         }
+        
+        // SEC-112: Clear the SecurityContextHolder's Authentication, as the
+        // existing Authentication is no longer considered valid
+        SecurityContextHolder.getContext().setAuthentication(null);
 
         authenticationEntryPoint.commence(request,
             (HttpServletResponse) fi.getResponse(), reason);