Skip to content

Commit

Permalink
Fixing `NotSerializableException: org.acegisecurity.context.SecurityC…
Browse files Browse the repository at this point in the history
…ontext$1` (#8918)
  • Loading branch information
jglick authored Feb 1, 2024
1 parent c00a30d commit ddf68d3
Show file tree
Hide file tree
Showing 2 changed files with 115 additions and 25 deletions.
71 changes: 46 additions & 25 deletions core/src/main/java/org/acegisecurity/context/SecurityContext.java
Original file line number Diff line number Diff line change
Expand Up @@ -27,46 +27,67 @@
import edu.umd.cs.findbugs.annotations.NonNull;
import hudson.model.User;
import hudson.security.ACL;
import java.io.Serializable;
import org.acegisecurity.Authentication;
import org.kohsuke.accmod.Restricted;
import org.kohsuke.accmod.restrictions.NoExternalUse;

/**
* @deprecated Use {@link ACL#as(User)} or {@link org.springframework.security.core.context.SecurityContext}
*/
@Deprecated
public interface SecurityContext {
public interface SecurityContext extends Serializable {

Authentication getAuthentication();

void setAuthentication(Authentication a);

static @NonNull SecurityContext fromSpring(@NonNull org.springframework.security.core.context.SecurityContext c) {
return new SecurityContext() {
@Override
public Authentication getAuthentication() {
org.springframework.security.core.Authentication a = c.getAuthentication();
return a != null ? Authentication.fromSpring(a) : null;
}

@Override
public void setAuthentication(Authentication a) {
c.setAuthentication(a != null ? a.toSpring() : null);
}
};
return new FromSpring(c);
}

@Restricted(NoExternalUse.class)
class FromSpring implements SecurityContext {
private final org.springframework.security.core.context.SecurityContext c;

FromSpring(org.springframework.security.core.context.SecurityContext c) {
this.c = c;
}

@Override
public Authentication getAuthentication() {
org.springframework.security.core.Authentication a = c.getAuthentication();
return a != null ? Authentication.fromSpring(a) : null;
}

@Override
public void setAuthentication(Authentication a) {
c.setAuthentication(a != null ? a.toSpring() : null);
}
}

default @NonNull org.springframework.security.core.context.SecurityContext toSpring() {
return new org.springframework.security.core.context.SecurityContext() {
@Override
public org.springframework.security.core.Authentication getAuthentication() {
Authentication a = SecurityContext.this.getAuthentication();
return a != null ? a.toSpring() : null;
}

@Override
public void setAuthentication(org.springframework.security.core.Authentication authentication) {
SecurityContext.this.setAuthentication(authentication != null ? Authentication.fromSpring(authentication) : null);
}
};
return new ToSpring(this);
}

@Restricted(NoExternalUse.class)
class ToSpring implements org.springframework.security.core.context.SecurityContext {
private final SecurityContext c;

ToSpring(SecurityContext c) {
this.c = c;
}

@Override
public org.springframework.security.core.Authentication getAuthentication() {
Authentication a = c.getAuthentication();
return a != null ? a.toSpring() : null;
}

@Override
public void setAuthentication(org.springframework.security.core.Authentication authentication) {
c.setAuthentication(authentication != null ? Authentication.fromSpring(authentication) : null);
}
}

}
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
/*
* The MIT License
*
* Copyright 2024 CloudBees, Inc.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in
* all copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
* THE SOFTWARE.
*/

package org.acegisecurity.context;

import static org.hamcrest.MatcherAssert.assertThat;
import static org.hamcrest.Matchers.is;

import java.io.ByteArrayInputStream;
import java.io.ByteArrayOutputStream;
import java.io.ObjectInputStream;
import java.io.ObjectOutputStream;
import org.acegisecurity.providers.UsernamePasswordAuthenticationToken;
import org.junit.jupiter.api.Test;

@SuppressWarnings("deprecation")
public class SecurityContextTest {

@Test
public void serializabilityFromSpring() throws Exception {
org.springframework.security.core.context.SecurityContext spring1 = new org.springframework.security.core.context.SecurityContextImpl();
spring1.setAuthentication(new org.springframework.security.authentication.UsernamePasswordAuthenticationToken("user", null));
SecurityContext acegi1 = SecurityContext.fromSpring(spring1);
SecurityContext acegi2 = serDeser(SecurityContext.class, acegi1);
org.springframework.security.core.context.SecurityContext spring2 = acegi2.toSpring();
assertThat(spring2.getAuthentication().getPrincipal(), is("user"));
}

@Test
public void serializabilityToSpring() throws Exception {
SecurityContext acegi1 = new SecurityContextImpl();
acegi1.setAuthentication(new UsernamePasswordAuthenticationToken("user", null));
org.springframework.security.core.context.SecurityContext spring1 = acegi1.toSpring();
org.springframework.security.core.context.SecurityContext spring2 = serDeser(org.springframework.security.core.context.SecurityContext.class, spring1);
SecurityContext acegi2 = SecurityContext.fromSpring(spring2);
assertThat(acegi2.getAuthentication().getPrincipal(), is("user"));
}

private static <T> T serDeser(Class<T> type, T object) throws Exception {
try (ByteArrayOutputStream baos = new ByteArrayOutputStream(); ObjectOutputStream oos = new ObjectOutputStream(baos)) {
oos.writeObject(object);
try (ByteArrayInputStream bais = new ByteArrayInputStream(baos.toByteArray()); ObjectInputStream ois = new ObjectInputStream(bais)) {
return type.cast(ois.readObject());
}
}
}

}

0 comments on commit ddf68d3

Please sign in to comment.