Browse Source

SEC-1770: Call refreshLastRequest on the session registry rather than the SessionInformation object to make sure it works with alternative SessionRegistry implementations.

Luke Taylor 14 năm trước cách đây
mục cha
commit
ca2af8bc59

+ 1 - 1
web/src/main/java/org/springframework/security/web/session/ConcurrentSessionFilter.java

@@ -101,7 +101,7 @@ public class ConcurrentSessionFilter extends GenericFilterBean {
                     return;
                 } else {
                     // Non-expired - update last request date/time
-                    info.refreshLastRequest();
+                    sessionRegistry.refreshLastRequest(info.getSessionId());
                 }
             }
         }