]> git.argeo.org Git - lgpl/argeo-commons.git/blobdiff - security/runtime/org.argeo.security.core/src/main/java/org/argeo/security/core/KeyBasedSystemExecutionService.java
Improve RCP security
[lgpl/argeo-commons.git] / security / runtime / org.argeo.security.core / src / main / java / org / argeo / security / core / KeyBasedSystemExecutionService.java
index 08ef6428ad925f9cc19db8ffece144002df41218..3235a9602bdad53f8aed8dcfe05765644353fdf1 100644 (file)
@@ -1,5 +1,10 @@
 package org.argeo.security.core;
 
+import java.security.AccessController;
+
+import javax.security.auth.Subject;
+
+import org.argeo.ArgeoException;
 import org.argeo.security.SystemExecutionService;
 import org.springframework.core.task.SimpleAsyncTaskExecutor;
 import org.springframework.core.task.TaskExecutor;
@@ -36,6 +41,23 @@ public class KeyBasedSystemExecutionService implements SystemExecutionService,
                        public void run() {
                                SecurityContext securityContext = SecurityContextHolder
                                                .getContext();
+                               Authentication currentAuth = securityContext
+                                               .getAuthentication();
+                               if (currentAuth != null)
+                                       throw new ArgeoException(
+                                                       "System execution on an already authenticated thread: "
+                                                                       + currentAuth + ", THREAD="
+                                                                       + Thread.currentThread().getId());
+
+                               Subject subject = Subject.getSubject(AccessController
+                                               .getContext());
+                               if (subject != null
+                                               && !subject.getPrincipals(Authentication.class)
+                                                               .isEmpty())
+                                       throw new ArgeoException(
+                                                       "There is already an authenticated subject: "
+                                                                       + subject);
+
                                Authentication auth = authenticationManager
                                                .authenticate(new InternalAuthentication(
                                                                systemAuthenticationKey));