Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Already on GitHub? Sign in to your account

SEC-1466: authentication-provider should reject child password-encoder element when used with ref attribute #1706

spring-issuemaster opened this Issue Apr 24, 2010 · 0 comments


None yet
1 participant

Nes Yarug (Migrated from SEC-1466) said:

Basically want to achieve the following (as was natural to me from reading the documentation and trying to adapt to my own situation):

<beans:bean id="passwordEncoder" class="org.springframework.security.authentication.encoding.ShaPasswordEncoder">
<beans:constructor-arg value="256"/>
<beans:bean id="saltSource" class="org.springframework.security.authentication.dao.ReflectionSaltSource">
<beans:property name="userPropertyToUse" value="username"/>
<beans:bean id="daoAuthenticationProvider" class="org.springframework.security.authentication.dao.DaoAuthenticationProvider">
<beans:property name="userDetailsService" ref="userDetailsService" />
<beans:property name="userCache">
<beans:bean class="org.springframework.security.core.userdetails.cache.EhCacheBasedUserCache">
<beans:property name="cache" ref="userCache" />

The above resulted in a null saltSource for daoAuthenticationProvider (but not a null passwordEncoder).

@spring-issuemaster spring-issuemaster added this to the 3.1.0.M1 milestone Feb 5, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment