This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 21af2b16ff7c205e010452ba8e1849cf0300b1b3 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 22:19:11 2026 +0200 Replicate SSO session key set changes from removeSession() and sessionChangedId() in ClusterSingleSignOn so SSO entries are deregistered on all nodes when the last associated session expires --- .../ha/authenticator/ClusterSingleSignOn.java | 20 ++++++++++++++++++++ webapps/docs/changelog.xml | 7 +++++++ 2 files changed, 27 insertions(+) diff --git a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java index a322ad6132..68df995d42 100644 --- a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java +++ b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java @@ -175,6 +175,26 @@ public class ClusterSingleSignOn extends SingleSignOn implements ClusterValve, M return result; } + @Override + protected void removeSession(String ssoId, Session session) { + super.removeSession(ssoId, session); + // If the entry still exists, replicate the updated session key set so + // the other nodes can also detect when the set becomes empty + if (cache.containsKey(ssoId)) { + ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, true); + } + } + + @Override + protected void sessionChangedId(String ssoId, Session session, String oldSessionId) { + super.sessionChangedId(ssoId, session, oldSessionId); + // Replicate the updated session key set so stale session IDs do not + // remain on the other nodes + if (cache.containsKey(ssoId)) { + ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, true); + } + } + @Override protected SessionListener getSessionListener(String ssoId) { return new ClusterSingleSignOnListener(ssoId); diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml index 6068683a67..b937aea636 100644 --- a/webapps/docs/changelog.xml +++ b/webapps/docs/changelog.xml @@ -401,6 +401,13 @@ <subsection name="Cluster"> <changelog> <!-- Entries for backport and removal before 12.0.0-M1 below this line --> + <fix> + Replicate SSO session key set changes made by <code>removeSession()</code> + and <code>sessionChangedId()</code> in <code>ClusterSingleSignOn</code> so + that SSO entries are correctly deregistered and removed from all nodes when + the last associated session expires, even when the sessions expire on + different cluster nodes. (remm) + </fix> </changelog> </subsection> <subsection name="WebSocket"> --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
