This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit f22f92c7a9a3472d8a7581ae98482fd44b9aace9 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 10:11:25 2026 +0200 Stop SSO session listeners accumulating on sessions by re-keying the SSO entry on session ID change without registering an additional listener --- java/org/apache/catalina/authenticator/SingleSignOn.java | 9 ++++++--- .../apache/catalina/authenticator/SingleSignOnEntry.java | 14 ++++++++++++++ 2 files changed, 20 insertions(+), 3 deletions(-) diff --git a/java/org/apache/catalina/authenticator/SingleSignOn.java b/java/org/apache/catalina/authenticator/SingleSignOn.java index fa683c154d..7dd0b6b14b 100644 --- a/java/org/apache/catalina/authenticator/SingleSignOn.java +++ b/java/org/apache/catalina/authenticator/SingleSignOn.java @@ -683,10 +683,13 @@ public class SingleSignOn extends ValveBase { } /* - * Associate the new sessionId with this SingleSignOnEntry. A SessionListener will be registered for the new - * sessionID. If not, then we would not notice any subsequent Session.SESSION_DESTROYED_EVENT for the session. + * Associate the new sessionId with this SingleSignOnEntry. No additional SessionListener is registered. The + * SessionListener is registered against the Session object, not the session ID, so the listener that + * triggered this method remains registered and will notice any subsequent + * Session.SESSION_CHANGED_ID_EVENT or Session.SESSION_DESTROYED_EVENT for the session. Registering a new + * listener on every ID change would leave the previous listener(s) orphaned on the session. */ - entry.addSession(this, ssoId, session); + entry.reassociateSession(session); /* * Remove the obsolete sessionId from the SingleSignOnEntry. The sessionId part of the SingleSignOnSessionKey is diff --git a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java index 09d6a6a3c1..490508452c 100644 --- a/java/org/apache/catalina/authenticator/SingleSignOnEntry.java +++ b/java/org/apache/catalina/authenticator/SingleSignOnEntry.java @@ -105,6 +105,20 @@ public class SingleSignOnEntry implements Serializable { } } + + /** + * Re-associates a <code>Session</code> with this SSO after its ID has changed, without registering an additional + * session listener. The listener is associated with the <code>Session</code> object rather than with the session + * ID, so the listener registered when the session was first associated with this SSO continues to receive events + * for the session. Registering another listener on each ID change would cause unbounded listener accumulation. + * + * @param session The <code>Session</code> being re-associated with this SSO. + */ + public void reassociateSession(Session session) { + SingleSignOnSessionKey key = new SingleSignOnSessionKey(session); + sessionKeys.putIfAbsent(key, key); + } + /** * Removes the given <code>Session</code> from the list of those associated with this SSO. * --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
