This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 995840a064708db68e629b6049360be9755db1e7 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 22:19:11 2026 +0200 Replicate SSO session key set changes from removeSession() and sessionChangedId() in ClusterSingleSignOn so SSO entries are deregistered on all nodes when the last associated session expires --- .../ha/authenticator/ClusterSingleSignOn.java | 20 ++++++++++++++++++++ webapps/docs/changelog.xml | 11 +++++++++++ 2 files changed, 31 insertions(+) diff --git a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java index a322ad6132..68df995d42 100644 --- a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java +++ b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java @@ -175,6 +175,26 @@ public class ClusterSingleSignOn extends SingleSignOn implements ClusterValve, M return result; } + @Override + protected void removeSession(String ssoId, Session session) { + super.removeSession(ssoId, session); + // If the entry still exists, replicate the updated session key set so + // the other nodes can also detect when the set becomes empty + if (cache.containsKey(ssoId)) { + ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, true); + } + } + + @Override + protected void sessionChangedId(String ssoId, Session session, String oldSessionId) { + super.sessionChangedId(ssoId, session, oldSessionId); + // Replicate the updated session key set so stale session IDs do not + // remain on the other nodes + if (cache.containsKey(ssoId)) { + ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, true); + } + } + @Override protected SessionListener getSessionListener(String ssoId) { return new ClusterSingleSignOnListener(ssoId); diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml index 30f7bbbc1c..daf04b29c1 100644 --- a/webapps/docs/changelog.xml +++ b/webapps/docs/changelog.xml @@ -172,6 +172,17 @@ </fix> </changelog> </subsection> + <subsection name="Cluster"> + <changelog> + <fix> + Replicate SSO session key set changes made by <code>removeSession()</code> + and <code>sessionChangedId()</code> in <code>ClusterSingleSignOn</code> so + that SSO entries are correctly deregistered and removed from all nodes when + the last associated session expires, even when the sessions expire on + different cluster nodes. (remm) + </fix> + </changelog> + </subsection> <subsection name="Web applications"> <changelog> <add> --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
