This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch 10.1.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/10.1.x by this push:
     new 197b45cc79 Follow-up to "Synchronise the check for an existing nonce 
cache..."
197b45cc79 is described below

commit 197b45cc79d41454860a97f6f059f5f534ab4b1e
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Oct 1 17:22:11 2026 +0100

    Follow-up to "Synchronise the check for an existing nonce cache..."
    
    Fix a race when generating a nonce
---
 .../catalina/filters/RestCsrfPreventionFilter.java    | 19 ++++++++++++-------
 1 file changed, 12 insertions(+), 7 deletions(-)

diff --git a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java 
b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
index fc5676d9eb..d56d8683af 100644
--- a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
+++ b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
@@ -81,6 +81,7 @@ public class RestCsrfPreventionFilter extends 
CsrfPreventionFilterBase {
      */
     public RestCsrfPreventionFilter() {
     }
+
     private enum MethodType {
         NON_MODIFYING_METHOD,
         MODIFYING_METHOD
@@ -204,14 +205,18 @@ public class RestCsrfPreventionFilter extends 
CsrfPreventionFilterBase {
         public boolean apply(HttpServletRequest request, HttpServletResponse 
response) {
             String nonceFromRequest = nonceFromRequestHeader.getNonce(request, 
Constants.CSRF_REST_NONCE_HEADER_NAME);
             if (Objects.nonNull(nonceFromRequest) && 
fetchRequest.test(nonceFromRequest)) {
-                String nonceFromSessionStr = 
nonceFromSession.getNonce(request.getSession(false),
-                        Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
-                if (nonceFromSessionStr == null) {
-                    nonceFromSessionStr = generateNonce(request);
-                    
nonceToSession.setNonce(Objects.requireNonNull(request.getSession(true)),
-                            Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME, 
nonceFromSessionStr);
+                HttpSession session = request.getSession(true);
+                Objects.requireNonNull(session);
+                synchronized (session) {
+                    String nonceFromSessionStr =
+                            nonceFromSession.getNonce(session, 
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
+                    if (nonceFromSessionStr == null) {
+                        nonceFromSessionStr = generateNonce(request);
+                        nonceToSession.setNonce(session, 
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME,
+                                nonceFromSessionStr);
+                    }
+                    nonceToResponse.setNonce(response, 
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
                 }
-                nonceToResponse.setNonce(response, 
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
                 if (getLogger().isDebugEnabled()) {
                     
getLogger().debug(sm.getString("restCsrfPreventionFilter.fetch.debug", 
request.getMethod(),
                             request.getRequestURI()));


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to