Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Already on GitHub? Sign in to your account

SEC-1151: Check on acl bounds not correct #1399

spring-issuemaster opened this Issue May 4, 2009 · 1 comment


None yet
1 participant

Taylor Mathewson (Migrated from SEC-1151) said:

On line 130 of AclImpl.java in trunk (line number is different in other releases) a check is performed on the upper bound of the list of access control entries.

Code is:
if (aceIndex > this.aces.size()) {

should be:
if (aceIndex >= this.aces.size()) {

Result is that exception out of underlying list impl is thrown. Minor.

Luke Taylor said:

Thanks for the report. I've updated AclImpl and added some extra tests.

I'm not sure that an IndexOutOfBoundsException might not be more appopriate in this case but we'll stick with the existing API.

@spring-issuemaster spring-issuemaster added this to the 3.0.0 M1 milestone Feb 5, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment