This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit a4be3f223ef1f87e3e03a46ea7114da980a4a0a4 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 10:22:41 2026 +0200 Document that a failure to create a persistent JASPIC provider registration is deliberately fatal rather than silently skipped, since skipping an authentication provider would fail open --- .../catalina/authenticator/jaspic/AuthConfigFactoryImpl.java | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java b/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java index d5c0b7357c..07ccd7d0f9 100644 --- a/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java +++ b/java/org/apache/catalina/authenticator/jaspic/AuthConfigFactoryImpl.java @@ -440,6 +440,13 @@ public class AuthConfigFactoryImpl extends AuthConfigFactory { } Providers providers = PersistentProviderRegistrations.loadProviders(CONFIG_FILE); for (Provider provider : providers.getProviders()) { + /* + * If a configured provider cannot be created, the resulting exception is allowed to propagate to + * the caller. This is deliberate: JASPIC is an authentication mechanism so, for security, a + * registration that cannot be honoured must be fatal rather than silently skipped, since silently + * skipping it could allow requests to be processed without the expected authentication provider. + * The admin must fix or remove the offending entry in jaspic-providers.xml. + */ doRegisterConfigProvider(provider.getClassName(), provider.getProperties(), provider.getLayer(), provider.getAppContext(), provider.getDescription(), wrappersToNotify); } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
