SEC-1039: Corrected reference to security context key to match new value.

This commit is contained in:
Luke Taylor 2008-12-05 14:52:52 +00:00
parent a650b73550
commit fd7fc0c8a5

View File

@ -12,7 +12,7 @@ import org.springframework.security.Authentication;
import org.springframework.security.AuthenticationTrustResolver;
import org.springframework.security.AuthenticationTrustResolverImpl;
import org.springframework.security.concurrent.SessionRegistry;
import org.springframework.security.context.HttpSessionContextIntegrationFilter;
import org.springframework.security.context.HttpSessionSecurityContextRepository;
import org.springframework.security.context.SecurityContext;
import org.springframework.security.context.SecurityContextHolder;
import org.springframework.security.util.SessionUtils;
@ -57,7 +57,7 @@ public class SessionFixationProtectionFilter extends SpringSecurityFilter {
HttpSession session = request.getSession();
SecurityContext sessionSecurityContext =
(SecurityContext) session.getAttribute(HttpSessionContextIntegrationFilter.SPRING_SECURITY_CONTEXT_KEY);
(SecurityContext) session.getAttribute(HttpSessionSecurityContextRepository.SPRING_SECURITY_CONTEXT_KEY);
if (sessionSecurityContext == null && isAuthenticated()) {
// The user has been authenticated during the current request, so do the session migration
@ -78,10 +78,10 @@ public class SessionFixationProtectionFilter extends SpringSecurityFilter {
}
public void setSessionRegistry(SessionRegistry sessionRegistry) {
this.sessionRegistry = sessionRegistry;
}
this.sessionRegistry = sessionRegistry;
}
public int getOrder() {
public int getOrder() {
return FilterChainOrder.SESSION_FIXATION_FILTER;
}