Skip to content

HTTP interfaces implemented by Netty may bypass the Spring Security filter chain. How can permission verification be performed? #17000

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
haojava opened this issue Apr 26, 2025 · 2 comments
Labels
status: feedback-reminder We've sent a reminder that we need additional information before we can continue status: waiting-for-feedback We need additional information before we can continue

Comments

@haojava
Copy link

haojava commented Apr 26, 2025

HTTP interfaces implemented by Netty may bypass the Spring Security filter chain. How can permission verification be performed?

@haojava haojava added status: waiting-for-triage An issue we've not yet triaged type: bug A general bug labels Apr 26, 2025
@jzheaux
Copy link
Contributor

jzheaux commented Apr 28, 2025

Hi, @haojava, I appreciate your question. I'll need more information to be able to address it, though. Could you, share a minimal GitHub sample that illustrates what is getting bypassed that you would hope Spring Security would intercept?

@jzheaux jzheaux added status: waiting-for-feedback We need additional information before we can continue and removed type: bug A general bug status: waiting-for-triage An issue we've not yet triaged labels Apr 28, 2025
@spring-projects-issues
Copy link

If you would like us to look at this issue, please provide the requested information. If the information is not provided within the next 7 days this issue will be closed.

@spring-projects-issues spring-projects-issues added the status: feedback-reminder We've sent a reminder that we need additional information before we can continue label May 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: feedback-reminder We've sent a reminder that we need additional information before we can continue status: waiting-for-feedback We need additional information before we can continue
Projects
None yet
Development

No branches or pull requests

3 participants