Browse Source

Deprecate storage of Authentication object in AuthenticationException.

pull/1/head
Luke Taylor 15 years ago
parent
commit
8fd2963e6b
  1. 3
      core/src/main/java/org/springframework/security/core/AuthenticationException.java

3
core/src/main/java/org/springframework/security/core/AuthenticationException.java

@ -64,11 +64,14 @@ public abstract class AuthenticationException extends RuntimeException { @@ -64,11 +64,14 @@ public abstract class AuthenticationException extends RuntimeException {
/**
* The authentication request which this exception corresponds to (may be {@code null})
* @deprecated to avoid potential leaking of sensitive information (e.g. through serialization/remoting).
*/
@Deprecated
public Authentication getAuthentication() {
return authentication;
}
@Deprecated
public void setAuthentication(Authentication authentication) {
this.authentication = authentication;
}

Loading…
Cancel
Save