This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 10.1.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 2bd518c3ac1ef8c7b759318365972bf1f1c7f78b
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 13:40:25 2026 +0200

    Validate the incoming entry at the start of 
NamingResourcesImpl.addEnvironment() so that an entry which is ignored or 
rejected cannot first destroy the existing environment entry or resource link 
with the same name
---
 .../catalina/deploy/NamingResourcesImpl.java       | 44 ++++++++++++----------
 1 file changed, 24 insertions(+), 20 deletions(-)

diff --git a/java/org/apache/catalina/deploy/NamingResourcesImpl.java 
b/java/org/apache/catalina/deploy/NamingResourcesImpl.java
index f795ed9db2..47f35e95f6 100644
--- a/java/org/apache/catalina/deploy/NamingResourcesImpl.java
+++ b/java/org/apache/catalina/deploy/NamingResourcesImpl.java
@@ -234,6 +234,30 @@ public class NamingResourcesImpl extends 
LifecycleMBeanBase implements Serializa
     @Override
     public void addEnvironment(ContextEnvironment environment) {
 
+        List<InjectionTarget> injectionTargets = 
environment.getInjectionTargets();
+        String value = environment.getValue();
+        String lookupName = environment.getLookupName();
+
+        // Validate the new entry before any existing entry is removed below.
+        // Otherwise, an invalid new entry would silently destroy a valid
+        // existing one.
+
+        // Entries with injection targets but no value are effectively ignored
+        if (injectionTargets != null && !injectionTargets.isEmpty() && (value 
== null || value.isEmpty())) {
+            return;
+        }
+
+        // Entries with lookup-name and value are an error (EE.5.4.1.3)
+        if (value != null && !value.isEmpty() && lookupName != null && 
!lookupName.isEmpty()) {
+            throw new IllegalArgumentException(
+                    sm.getString("namingResources.envEntryLookupValue", 
environment.getName()));
+        }
+
+        if (!checkResourceType(environment)) {
+            throw new IllegalArgumentException(
+                    sm.getString("namingResources.resourceTypeFail", 
environment.getName(), environment.getType()));
+        }
+
         if (entries.contains(environment.getName())) {
             ContextEnvironment ce = findEnvironment(environment.getName());
             ContextResourceLink rl = findResourceLink(environment.getName());
@@ -263,26 +287,6 @@ public class NamingResourcesImpl extends 
LifecycleMBeanBase implements Serializa
             }
         }
 
-        List<InjectionTarget> injectionTargets = 
environment.getInjectionTargets();
-        String value = environment.getValue();
-        String lookupName = environment.getLookupName();
-
-        // Entries with injection targets but no value are effectively ignored
-        if (injectionTargets != null && !injectionTargets.isEmpty() && (value 
== null || value.isEmpty())) {
-            return;
-        }
-
-        // Entries with lookup-name and value are an error (EE.5.4.1.3)
-        if (value != null && !value.isEmpty() && lookupName != null && 
!lookupName.isEmpty()) {
-            throw new IllegalArgumentException(
-                    sm.getString("namingResources.envEntryLookupValue", 
environment.getName()));
-        }
-
-        if (!checkResourceType(environment)) {
-            throw new IllegalArgumentException(
-                    sm.getString("namingResources.resourceTypeFail", 
environment.getName(), environment.getType()));
-        }
-
         entries.add(environment.getName());
 
         synchronized (envs) {


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to