This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit cc591a12b915fa3e734a4b0caaa60840133f46e8
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 10:11:25 2026 +0200

    Stop SSO session listeners accumulating on sessions by re-keying the SSO 
entry on session ID change without registering an additional listener
---
 java/org/apache/catalina/authenticator/SingleSignOn.java   |  9 ++++++---
 .../apache/catalina/authenticator/SingleSignOnEntry.java   | 14 ++++++++++++++
 2 files changed, 20 insertions(+), 3 deletions(-)

diff --git a/java/org/apache/catalina/authenticator/SingleSignOn.java 
b/java/org/apache/catalina/authenticator/SingleSignOn.java
index 65f173dfb5..cb5c66acaa 100644
--- a/java/org/apache/catalina/authenticator/SingleSignOn.java
+++ b/java/org/apache/catalina/authenticator/SingleSignOn.java
@@ -687,10 +687,13 @@ public class SingleSignOn extends ValveBase {
         }
 
         /*
-         * Associate the new sessionId with this SingleSignOnEntry. A 
SessionListener will be registered for the new
-         * sessionID. If not, then we would not notice any subsequent 
Session.SESSION_DESTROYED_EVENT for the session.
+         * Associate the new sessionId with this SingleSignOnEntry. No 
additional SessionListener is registered. The
+         * SessionListener is registered against the Session object, not the 
session ID, so the listener that
+         * triggered this method remains registered and will notice any 
subsequent
+         * Session.SESSION_CHANGED_ID_EVENT or Session.SESSION_DESTROYED_EVENT 
for the session. Registering a new
+         * listener on every ID change would leave the previous listener(s) 
orphaned on the session.
          */
-        entry.addSession(this, ssoId, session);
+        entry.reassociateSession(session);
 
         /*
          * Remove the obsolete sessionId from the SingleSignOnEntry. The 
sessionId part of the SingleSignOnSessionKey is
diff --git a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java 
b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java
index 4ce12e27ab..d91a91dd12 100644
--- a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java
+++ b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java
@@ -107,6 +107,20 @@ public class SingleSignOnEntry implements Serializable {
         }
     }
 
+
+    /**
+     * Re-associates a <code>Session</code> with this SSO after its ID has 
changed, without registering an additional
+     * session listener. The listener is associated with the 
<code>Session</code> object rather than with the session
+     * ID, so the listener registered when the session was first associated 
with this SSO continues to receive events
+     * for the session. Registering another listener on each ID change would 
cause unbounded listener accumulation.
+     *
+     * @param session The <code>Session</code> being re-associated with this 
SSO.
+     */
+    public void reassociateSession(Session session) {
+        SingleSignOnSessionKey key = new SingleSignOnSessionKey(session);
+        sessionKeys.putIfAbsent(key, key);
+    }
+
     /**
      * Removes the given <code>Session</code> from the list of those 
associated with this SSO.
      *


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to