Spring Security 4 with GraniteDS

147 views Asked by At

I upgraded to the latest version of Spring Security 4.0.2, and I'm getting the following error

java.lang.NullPointerException
at org.granite.messaging.amf.io.AMF0Serializer.serializeMessage(AMF0Serializer.java:113)
at org.granite.messaging.webapp.AMFMessageFilter.doAMFFilter(AMFMessageFilter.java:153)
at org.granite.messaging.webapp.AMFMessageFilter.doFilter(AMFMessageFilter.java:103)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:239)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:219)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:106)
at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:614)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:142)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:79)
at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:617)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:88)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:518)
at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1091)
at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:668)
at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1521)
at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.run(NioEndpoint.java:1478)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
at java.lang.Thread.run(Thread.java:744)

I'm using GraniteDS 3.1.1.GA, Spring 4.2 and my granite-config.xml file has

<security type="org.granite.spring.security.SpringSecurity3Service"/>

I can see it has specifically Spring3 in it, but not sure how to go around this.

1

There are 1 answers

0
kayoubi On

in spring security 4 csrf was enabled by default which caused this issue! disabling it fixed the problem. Something like:

<http pattern="/graniteamf/**" etc.. >
    <intercept-url pattern="/graniteamf/**" />
    <csrf disabled="true"/>
</http>