Skip to content

Clear the WS-Security caller identity after the JAX-WS request - #3084

Open
rzo1 wants to merge 1 commit into
mainfrom
ws-security-login-cleanup
Open

rzo1 wants to merge 1 commit into
mainfrom
ws-security-login-cleanup

Conversation

@rzo1

@rzo1 rzo1 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

OpenEJBLoginValidator associated the UsernameToken identity with the worker thread and never released it, so it could leak to later requests on the same pooled thread. The previous state is now restored and every token login of the message is logged out, also when the chain fails or resumes on another thread. Covered by CxfWsContainerSecurityStateTest.

Every UsernameToken login of a message is undone on the thread which
did it, also when the chain fails or resumes on another thread.
@rzo1 rzo1 self-assigned this Oct 9, 2026
@rzo1
rzo1 requested a review from jungm October 9, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant