|Summary:||dynamic servlet security incomplete and badly distributed|
|Product:||Tomcat 7||Reporter:||david jencks <djencks>|
|Component:||Catalina||Assignee:||Tomcat Developers Mailing List <dev>|
|Attachments:||patch for improved dynamic servlet security implementations|
Description david jencks 2010-09-27 16:22:54 UTC
The current implementation of dynamic servlet security through ServletRegistration.Dynamic.setServletSecurity and the ServletContext.createServlet and addServlet methods is incomplete, and includes some logic that exposes internals of the tomcat security framework directly in the ServletRegistration.Dynamic implementation. The attached patch: - moves the logic that depends on the internals of tomcats security implementation from ApplicationServletRegistration to StandardContext where it can at least be overridden by e.g. jacc implementations - provides notifications to StandardContext of users calling createServlet and addServlet on ApplicationContext/ServletContext so subclasses of StandardContext can implement the spec behavior without subclassing ApplicationContext. This patch is generated from a tomcat copy that already has several other patches I've proposed applied. Let me know if there are problems applying it.
Comment 1 david jencks 2010-09-27 16:24:07 UTC
Created attachment 26088 [details] patch for improved dynamic servlet security implementations
Comment 2 Mark Thomas 2010-10-08 09:22:03 UTC
Thanks. Patch applied. Will be in 7.0.4 onwards.