This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit f06147373238a62288a7a9c382a144b3b11e070b
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 22:19:11 2026 +0200

    Replicate SSO session key set changes from removeSession() and
    sessionChangedId() in ClusterSingleSignOn so SSO entries are
    deregistered on all nodes when the last associated session expires
---
 .../ha/authenticator/ClusterSingleSignOn.java        | 20 ++++++++++++++++++++
 webapps/docs/changelog.xml                           | 11 +++++++++++
 2 files changed, 31 insertions(+)

diff --git a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java 
b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
index a322ad6132..68df995d42 100644
--- a/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
+++ b/java/org/apache/catalina/ha/authenticator/ClusterSingleSignOn.java
@@ -175,6 +175,26 @@ public class ClusterSingleSignOn extends SingleSignOn 
implements ClusterValve, M
         return result;
     }
 
+    @Override
+    protected void removeSession(String ssoId, Session session) {
+        super.removeSession(ssoId, session);
+        // If the entry still exists, replicate the updated session key set so
+        // the other nodes can also detect when the set becomes empty
+        if (cache.containsKey(ssoId)) {
+            ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, 
true);
+        }
+    }
+
+    @Override
+    protected void sessionChangedId(String ssoId, Session session, String 
oldSessionId) {
+        super.sessionChangedId(ssoId, session, oldSessionId);
+        // Replicate the updated session key set so stale session IDs do not
+        // remain on the other nodes
+        if (cache.containsKey(ssoId)) {
+            ((ReplicatedMap<String,SingleSignOnEntry>) cache).replicate(ssoId, 
true);
+        }
+    }
+
     @Override
     protected SessionListener getSessionListener(String ssoId) {
         return new ClusterSingleSignOnListener(ssoId);
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index 569c738663..2a649365d3 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -172,6 +172,17 @@
       </fix>
     </changelog>
   </subsection>
+  <subsection name="Cluster">
+    <changelog>
+      <fix>
+        Replicate SSO session key set changes made by 
<code>removeSession()</code>
+        and <code>sessionChangedId()</code> in 
<code>ClusterSingleSignOn</code> so
+        that SSO entries are correctly deregistered and removed from all nodes 
when
+        the last associated session expires, even when the sessions expire on
+        different cluster nodes. (remm)
+      </fix>
+    </changelog>
+  </subsection>
   <subsection name="Web applications">
     <changelog>
       <add>


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to