This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 39d7f9f2213249cec6e8d595002ea1cc598d7f89
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 10:22:41 2026 +0200

    Document that a failure to create a persistent JASPIC provider registration 
is deliberately fatal rather than silently skipped, since skipping an 
authentication provider would fail open
---
 .../catalina/authenticator/jaspic/AuthConfigFactoryImpl.java       | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git 
a/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java 
b/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java
index d5c0b7357c..07ccd7d0f9 100644
--- a/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java
+++ b/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java
@@ -440,6 +440,13 @@ public class AuthConfigFactoryImpl extends 
AuthConfigFactory {
                 }
                 Providers providers = 
PersistentProviderRegistrations.loadProviders(CONFIG_FILE);
                 for (Provider provider : providers.getProviders()) {
+                    /*
+                     * If a configured provider cannot be created, the 
resulting exception is allowed to propagate to
+                     * the caller. This is deliberate: JASPIC is an 
authentication mechanism so, for security, a
+                     * registration that cannot be honoured must be fatal 
rather than silently skipped, since silently
+                     * skipping it could allow requests to be processed 
without the expected authentication provider.
+                     * The admin must fix or remove the offending entry in 
jaspic-providers.xml.
+                     */
                     doRegisterConfigProvider(provider.getClassName(), 
provider.getProperties(), provider.getLayer(),
                             provider.getAppContext(), 
provider.getDescription(), wrappersToNotify);
                 }


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to