Redis security recommends disabling the CONFIG command so that remote users cannot reconfigure an instance. The RedisHttpSessionConfiguration requires access to this during its initialization. Hosted Redis services, like AWS ElastiCache disable this command by default, with no option to re-enable it.
Thanks for the report @danveloper! This indeed seems to be a bug with the RedisHttpSessionConfiguration and thus the @EnableRedisHttpSession annotation.
As of Spring Session 1.0.1 this can be disabled by exposing ConfigureRedisAction.NO_OP as a bean.
An XML Configuration example
<util:constant
static-field="org.springframework.session.data.redis.config.ConfigureRedisAction.NO_OP"/>
A Java Configuration example
@Bean
public static ConfigureRedisAction configureRedisAction() {
return ConfigureRedisAction.NO_OP;
}
I'm debating what the best approach to fixing this would be though and wondering what your thoughts were @danveloper.
There is certainly a need for a fix, so I'm not debating that we need to fix something. However, I like the fact that it updates the Redis configuration _by default_ for two reasons:
SessionDestroyedEvent to be fired to clean up resources. In particular, this is important for WebSocket applications to ensure open WebSockets are closed when the HttpSession expires.My initial thoughts on how we should update the configuration is:
RedisHttpSessionConfiguration should _by default_ update the Redis configuration _only if_ Spring WebSocket support is enabled. RedisHttpSessionConfiguration should allow disabling updating the Redis configurationRedisHttpSessionConfiguration should _by default_ try to subscribe to keyspace notifications _only if_ Spring WebSocket support is enabled. This will help increase performance for applications simply using Spring Session for HttpSession which typically does not need to receive the SessionDestroyedEventRedisHttpSessionConfiguration should allow explicitly configuring if the application should subscribe to keyspace notificationsIn the meantime, a workaround is to remove @EnableRedisHttpSession from your configuration and then include a configuration with a fix. For example:
import java.util.Arrays;
import java.util.List;
import java.util.Map;
import org.springframework.beans.factory.BeanClassLoaderAware;
import org.springframework.beans.factory.InitializingBean;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.ApplicationEventPublisher;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.ImportAware;
import org.springframework.core.annotation.AnnotationAttributes;
import org.springframework.core.annotation.AnnotationUtils;
import org.springframework.core.type.AnnotationMetadata;
import org.springframework.data.redis.connection.RedisConnection;
import org.springframework.data.redis.connection.RedisConnectionFactory;
import org.springframework.data.redis.core.RedisTemplate;
import org.springframework.data.redis.listener.PatternTopic;
import org.springframework.data.redis.listener.RedisMessageListenerContainer;
import org.springframework.data.redis.serializer.StringRedisSerializer;
import org.springframework.scheduling.annotation.EnableScheduling;
import org.springframework.session.ExpiringSession;
import org.springframework.session.SessionRepository;
import org.springframework.session.data.redis.RedisOperationsSessionRepository;
import org.springframework.session.data.redis.SessionMessageListener;
import org.springframework.session.web.http.HttpSessionStrategy;
import org.springframework.session.web.http.SessionRepositoryFilter;
import org.springframework.util.ClassUtils;
@Configuration
@EnableScheduling
public class RedisHttpSessionConfiguration {
@Value("${spring.session.maxInactive ?: 1800}")
private Integer maxInactiveIntervalInSeconds;
private HttpSessionStrategy httpSessionStrategy;
@Autowired
private ApplicationEventPublisher eventPublisher;
@Bean
public RedisMessageListenerContainer redisMessageListenerContainer(
RedisConnectionFactory connectionFactory) {
RedisMessageListenerContainer container = new RedisMessageListenerContainer();
container.setConnectionFactory(connectionFactory);
container.addMessageListener(redisSessionMessageListener(),
Arrays.asList(new PatternTopic("__keyevent@*:del"),new PatternTopic("__keyevent@*:expired")));
return container;
}
@Bean
public SessionMessageListener redisSessionMessageListener() {
return new SessionMessageListener(eventPublisher);
}
@Bean
public RedisTemplate<String,ExpiringSession> sessionRedisTemplate(RedisConnectionFactory connectionFactory) {
