Bug 779762 (SOA-2124) - JBossASContextPropagation should be using SecurityContextAssociation in AS5 environments, at present it uses SecurityAssociation
Summary: JBossASContextPropagation should be using SecurityContextAssociation in AS5 e...
Keywords:
Status: CLOSED NEXTRELEASE
Alias: SOA-2124
Product: JBoss Enterprise SOA Platform 5
Classification: JBoss
Component: unspecified
Version: 5.0.0 GA
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
: 5.0.2
Assignee: Kevin Conner
QA Contact:
URL: http://jira.jboss.org/jira/browse/SOA...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-06-15 11:35 UTC by Kevin Conner
Modified: 2010-07-08 13:59 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-07-08 13:59:43 UTC
Type: Bug


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SOA-2124 0 Critical Closed JBossASContextPropagation should be using SecurityContextAssociation in AS5 environments, at present it uses SecurityAss... 2013-11-07 15:56:04 UTC

Description Kevin Conner 2010-06-15 11:35:53 UTC
Date of First Response: 2010-06-15 20:33:59
project_key: SOA

Comment 1 Kevin Conner 2010-06-15 11:36:16 UTC
Link: Added: This issue depends JBESB-3346


Comment 2 Kevin Conner 2010-06-15 11:50:00 UTC
Updated in ESB codebase, will be in next tag for the platform.

Comment 3 Dana Mison 2010-06-16 00:33:59 UTC
More information required for SOA 5.0.2 releases notes:

"JBossASContextPropagation should be using SecurityContextAssociation in AS5 environments, at present it uses SecurityAssociation"

JBossASContextPropagation is a class/method/??? in ESB ? I couldn't find it in the JavaDocs

Likewise SecurityContextAssociation/SecurityAssociation are methods/classes/enumerations/???

* The AS4 behaviour was being used even when running on AS5.  
Would this have presented any particular behaviour or problems?  Is there an issue that an admin/devel might have had that this would resolve ?  

Assuming that this was fixed by putting in a check for the environment ?

Comment 4 Kevin Conner 2010-06-16 08:54:39 UTC
JBossASContextPropagation is an internal class which is used to propagate the security context to other modules within an app server environment.  It is responsible for creating/destroying the associated context around the execution of an action pipeline.

The AS4 context is initialised using SecurityAssociation (jbosssx class, initialising subject, principal, credential, runas) whereas the AS5 context is initialised using SecurityContextAssociation (jbosssx class initialising all previous plus security domain)

The AS5 implementation of SecurityAssociation maps on to the SecurityContextAssociation, but what was missing was the security domain information.

Comment 5 Dana Mison 2010-06-22 05:22:58 UTC
Added to the SOA 5.1 release notes as resolved:

JBESB-3346
JBossASContextPropagation was using the class SecurityAssociation instead of SecurityContextAssociation.  SecurityContextAssociation contains 
security domain information in addition to the information included in SecurityAssociation.  The correct class is now used.

Comment 6 Martin Vecera 2010-07-08 13:59:43 UTC
Verified in 5.0.2.CR3


Note You need to log in before you can comment on or make changes to this bug.