Sessions for Someone Else — Java Bug Hunt

Inspired by the session-mixup incidents that follow Java's most classic beginner-to-production bug: comparing strings with ==.

  • Language: Java
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Strings, Equality
  • Modelled on: Java == lore
  • Visible tests: equal content from different objects matches; different tokens never match
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the session-mixup incidents that follow Java's most classic beginner-to-production bug: comparing strings with ==. It works in unit tests (interned literals!), then fails in production the moment tokens arrive off the wire as fresh objects.

SessionStore.java decides whether a request's token matches the session owner.

Bug report

BUG-EQEQ · Priority: Critical (auth) · Reported by: security review

isOwner(sessionToken, requestToken):

  • equal CONTENT means owner — regardless of object identity
  • null request tokens are never the owner (and must not throw)

Observed: valid tokens read from the network are rejected (== compares references), so a "helpful" fallback upstream started letting requests through unchecked.

Logs

[auth] token match failed for identical strings; fallback path engaged (!!)

The code as shipped

SessionStore.java (editable)

class SessionStore {
    static boolean isOwner(String sessionToken, String requestToken) {
        return sessionToken == requestToken;
    }
}

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Java bug hunts.