This is an automated email from the ASF dual-hosted git repository.
markt-asf pushed a commit to branch 10.1.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git
The following commit(s) were added to refs/heads/10.1.x by this push:
new 197b45cc79 Follow-up to "Synchronise the check for an existing nonce
cache..."
197b45cc79 is described below
commit 197b45cc79d41454860a97f6f059f5f534ab4b1e
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Oct 1 17:22:11 2026 +0100
Follow-up to "Synchronise the check for an existing nonce cache..."
Fix a race when generating a nonce
---
.../catalina/filters/RestCsrfPreventionFilter.java | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
index fc5676d9eb..d56d8683af 100644
--- a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
+++ b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
@@ -81,6 +81,7 @@ public class RestCsrfPreventionFilter extends
CsrfPreventionFilterBase {
*/
public RestCsrfPreventionFilter() {
}
+
private enum MethodType {
NON_MODIFYING_METHOD,
MODIFYING_METHOD
@@ -204,14 +205,18 @@ public class RestCsrfPreventionFilter extends
CsrfPreventionFilterBase {
public boolean apply(HttpServletRequest request, HttpServletResponse
response) {
String nonceFromRequest = nonceFromRequestHeader.getNonce(request,
Constants.CSRF_REST_NONCE_HEADER_NAME);
if (Objects.nonNull(nonceFromRequest) &&
fetchRequest.test(nonceFromRequest)) {
- String nonceFromSessionStr =
nonceFromSession.getNonce(request.getSession(false),
- Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
- if (nonceFromSessionStr == null) {
- nonceFromSessionStr = generateNonce(request);
-
nonceToSession.setNonce(Objects.requireNonNull(request.getSession(true)),
- Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME,
nonceFromSessionStr);
+ HttpSession session = request.getSession(true);
+ Objects.requireNonNull(session);
+ synchronized (session) {
+ String nonceFromSessionStr =
+ nonceFromSession.getNonce(session,
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
+ if (nonceFromSessionStr == null) {
+ nonceFromSessionStr = generateNonce(request);
+ nonceToSession.setNonce(session,
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME,
+ nonceFromSessionStr);
+ }
+ nonceToResponse.setNonce(response,
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
}
- nonceToResponse.setNonce(response,
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
if (getLogger().isDebugEnabled()) {
getLogger().debug(sm.getString("restCsrfPreventionFilter.fetch.debug",
request.getMethod(),
request.getRequestURI()));
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]