Allow update of existing WebSession after max sessions limit is reached

Previously, when saving a WebSession, the system did not check whether
the session ID already existed. As a result, even if the session being
saved was an update to an existing one, it was incorrectly treated as a
new session, and a "maximum sessions exceeded" error was triggered.

This fix ensures that if a WebSession with the same ID already exists,
it will be updated rather than counted as a new session, thereby
preventing unnecessary session limit violations.

Closes gh-35013

Signed-off-by: Mohammad Saeed Nouri <msnsaeed71@gmail.com>
This commit is contained in:
Mohammad Saeed Nouri
2025-06-08 15:44:06 +03:30
committed by Sam Brannen
parent 3c265e1044
commit c04902fefb
2 changed files with 21 additions and 1 deletions
@@ -283,7 +283,7 @@ public class InMemoryWebSessionStore implements WebSessionStore {
private void checkMaxSessionsLimit() {
if (sessions.size() >= maxSessions) {
expiredSessionChecker.removeExpiredSessions(clock.instant());
if (sessions.size() >= maxSessions) {
if (sessions.size() >= maxSessions && !sessions.containsKey(this.getId())) {
throw new IllegalStateException("Max sessions limit reached: " + sessions.size());
}
}