MapUserCredentialRepository leaves a stale owner index when a credential ID is reassigned
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 78/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- java
- Ambito
- authentication, backend
Direzione di ricerca
Inizia con MapUserCredentialRepository.save e il test di riproduzione MapUserCredentialRepositoryReproductionTests.java collegato nell’issue. Esegui il comando Gradle per il test mirato indicato nel report e segui come il salvataggio di una credenziale aggiorna gli indici primario e dei proprietari. Il lavoro è completo quando la riassegnazione mantiene coerenti entrambi gli indici e il test di riproduzione passa, comprese le query dopo l’eliminazione senza una NullPointerException.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Describe the bug
MapUserCredentialRepository.save does not remove an existing credential ID
from its previous owner's index when the same credential ID is saved with a
different userEntityUserId.
This leaves the primary credential index and the owner-to-credential-ID index
inconsistent. After deleting the credential, the old owner's index still
contains the credential ID. A subsequent findByUserId call then throws a
NullPointerException.
This is not reproducible through the standard /webauthn/register browser
registration flow because
Webauthn4JRelyingPartyOperations.registerCredential checks whether the
credential ID already exists first.
It is reproducible when application code directly calls
MapUserCredentialRepository.save with an existing credential ID and a
different owner ID.
To Reproduce
Sample repository:
https://github.com/789-yu/spring-security/tree/repro-map-user-credential-repository
Reproducer test:
Environment:
- Spring Security commit:
29f8dd53cd - Version:
7.1.0-243-g29f8dd53cd - JDK: 21
- Module:
spring-security-webauthn
Run:
./gradlew :spring-security-webauthn:test \
--tests org.springframework.security.web.webauthn.management.MapUserCredentialRepositoryReproductionTests \
--no-daemon \
-PtestToolchain=21 \
--rerun-tasks \
--console=plain
The reproducer performs these operations:
1. Save a credential for oldOwnerId.
2. Save the same credential ID again with newOwnerId.
3. Query the old owner.
4. Delete the credential by ID.
5. Query the old owner again.
Observed output:
1 old owner records after overwrite: [ImmutableCredentialRecord@...]
2 main index lookup from old owner credentialId: ImmutableCredentialRecord@...
3 new owner records after delete: []
4 old owner lookup after delete: java.lang.NullPointerException
The old owner's index still contains the credential ID after reassignment.
The primary index points to the new owner's record. Deleting the credential only
removes it from the new owner's index. The old owner's stale ID remains, and
findByUserId(oldOwnerId) throws a NullPointerException.
Expected behavior
When an existing credential ID is saved with a different owner, both internal
indexes should remain consistent.
The credential ID should either:
- be removed from the previous owner's index before being added to the new
owner's index; or
- be rejected if reassignment is not supported.
After deleting a credential, querying either owner should not leave a stale
credential ID or throw a NullPointerException.
**Sample**
A minimal reproducer is available here:
https://github.com/789-yu/spring-security/tree/repro-map-user-credential-repository
The reproducer test is available here:
https://github.com/789-yu/spring-security/blob/repro-map-user-credential-repository/webauthn/src/test/java/org/springframework/security/web/webauthn/management/MapUserCredentialRepositoryReproductionTests.java
[MapUserCredentialRepositoryReproductionTests.java](https://github.com/user-attachments/files/33189187/MapUserCredentialRepositoryReproductionTests.java)
- Lingua principale
- Java
- Stelle
- 9.6k
- Fork
- 6.4k
- Merge medio
- 1h 21m
- PR unite (30g)
- 42
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di spring-projects/spring-security
-
status: waiting-for-triage type: enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
spring-projects/spring-security#19834 ·
I maintainer di solito rispondono entro 1 giorno
-
status: waiting-for-triage type: enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
spring-projects/spring-security#19805 ·
I maintainer di solito rispondono entro 1 giorno
-
Avoid eager PasswordEncoder initialization in ClientSecretAuthenticationProviderForse già presa @tech00exploere l’ha presa 9 giorni fa. Apertastatus: waiting-for-triage type: enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
spring-projects/spring-security#19783 ·
I maintainer di solito rispondono entro 1 giorno
-
MethodSecurityExpressionHandler doesn't allow null to be returned when filteringForse già presa @zemiles l’ha presa 14 giorni fa. Apertastatus: waiting-for-triage type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
spring-projects/spring-security#19781 ·
I maintainer di solito rispondono entro 1 giorno
-
IpInetAddressMatcher throws ArrayIndexOutOfBoundsException instead of returning false for mismatched IPv4/IPv6 familiesForse già presa @minwoo-3 l’ha presa 22 giorni fa. Apertastatus: waiting-for-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
spring-projects/spring-security#19733 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di spring-projects/spring-security
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 74/100
I maintainer di solito rispondono entro 1 giorno
-
team:Lumberjack
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
OpenLiberty/open-liberty#35998 ·
I maintainer di solito rispondono entro 1 giorno
-
[BUG] SQS SendMessageBatch accepts more than 10 entries instead of TooManyEntriesInBatchRequestAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
floci-io/floci#5319 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Bug QWP
Difficoltà 2/5 1-3 ore Idoneità per principianti 79/100
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100