RedisTemplate<String, ExpiringSession> template = new RedisTemplate<String, ExpiringSession>();
template.setKeySerializer(new StringRedisSerializer());
template.setHashKeySerializer(new StringRedisSerializer());
template.setConnectionFactory(connectionFactory);
return template;
}
@Bean
public RedisOperationsSessionRepository sessionRepository(RedisTemplate<String, ExpiringSession> sessionRedisTemplate) {
RedisOperationsSessionRepository sessionRepository = new RedisOperationsSessionRepository(sessionRedisTemplate);
sessionRepository.setDefaultMaxInactiveInterval(maxInactiveIntervalInSeconds);
return sessionRepository;
}
@Bean
public <S extends ExpiringSession> SessionRepositoryFilter<? extends ExpiringSession> springSessionRepositoryFilter(SessionRepository<S> sessionRepository) {
SessionRepositoryFilter<S> sessionRepositoryFilter = new SessionRepositoryFilter<S>(sessionRepository);
if(httpSessionStrategy != null) {
sessionRepositoryFilter.setHttpSessionStrategy(httpSessionStrategy);
}
return sessionRepositoryFilter;
}
@Autowired(required = false)
public void setHttpSessionStrategy(HttpSessionStrategy httpSessionStrategy) {
this.httpSessionStrategy = httpSessionStrategy;
}
}
If you are not using the SessionDestroyedEvent you can also disable subscribing to the notifications which should improve performance. For example:
import java.util.Arrays;
import java.util.List;
import java.util.Map;
import org.springframework.beans.factory.BeanClassLoaderAware;
import org.springframework.beans.factory.InitializingBean;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.beans.factory.annotation.Qualifier;
import org.springframework.context.ApplicationEventPublisher;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.ImportAware;
import org.springframework.core.annotation.AnnotationAttributes;
import org.springframework.core.annotation.AnnotationUtils;
import org.springframework.core.type.AnnotationMetadata;
import org.springframework.data.redis.connection.RedisConnection;
import org.springframework.data.redis.connection.RedisConnectionFactory;
import org.springframework.data.redis.core.RedisTemplate;
import org.springframework.data.redis.listener.PatternTopic;
import org.springframework.data.redis.listener.RedisMessageListenerContainer;
import org.springframework.data.redis.serializer.StringRedisSerializer;
import org.springframework.scheduling.annotation.EnableScheduling;
import org.springframework.session.ExpiringSession;
import org.springframework.session.SessionRepository;
import org.springframework.session.data.redis.RedisOperationsSessionRepository;
import org.springframework.session.data.redis.SessionMessageListener;
import org.springframework.session.web.http.HttpSessionStrategy;
import org.springframework.session.web.http.SessionRepositoryFilter;
import org.springframework.util.ClassUtils;
@Configuration
public class RedisHttpSessionConfiguration {
@Value("${spring.session.maxInactive ?: 1800}")
private Integer maxInactiveIntervalInSeconds;
private HttpSessionStrategy httpSessionStrategy;
@Bean
public RedisTemplate<String,ExpiringSession> sessionRedisTemplate(RedisConnectionFactory connectionFactory) {
RedisTemplate<String, ExpiringSession> template = new RedisTemplate<String, ExpiringSession>();
template.setKeySerializer(new StringRedisSerializer());
template.setHashKeySerializer(new StringRedisSerializer());
template.setConnectionFactory(connectionFactory);
return template;
}
@Bean
public RedisOperationsSessionRepository sessionRepository(RedisTemplate<String, ExpiringSession> sessionRedisTemplate) {
RedisOperationsSessionRepository sessionRepository = new RedisOperationsSessionRepository(sessionRedisTemplate);
sessionRepository.setDefaultMaxInactiveInterval(maxInactiveIntervalInSeconds);
return sessionRepository;
}
@Bean
public <S extends ExpiringSession> SessionRepositoryFilter<? extends ExpiringSession> springSessionRepositoryFilter(SessionRepository<S> sessionRepository) {
SessionRepositoryFilter<S> sessionRepositoryFilter = new SessionRepositoryFilter<S>(sessionRepository);
if(httpSessionStrategy != null) {
sessionRepositoryFilter.setHttpSessionStrategy(httpSessionStrategy);
}
return sessionRepositoryFilter;
}
@Autowired(required = false)
public void setHttpSessionStrategy(HttpSessionStrategy httpSessionStrategy) {
this.httpSessionStrategy = httpSessionStrategy;
}
}
I think it should be enabled by default, but fail gracefully with a warning. This would allow the same configuration to be used between dev and prod, where dev would _JustWork(tm)_ and prod would require some manual intervention (which would be obvious from the warning).
