interview-com-ua / website

8 stars 23 forks source link

Fix security vulnerability / fix storing SecurityContext in HttpSession #107

Closed rilaby closed 10 years ago

rilaby commented 10 years ago

...

rilaby commented 10 years ago

Consider: http://docs.spring.io/spring-security/site/docs/3.2.x/reference/htmlsingle/#tech-intro-sec-context-persistence

org.springframework.security.web.context.SecurityContextPersistenceFilter does the job of storing SercurityContext in org.springframework.security.web.context.SecurityContextRepository on the response sent out and retrieves it on request comes in.