runAs feature doesn't works
----------------------------
Key: SHIRO-344
URL: https://issues.apache.org/jira/browse/SHIRO-344
Project: Shiro
Issue Type: Bug
Components: Realms
Affects Versions: 1.2.0
Reporter: yourik
Fix For: 1.2.1
Right after SecurityUtils.getSubject().runAs(new new
SimplePrincipalCollection(){...})
SecurityUtils.getSubject().getPrincipal() returns correct new Principal
SecurityUtils.getSubject()..getPreviousPrincipals() returns correct original
Principal
but DefaultSubjectDAO merge principals in method
protected void mergePrincipals(Subject subject) {
PrincipalCollection currentPrincipals = subject.getPrincipals();
...
if (session == null) {
...
} else {
PrincipalCollection existingPrincipals = (PrincipalCollection)
session.getAttribute(DefaultSubjectContext.PRINCIPALS_SESSION_KEY);
if (CollectionUtils.isEmpty(currentPrincipals)) {
...
} else {
if (!currentPrincipals.equals(existingPrincipals)) {
session.setAttribute(DefaultSubjectContext.PRINCIPALS_SESSION_KEY,
currentPrincipals);
}
}
}
and after that
SecurityUtils.getSubject().getPrincipal() and
SecurityUtils.getSubject().getPreviousPrincipals() both returns new Principal -
this is wrong behavior
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators:
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira