SessionRegistryImpl is now aware of SessionIdChangedEvent
This commit is contained in:
committed by
Eleftheria Stein
parent
ae532c080c
commit
5fc6414377
@@ -0,0 +1,29 @@
|
||||
/*
|
||||
* Copyright 2002-2016 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.springframework.security.core.session;
|
||||
|
||||
import org.springframework.context.ApplicationEvent;
|
||||
|
||||
public abstract class SessionIdChangedEvent extends ApplicationEvent {
|
||||
|
||||
public SessionIdChangedEvent(Object source) {
|
||||
super(source);
|
||||
}
|
||||
|
||||
public abstract String getOldSessionId();
|
||||
|
||||
public abstract String getNewSessionId();
|
||||
}
|
||||
@@ -18,6 +18,7 @@ package org.springframework.security.core.session;
|
||||
|
||||
import org.apache.commons.logging.Log;
|
||||
import org.apache.commons.logging.LogFactory;
|
||||
import org.springframework.context.ApplicationEvent;
|
||||
import org.springframework.context.ApplicationListener;
|
||||
import org.springframework.util.Assert;
|
||||
|
||||
@@ -40,7 +41,7 @@ import java.util.concurrent.CopyOnWriteArraySet;
|
||||
* @author Luke Taylor
|
||||
*/
|
||||
public class SessionRegistryImpl implements SessionRegistry,
|
||||
ApplicationListener<SessionDestroyedEvent> {
|
||||
ApplicationListener<ApplicationEvent> {
|
||||
|
||||
// ~ Instance fields
|
||||
// ================================================================================================
|
||||
@@ -101,9 +102,18 @@ public class SessionRegistryImpl implements SessionRegistry,
|
||||
return sessionIds.get(sessionId);
|
||||
}
|
||||
|
||||
public void onApplicationEvent(SessionDestroyedEvent event) {
|
||||
String sessionId = event.getId();
|
||||
removeSessionInformation(sessionId);
|
||||
public void onApplicationEvent(ApplicationEvent event) {
|
||||
if (event instanceof SessionDestroyedEvent) {
|
||||
SessionDestroyedEvent sessionDestroyedEvent = (SessionDestroyedEvent) event;
|
||||
String sessionId = sessionDestroyedEvent.getId();
|
||||
removeSessionInformation(sessionId);
|
||||
} else if (event instanceof SessionIdChangedEvent) {
|
||||
SessionIdChangedEvent sessionIdChangedEvent = (SessionIdChangedEvent) event;
|
||||
String oldSessionId = sessionIdChangedEvent.getOldSessionId();
|
||||
Object principal = sessionIds.get(oldSessionId).getPrincipal();
|
||||
removeSessionInformation(oldSessionId);
|
||||
registerNewSession(sessionIdChangedEvent.getNewSessionId(), principal);
|
||||
}
|
||||
}
|
||||
|
||||
public void refreshLastRequest(String sessionId) {
|
||||
|
||||
@@ -69,6 +69,33 @@ public class SessionRegistryImplTests {
|
||||
assertThat(sessionRegistry.getSessionInformation(sessionId)).isNull();
|
||||
}
|
||||
|
||||
@Test
|
||||
public void sessionIdChangedEventRemovesOldSessionAndAddsANewSession() {
|
||||
Object principal = "Some principal object";
|
||||
final String sessionId = "zzzz";
|
||||
final String newSessionId = "123";
|
||||
|
||||
// Register new Session
|
||||
sessionRegistry.registerNewSession(sessionId, principal);
|
||||
|
||||
// De-register session via an ApplicationEvent
|
||||
sessionRegistry.onApplicationEvent(new SessionIdChangedEvent("") {
|
||||
@Override
|
||||
public String getOldSessionId() {
|
||||
return sessionId;
|
||||
}
|
||||
|
||||
@Override
|
||||
public String getNewSessionId() {
|
||||
return newSessionId;
|
||||
}
|
||||
});
|
||||
|
||||
assertThat(sessionRegistry.getSessionInformation(sessionId)).isNull();
|
||||
assertThat(sessionRegistry.getSessionInformation(newSessionId)).isNotNull();
|
||||
assertThat(sessionRegistry.getSessionInformation(newSessionId).getPrincipal()).isEqualTo(principal);
|
||||
}
|
||||
|
||||
@Test
|
||||
public void testMultiplePrincipals() {
|
||||
Object principal1 = "principal_1";
|
||||
|
||||
Reference in New Issue
Block a user