[
https://issues.apache.org/jira/browse/CXF-7374?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16015909#comment-16015909
]
ASF GitHub Bot commented on CXF-7374:
-------------------------------------
GitHub user vgagara-talend opened a pull request:
https://github.com/apache/cxf/pull/273
lock RefreshToken entity with pissimistic locking to avoid concurrent
updates
issue: https://issues.apache.org/jira/browse/CXF-7374
orig issue: https://jira.talendforge.org/browse/TPSVC-2439
You can merge this pull request into a Git repository by running:
$ git pull https://github.com/vgagara-talend/cxf
cxf-7374-concurrent-access-token-refresh
Alternatively you can review and apply these changes as the patch at:
https://github.com/apache/cxf/pull/273.patch
To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:
This closes #273
----
commit 17f3a8bff79a29ae74a3bc12317519fb50863e86
Author: Viacheslav Gagara <[email protected]>
Date: 2017-05-18T15:02:01Z
lock RefreshToken entity with pissimistic locking to avoid concurrent
updates (unit test added)
----
> Concurrent calls to refreshAccessToken() fails with SQL constraint violation
> ----------------------------------------------------------------------------
>
> Key: CXF-7374
> URL: https://issues.apache.org/jira/browse/CXF-7374
> Project: CXF
> Issue Type: Bug
> Components: JAX-RS Security
> Affects Versions: 3.2.0
> Reporter: Viacheslav Gagara
> Fix For: 3.2.0, 3.1.12
>
>
> When recycleRefreshTokens=false concurrent calls to refreshAccessToken()
> cause SQLException (2 accessTokens are created simultaneously and added to
> RefreshToken#accessTokens with the same index from different threads)
> {code}
> Batch entry 0 insert into RefreshToken_accessTokens (RefreshToken_tokenKey,
> accessTokens_ORDER, accessTokens) values ('fced31aaba6723ecc5956721e8f029f1',
> 1, '8c559d9f738f33a1b866e7172c9e5644') was aborted: ERROR: duplicate key
> value violates unique constraint "refreshtoken_accesstokens_pkey"
> Detail: Key (refreshtoken_tokenkey,
> accesstokens_order)=(fced31aaba6723ecc5956721e8f029f1, 1) already exists.
> {code}
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)