I was able to work around the problem by subclassing the RedisHttpSessionConfiguration with an implementation that disables the keyspace notifications initializer, and bringing it in through normal configuration means:
package org.springframework.session.data.redis.config.annotation.web.http
import org.springframework.beans.factory.annotation.Value
import org.springframework.context.annotation.Bean
import org.springframework.context.annotation.Configuration
import org.springframework.core.type.AnnotationMetadata
import org.springframework.data.redis.connection.RedisConnectionFactory
import org.springframework.data.redis.core.RedisTemplate
import org.springframework.session.ExpiringSession
import org.springframework.session.data.redis.RedisOperationsSessionRepository
@Configuration
class GateRedisHttpSessionConfiguration extends RedisHttpSessionConfiguration {
@Value('${session.expiration:1800}')
int expiration
public void setImportMetadata(AnnotationMetadata importMetadata) {
}
@Bean
public RedisOperationsSessionRepository sessionRepository(RedisTemplate<String, ExpiringSession> sessionRedisTemplate) {
RedisOperationsSessionRepository sessionRepository = new RedisOperationsSessionRepository(sessionRedisTemplate);
sessionRepository.setDefaultMaxInactiveInterval(expiration);
return sessionRepository;
}
@Override
public RedisHttpSessionConfiguration.EnableRedisKeyspaceNotificationsInitializer enableRedisKeyspaceNotificationsInitializer(RedisConnectionFactory connectionFactory) {
null
}
}
For posterity, here are the steps for enabling the keyspace notifications on AWS:






@danveloper I'm glad you were able to work around the issue. Thank you for your feedback and for the useful directions on enabling keyspace notifications in AWS.
I have concerns with the configuration not failing when it tries to update the Redis configuration.
Developers likely did thorough testing within another environment. For example, they might be integrating with WebSocket support and validate that when an HttpSession is terminated the WebSocket is indeed closing properly.
This means they are confident that everything is working by the time the get to production. Many users may not even notice a warning being logged. Without Redis keyspace notifications being enabled, the applications WebSocket connections will not properly closed when the HttpSession is destroyed.
Obviously developers should read the instructions completely, look for warnings, and perform some smoke tests in production to avoid such issues. However, I fear that by not failing we are setting up users for failure.
A compromise might be to require users to explicitly set a property to allow "fall back". This means users would be aware that they need to do something in production. Of course this is one more piece of configuration users would need. Thoughts?
Could it provide a different strategy for ascertaining the database's configuration? Maybe in the absence of the CONFIG command, the event notification initializer could run a test to determine if expirations were working? This might introduce some slowness during startup, but might be favorable to total failure.
I'd probably prefer a slower startup over managing feature flags between dev & prod. If this isn't possible or is otherwise infeasible, then feature flag might be the only way to go.
Great idea! I think this may be doable, but we will see when I get into the details. Thanks for your feedback!
RedisHttpSessionConfiguration.EnableRedisKeyspaceNotificationsInitializer is not visible for outsiders extending RedisHttpSessionConfiguration. The workaround doesn't work. Can you help me with this?
@njariwala You would need to place it in the same package as illustrated in the example above.
If the class is semantically usable for non-core extensions, it seems like a bad practice to trespass on the distribution package, especially since that can fail in interesting ways with particular classloader hierarchies.
@chrylis Yes this is considered a workaround until we can get a fix out. The alternative is to use the more verbose workaround I provided.
@rwinch , @danveloper ,
I think calling the config commands is a bit like hibernate.hbm2ddl.auto option, its better to make it disabled by default.
what do you think?
@andirdju Thanks for your thoughts. I think this is quite a bit different:
I've been giving this quite a bit of thought and I think the best route is to:
The reason being:
@danveloper I know you disagreed with this approach, so I'd like to encourage a response from you about this.
Anyone else following this issue, I'd love to hear your feedback as well.
@rwinch Is there anything wrong with adding @Profile(value = "production") to the beans so that local Redis testing is still allowed?
@ccit-spence I generally do not like to use a different setup for production than development. The problem is that you are testing your production setup throughout development which means you are almost sure to run into "unforeseen" problems. Given Redis is so easy to setup, I would highly recommend using the same setup in development as production.
With all that said, you are obviously free to do as you choose. Using a profile will work, but I wouldn't recommend it for the reasons above.
@rwinch We basically have 2 sets of testing. One: local for making sure nothing obvious is broken, Two: Test ran on CI servers i.e. production. A problem good or bad is from a dev machine you can't access Elasticache. Elasticache is only accessible via EC2 instances.
But yes, I do agree having 2 sets of tests is not something I like to do. In this case since Elasticache is only accessible from EC2 I don't see any other way for a dev to test locally.
@ccit-spence Are you just using Redis within Elasticache or do you have a custom implementation of Spring Sessions' SessionRepository? If you are just using Redis within Elasticache, you can easily install Redis locally.
@rwinch Right now it is pretty basic. Just using Spring Session defaults. Main motivation for Elasticache is not having to maintain the cluster/nodes.
