瀏覽代碼

SEC-159: Comment about use of SecurityContextHolder.clearContext().

Ben Alex 19 年之前
父節點
當前提交
c8e81bd425
共有 1 個文件被更改,包括 9 次插入0 次删除
  1. 9 0
      doc/xdocs/upgrade/upgrade-090-100.html

+ 9 - 0
doc/xdocs/upgrade/upgrade-090-100.html

@@ -66,6 +66,15 @@ applications:
 	an additional filter entry to web.xml and use FilterToBeanProxy to access the FilterSecurityInterceptor.
 	</li>
 	
+	<li>
+	If you are directly using SecurityContextHolder.setContext(SecurityContext) - which is not
+	very common - please not that best practise is now to call SecurityContextHolder.clearContext()
+	if you wish to erase the contents of the SecurityContextHolder. Previously code such as
+	SecurityContextHolder.setContext(new SecurityContextImpl()) would have been used. The revised
+	method internally stores null, which helps avoids redeployment issue caused by the previous
+	approaches (see SEC-159 for further details).
+	</li>
+	
     </ul>
 
 </body>