8000 [Security] Fix SwitchUserToken wrongly deauthenticated · symfony/symfony@c280780 · GitHub
[go: up one dir, main page]

Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit c280780

Browse files
committed
[Security] Fix SwitchUserToken wrongly deauthenticated
1 parent bbbbb21 commit c280780

File tree

2 files changed

+41
-2
lines changed

2 files changed

+41
-2
lines changed

src/Symfony/Component/Security/Core/Authentication/Token/AbstractToken.php

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -318,9 +318,12 @@ private function hasUserChanged(UserInterface $user): bool
318318
}
319319

320320
$userRoles = array_map('strval', (array) $user->getRoles());
321-
$rolesChanged = \count($userRoles) !== \count($this->getRoleNames()) || \count($userRoles) !== \count(array_intersect($userRoles, $this->getRoleNames()));
322321

323-
if ($rolesChanged) {
322+
if ($this instanceof SwitchUserToken) {
323+
$userRoles[] = 'ROLE_PREVIOUS_ADMIN';
324+
}
325+
326+
if (\count($userRoles) !== \count($this->getRoleNames()) || \count($userRoles) !== \count(array_intersect($userRoles, $this->getRoleNames()))) {
324327
return true;
325328
}
326329

src/Symfony/Component/Security/Core/Tests/Authentication/Token/SwitchUserTokenTest.php

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@
1414
use PHPUnit\Framework\TestCase;
1515
use Symfony\Component\Security\Core\Authentication\Token\SwitchUserToken;
1616
use Symfony\Component\Security\Core\Authentication\Token\UsernamePasswordToken;
17+
use Symfony\Component\Security\Core\User\User;
18+
use Symfony\Component\Security\Core\User\UserInterface;
1719

1820
class SwitchUserTokenTest extends TestCase
1921
{
@@ -38,4 +40,38 @@ public function testSerialize()
3840
$this->assertSame('provider-key', $unserializedOriginalToken->getProviderKey());
3941
$this->assertEquals(['ROLE_ADMIN', 'ROLE_ALLOWED_TO_SWITCH'], $unserializedOriginalToken->getRoleNames());
4042
}
43+
44+
public function testSetUserDoesNotDeauthenticate()
45+
{
46+
$impersonated = new class implements UserInterface {
47+
public function getUsername()
48+
{
49+
return 'impersonated';
50+
}
51+
52+
public function getPassword()
53+
{
54+
return null;
55+
}
56+
57+
public function eraseCredentials()
58+
{
59+
}
60+
61+
public function getRoles()
62+
{
63+
return ['ROLE_USER'];
64+
}
65+
66+
public function getSalt()
67+
{
68+
return null;
69+
}
70+
};
71+
72+
$originalToken = new UsernamePasswordToken('impersonator', 'foo', 'provider-key', ['ROLE_ADMIN', 'ROLE_ALLOWED_TO_SWITCH']);
73+
$token = new SwitchUserToken($impersonated, 'bar', 'provider-key', ['ROLE_USER', 'ROLE_PREVIOUS_ADMIN'], $originalToken);
74+
$token->setUser($impersonated);
75+
$this->assertTrue($token->isAuthenticated());
76+
}
4177
}

0 commit comments

Comments
 (0)
0