This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch 9.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/9.0.x by this push:
     new 44428a2030 Follow-up to "Synchronise the check for an existing nonce 
cache..."
44428a2030 is described below

commit 44428a20309517b977dc0d7e067adced2f07c317
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Oct 1 17:22:11 2026 +0100

    Follow-up to "Synchronise the check for an existing nonce cache..."
    
    Fix a race when generating a nonce
---
 .../catalina/filters/RestCsrfPreventionFilter.java    | 19 ++++++++++++-------
 1 file changed, 12 insertions(+), 7 deletions(-)

diff --git a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java 
b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
index 427aeabe14..4149f1c4e9 100644
--- a/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
+++ b/java/org/apache/catalina/filters/RestCsrfPreventionFilter.java
@@ -81,6 +81,7 @@ public class RestCsrfPreventionFilter extends 
CsrfPreventionFilterBase {
      */
     public RestCsrfPreventionFilter() {
     }
+
     private enum MethodType {
         NON_MODIFYING_METHOD,
         MODIFYING_METHOD
@@ -204,14 +205,18 @@ public class RestCsrfPreventionFilter extends 
CsrfPreventionFilterBase {
         public boolean apply(HttpServletRequest request, HttpServletResponse 
response) {
             String nonceFromRequest = nonceFromRequestHeader.getNonce(request, 
Constants.CSRF_REST_NONCE_HEADER_NAME);
             if (Objects.nonNull(nonceFromRequest) && 
fetchRequest.test(nonceFromRequest)) {
-                String nonceFromSessionStr = 
nonceFromSession.getNonce(request.getSession(false),
-                        Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
-                if (nonceFromSessionStr == null) {
-                    nonceFromSessionStr = generateNonce(request);
-                    
nonceToSession.setNonce(Objects.requireNonNull(request.getSession(true)),
-                            Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME, 
nonceFromSessionStr);
+                HttpSession session = request.getSession(true);
+                Objects.requireNonNull(session);
+                synchronized (session) {
+                    String nonceFromSessionStr =
+                            nonceFromSession.getNonce(session, 
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME);
+                    if (nonceFromSessionStr == null) {
+                        nonceFromSessionStr = generateNonce(request);
+                        nonceToSession.setNonce(session, 
Constants.CSRF_REST_NONCE_SESSION_ATTR_NAME,
+                                nonceFromSessionStr);
+                    }
+                    nonceToResponse.setNonce(response, 
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
                 }
-                nonceToResponse.setNonce(response, 
Constants.CSRF_REST_NONCE_HEADER_NAME, nonceFromSessionStr);
                 if (getLogger().isDebugEnabled()) {
                     
getLogger().debug(sm.getString("restCsrfPreventionFilter.fetch.debug", 
request.getMethod(),
                             request.getRequestURI()));


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to