This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 21af2b16ff7c205e010452ba8e1849cf0300b1b3
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 22:19:11 2026 +0200

    Replicate SSO session key set changes from removeSession() and 
sessionChangedId() in ClusterSingleSignOn so SSO entries are deregistered on 
all nodes when the last associated session expires
---
 .../ha/authenticator/ClusterSingleSignOn.java        | 20 ++++++++++++++++++++
 webapps/docs/changelog.xml                           |  7 +++++++
 2 files changed, 27 insertions(+)

diff --git a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java 
b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
index a322ad6132..68df995d42 100644
--- a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
+++ b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
@@ -175,6 +175,26 @@ public class ClusterSingleSignOn extends SingleSignOn 
implements ClusterValve, M
         return result;
     }
 
+    @Override
+    protected void removeSession(String ssoId, Session session) {
+        super.removeSession(ssoId, session);
+        // If the entry still exists, replicate the updated session key set so
+        // the other nodes can also detect when the set becomes empty
+        if (cache.containsKey(ssoId)) {
+            ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, 
true);
+        }
+    }
+
+    @Override
+    protected void sessionChangedId(String ssoId, Session session, String 
oldSessionId) {
+        super.sessionChangedId(ssoId, session, oldSessionId);
+        // Replicate the updated session key set so stale session IDs do not
+        // remain on the other nodes
+        if (cache.containsKey(ssoId)) {
+            ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, 
true);
+        }
+    }
+
     @Override
     protected SessionListener getSessionListener(String ssoId) {
         return new ClusterSingleSignOnListener(ssoId);
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index 6068683a67..b937aea636 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -401,6 +401,13 @@
   <subsection name="Cluster">
     <changelog>
       <!-- Entries for backport and removal before 12.0.0-M1 below this line 
-->
+      <fix>
+        Replicate SSO session key set changes made by 
<code>removeSession()</code>
+        and <code>sessionChangedId()</code> in 
<code>ClusterSingleSignOn</code> so
+        that SSO entries are correctly deregistered and removed from all nodes 
when
+        the last associated session expires, even when the sessions expire on
+        different cluster nodes. (remm)
+      </fix>
     </changelog>
   </subsection>
   <subsection name="WebSocket">


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to