This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 0109e76b8d5b3aff522d949144a8423f0929ed06
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 10:20:47 2026 +0200

    Load statically configured ServerAuthModule classes via the thread context 
(web application) class loader first, matching the pattern used for 
AuthConfigProvider classes, so modules packaged in WEB-INF/lib are found
---
 .../catalina/authenticator/jaspic/SimpleServerAuthConfig.java | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

diff --git 
a/java/org/apache/catalina/authenticator/jaspic/SimpleServerAuthConfig.java 
b/java/org/apache/catalina/authenticator/jaspic/SimpleServerAuthConfig.java
index 78a6c56f6a..27c8eca20b 100644
--- a/java/org/apache/catalina/authenticator/jaspic/SimpleServerAuthConfig.java
+++ b/java/org/apache/catalina/authenticator/jaspic/SimpleServerAuthConfig.java
@@ -141,7 +141,16 @@ public class SimpleServerAuthConfig implements 
ServerAuthConfig {
                     Object moduleClassName = mergedProperties.get(key);
                     while (moduleClassName instanceof String) {
                         try {
-                            Class<?> clazz = Class.forName((String) 
moduleClassName);
+                            Class<?> clazz = null;
+                            try {
+                                clazz = Class.forName((String) 
moduleClassName, true,
+                                        
Thread.currentThread().getContextClassLoader());
+                            } catch (ClassNotFoundException ignore) {
+                                // Ignore so the re-try below can proceed
+                            }
+                            if (clazz == null) {
+                                clazz = Class.forName((String) 
moduleClassName);
+                            }
                             ServerAuthModule module = (ServerAuthModule) 
clazz.getConstructor().newInstance();
                             module.initialize(null, null, handler, 
mergedProperties);
                             modules.add(module);


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to