Search code examples

Trouble saving session when mixing spring-security-gemfire and spring-security-oauth2

Background: I have a web app that utilizes AngularJS, spring-mvc, and spring-rest for delivering the UI. I have a requirement to load balance using an Elastic LB and it is not using sticky sessions; requests are round robin. I implemented session replication using spring-session with gemfire for session storage. This works well.

I need to integrate with an OAuth2 auth server (and eventually multiple OAuth2 servers) purely for authentication and the passing of userInfo. I attempted to use the spring cloud oauth2 @EnableOAuth2Sso on the web-app and hit some session serialization issues. The mere addition of the oauth2ClientContext to the session seemed to cause ClassCastException problems during session saving.

I attempted to pull down the following samples and they worked well out of the box, Particularly the UI and the Authserver.

However, when I added spring session into the mix, trying to serialize to a gemfire server, I encountered the exact same issue.

Here is the stacktrace highlight:

java.lang.ClassCastException: cannot assign instance of to field org.springframework.aop.scope.DefaultScopedObject.beanFactory of type org.springframework.beans.factory.config.ConfigurableBeanFactory in instance of org.springframework.aop.scope.DefaultScopedObject

Below is abbreviated stacktrace:

ERROR o.a.c.c.C.[.[.[/].[dispatcherServlet]    : Servlet.service() for servlet [dispatcherServlet] in context with path [] threw exception

org.springframework.dao.DataAccessResourceFailureException: remote server on machine(gemfire:21800:loner):57660:9d1f3438:gemfire: : While performing a remote put; nested exception is com.gemstone.gemfire.cache.client.ServerOperationException: remote server on machine(gemfire:21800:loner):57660:9d1f3438:gemfire: : While performing a remote put
    at ~[spring-data-gemfire-1.7.4.RELEASE.jar:1.7.4.RELEASE]
    at ~[spring-data-gemfire-1.7.4.RELEASE.jar:1.7.4.RELEASE]
    at ~[spring-data-gemfire-1.7.4.RELEASE.jar:1.7.4.RELEASE]
    at ~[spring-session-1.2.1.RELEASE.jar:na]
    at ~[spring-session-1.2.1.RELEASE.jar:na]
    at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.commitSession( ~[spring-session-1.2.1.RELEASE.jar:na]
    at org.springframework.session.web.http.SessionRepositoryFilter$SessionRepositoryRequestWrapper.access$100( ~[spring-session-1.2.1.RELEASE.jar:na]
    at org.springframework.session.web.http.SessionRepositoryFilter.doFilterInternal( ~[spring-session-1.2.1.RELEASE.jar:na]
    at org.springframework.session.web.http.OncePerRequestFilter.doFilter( ~[spring-session-1.2.1.RELEASE.jar:na]
    ... tomcat filter chain and spring filter stuff
Caused by: com.gemstone.gemfire.cache.client.ServerOperationException: remote server on machine(gemfire:21800:loner):57660:9d1f3438:gemfire: : While performing a remote put
    ... gemfire internal stuff
    at ~[spring-data-gemfire-1.7.4.RELEASE.jar:1.7.4.RELEASE]
    ... 31 common frames omitted
Caused by: java.lang.ClassCastException: cannot assign instance of to field org.springframework.aop.scope.DefaultScopedObject.beanFactory of type org.springframework.beans.factory.config.ConfigurableBeanFactory in instance of org.springframework.aop.scope.DefaultScopedObject
    at$FieldReflector.setObjFieldValues( ~[na:1.7.0_80]
    at ~[na:1.7.0_80]
    ... stuff
    at org.springframework.aop.framework.AdvisedSupport.readObject( ~[spring-aop-4.3.2.RELEASE.jar:4.3.2.RELEASE]
    at sun.reflect.GeneratedMethodAccessor224.invoke(Unknown Source) ~[na:na]
    at sun.reflect.DelegatingMethodAccessorImpl.invoke( ~[na:1.7.0_80]
    at java.lang.reflect.Method.invoke( ~[na:1.7.0_80]
    at ~[na:1.7.0_80]
    ... stuff
    at com.gemstone.gemfire.internal.InternalDataSerializer.basicReadObject( ~[gemfire-8.1.0.jar:na]
    at com.gemstone.gemfire.DataSerializer.readObject( ~[gemfire-8.1.0.jar:na]
    at$GemFireSessionAttributes.readObject( ~[spring-session-1.2.1.RELEASE.jar:na]
    at$GemFireSessionAttributes.fromDelta( ~[spring-session-1.2.1.RELEASE.jar:na]
    at$GemFireSession.fromDelta( ~[spring-session-1.2.1.RELEASE.jar:na]
    at com.gemstone.gemfire.internal.cache.EntryEventImpl.processDeltaBytes( ~[gemfire-8.1.0.jar:na]
    ... gemfire internal stuff
    at java.util.concurrent.ThreadPoolExecutor.runWorker( [na:1.7.0_80]
    at java.util.concurrent.ThreadPoolExecutor$ [na:1.7.0_80]
    at com.gemstone.gemfire.internal.cache.tier.sockets.AcceptorImpl$1$ ~[gemfire-8.1.0.jar:na]
    ... 1 common frames omitted

I found the following,, which encouraged me to update some of the jars to the newest versions, hoping the spring boot versions were simply behind, however it didn't seem to help.

Version info:

spring-cloud-starter-parent: Brixton.SR4 spring-cloud-security: 1.1.2.RELEASE spring-core: 4.3.2.RELEASE spring-security-oauth2: 2.0.10.RELEASE spring-session: 1.2.1.RELEASE

I've considered a few options: rewiring the OAuth2 framework to no longer use ScopedProxyMode.INTERFACES (seems daunting), use Redis vs. Gemfire, write the entire client from scratch (I've done it before... wasn't fun).

FWIW I've already added the RequestContextFilter as recommended here: OAuth2ClientContext (spring-security-oauth2) not persisted in Redis when using spring-session and spring-cloud-security

Does anyone have any guidance?


  • I don't know if this speaks to your problem directly but I had/have a similar problem and I think I have all the same versions as you. Seems that there are so many Spring projects and they all try to keep up with each other so sometimes there seem to be compatibility issues. I found the steps outlined here by Rob Winch fixed my issue -