This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 947b2d0e53f60b14935519ab5d9c6456477e2dfd
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 13:40:25 2026 +0200

    Validate the incoming entry at the start of 
NamingResourcesImpl.addEnvironment() so that an entry which is ignored or 
rejected cannot first destroy the existing environment entry or resource link 
with the same name
---
 .../catalina/deploy/NamingResourcesImpl.java       | 44 ++++++++++++----------
 1 file changed, 24 insertions(+), 20 deletions(-)

diff --git a/java/org/apache/catalina/deploy/NamingResourcesImpl.java 
b/java/org/apache/catalina/deploy/NamingResourcesImpl.java
index 9d15e54666..e97f1706e9 100644
--- a/java/org/apache/catalina/deploy/NamingResourcesImpl.java
+++ b/java/org/apache/catalina/deploy/NamingResourcesImpl.java
@@ -236,6 +236,30 @@ public class NamingResourcesImpl extends 
LifecycleMBeanBase implements Serializa
     @Override
     public void addEnvironment(ContextEnvironment environment) {
 
+        List<InjectionTarget> injectionTargets = 
environment.getInjectionTargets();
+        String value = environment.getValue();
+        String lookupName = environment.getLookupName();
+
+        // Validate the new entry before any existing entry is removed below.
+        // Otherwise, an invalid new entry would silently destroy a valid
+        // existing one.
+
+        // Entries with injection targets but no value are effectively ignored
+        if (injectionTargets != null && !injectionTargets.isEmpty() && (value 
== null || value.isEmpty())) {
+            return;
+        }
+
+        // Entries with lookup-name and value are an error (EE.5.4.1.3)
+        if (value != null && !value.isEmpty() && lookupName != null && 
!lookupName.isEmpty()) {
+            throw new IllegalArgumentException(
+                    sm.getString("namingResources.envEntryLookupValue", 
environment.getName()));
+        }
+
+        if (!checkResourceType(environment)) {
+            throw new IllegalArgumentException(
+                    sm.getString("namingResources.resourceTypeFail", 
environment.getName(), environment.getType()));
+        }
+
         if (entries.contains(environment.getName())) {
             ContextEnvironment ce = findEnvironment(environment.getName());
             ContextResourceLink rl = findResourceLink(environment.getName());
@@ -265,26 +289,6 @@ public class NamingResourcesImpl extends 
LifecycleMBeanBase implements Serializa
             }
         }
 
-        List<InjectionTarget> injectionTargets = 
environment.getInjectionTargets();
-        String value = environment.getValue();
-        String lookupName = environment.getLookupName();
-
-        // Entries with injection targets but no value are effectively ignored
-        if (injectionTargets != null && !injectionTargets.isEmpty() && (value 
== null || value.isEmpty())) {
-            return;
-        }
-
-        // Entries with lookup-name and value are an error (EE.5.4.1.3)
-        if (value != null && !value.isEmpty() && lookupName != null && 
!lookupName.isEmpty()) {
-            throw new IllegalArgumentException(
-                    sm.getString("namingResources.envEntryLookupValue", 
environment.getName()));
-        }
-
-        if (!checkResourceType(environment)) {
-            throw new IllegalArgumentException(
-                    sm.getString("namingResources.resourceTypeFail", 
environment.getName(), environment.getType()));
-        }
-
         entries.add(environment.getName());
 
         synchronized (envs) {


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to