@ccit-spence So you could run a local Redis instance right? Not saying you have to, but it seems like an option that would make the development and production much more similar. Anyways, the choice is totally up to you :)
I'm reopen this issue because if facing the same issue on azure with their redis server. Any idea how to over come this as I cannot change some of the config. According to the doc:
https://azure.microsoft.com/en-us/documentation/articles/cache-configure/
Important:
Because configuration and management of Azure Redis Cache instances is managed by Microsoft the following commands are disabled. If you try to invoke them you will receive an error message similar to "(error) ERR unknown command".
@oak-tree See https://github.com/spring-projects/spring-session/issues/124#issuecomment-71490616 and http://docs.spring.io/spring-session/docs/current/reference/html5/#api-redisoperationssessionrepository-sessiondestroyedevent
Thanks!
I am facing the same issue even after trying the solutions provided above
I think it should be enabled by default, but fail gracefully with a warning. This would allow the same configuration to be used between dev and prod, where dev would _JustWork(tm)_ and prod would require some manual intervention (which would be obvious from the warning).
I was able to work around the problem by subclassing the
RedisHttpSessionConfigurationwith an implementation that disables the keyspace notifications initializer, and bringing it in through normal configuration means:package org.springframework.session.data.redis.config.annotation.web.http import org.springframework.beans.factory.annotation.Value import org.springframework.context.annotation.Bean import org.springframework.context.annotation.Configuration import org.springframework.core.type.AnnotationMetadata import org.springframework.data.redis.connection.RedisConnectionFactory import org.springframework.data.redis.core.RedisTemplate import org.springframework.session.ExpiringSession import org.springframework.session.data.redis.RedisOperationsSessionRepository @Configuration class GateRedisHttpSessionConfiguration extends RedisHttpSessionConfiguration { @Value('${session.expiration:1800}') int expiration public void setImportMetadata(AnnotationMetadata importMetadata) { } @Bean public RedisOperationsSessionRepository sessionRepository(RedisTemplate<String, ExpiringSession> sessionRedisTemplate) { RedisOperationsSessionRepository sessionRepository = new RedisOperationsSessionRepository(sessionRedisTemplate); sessionRepository.setDefaultMaxInactiveInterval(expiration); return sessionRepository; } @Override public RedisHttpSessionConfiguration.EnableRedisKeyspaceNotificationsInitializer enableRedisKeyspaceNotificationsInitializer(RedisConnectionFactory connectionFactory) { null } }For posterity, here are the steps for enabling the keyspace notifications on AWS:
Log into the AWS console and choose the _ElastiCache_ service
Choose the _Cache Parameter Groups_ and click _Create Parameter Group_
Give the new group and name and description and click _Create_
With the new parameter group created, select it and click _Edit Parameters_
Page through the parameters until you find _notify-keyspace-events_ and enter "eA" in the _Value_ field and click _Save Changes___
__
#### Choose _Cache Clusters_ from the context navigation and create a new _Redis_ cache cluster #### When specifying your cluster detail, choose the newly created parameter group
__
The value to set in notify-keyspace-events obbeys to the below information :
K โ Keyspace events, published with a prefix of __keyspace@<db>__
E โ Key-event events, published with a prefix of __keyevent@<db>__
g โ Generic, non-specific commands such as DEL, EXPIRE, RENAME, etc.
$ โ String commands
l โ List commands
s โ Set commands
h โ Hash commands
z โ Sorted set commands
x โ Expired events (events generated every time a key expires)
e โ Evicted events (events generated when a key is evicted for maxmemory)
A โ An alias for g$lshzxe
This information is located in https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/ParameterGroups.Redis.html#ParameterGroups.Redis.2-8-6
Thanks @danveloper for your explanation.
Most helpful comment
I think it should be enabled by default, but fail gracefully with a warning. This would allow the same configuration to be used between dev and prod, where dev would _JustWork(tm)_ and prod would require some manual intervention (which would be obvious from the warning).
I was able to work around the problem by subclassing the
RedisHttpSessionConfigurationwith an implementation that disables the keyspace notifications initializer, and bringing it in through normal configuration means:For posterity, here are the steps for enabling the keyspace notifications on AWS:
Log into the AWS console and choose the ElastiCache service
Choose the Cache Parameter Groups and click Create Parameter Group
Give the new group and name and description and click Create
With the new parameter group created, select it and click Edit Parameters
Page through the parameters until you find notify-keyspace-events and enter "eA" in the Value field and click Save Changes
Choose Cache Clusters from the context navigation and create a new Redis cache cluster
When specifying your cluster detail, choose the newly created parameter group