This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 14e23625a6e372906a4f689cf750cfe135227ca8 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 10:11:25 2026 +0200 Stop SSO session listeners accumulating on sessions by re-keying the SSO entry on session ID change without registering an additional listener --- java/org/apache/catalina/authenticator/SingleSignOn.java | 9 ++++++--- .../apache/catalina/authenticator/SingleSignOnEntry.java | 14 ++++++++++++++ 2 files changed, 20 insertions(+), 3 deletions(-) diff --git a/java/org/apache/catalina/authenticator/SingleSignOn.java b/java/org/apache/catalina/authenticator/SingleSignOn.java index 65f173dfb5..cb5c66acaa 100644 --- a/java/org/apache/catalina/authenticator/SingleSignOn.java +++ b/java/org/apache/catalina/authenticator/SingleSignOn.java @@ -687,10 +687,13 @@ public class SingleSignOn extends ValveBase { } /* - * Associate the new sessionId with this SingleSignOnEntry. A SessionListener will be registered for the new - * sessionID. If not, then we would not notice any subsequent Session.SESSION_DESTROYED_EVENT for the session. + * Associate the new sessionId with this SingleSignOnEntry. No additional SessionListener is registered. The + * SessionListener is registered against the Session object, not the session ID, so the listener that + * triggered this method remains registered and will notice any subsequent + * Session.SESSION_CHANGED_ID_EVENT or Session.SESSION_DESTROYED_EVENT for the session. Registering a new + * listener on every ID change would leave the previous listener(s) orphaned on the session. */ - entry.addSession(this, ssoId, session); + entry.reassociateSession(session); /* * Remove the obsolete sessionId from the SingleSignOnEntry. The sessionId part of the SingleSignOnSessionKey is diff --git a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java index 4ce12e27ab..d91a91dd12 100644 --- a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java +++ b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java @@ -107,6 +107,20 @@ public class SingleSignOnEntry implements Serializable { } } + + /** + * Re-associates a <code>Session</code> with this SSO after its ID has changed, without registering an additional + * session listener. The listener is associated with the <code>Session</code> object rather than with the session + * ID, so the listener registered when the session was first associated with this SSO continues to receive events + * for the session. Registering another listener on each ID change would cause unbounded listener accumulation. + * + * @param session The <code>Session</code> being re-associated with this SSO. + */ + public void reassociateSession(Session session) { + SingleSignOnSessionKey key = new SingleSignOnSessionKey(session); + sessionKeys.putIfAbsent(key, key); + } + /** * Removes the given <code>Session</code> from the list of those associated with this SSO. * --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
