Sessions for Someone Else — Java Bug Hunt
Inspired by the session-mixup incidents that follow Java's most classic beginner-to-production bug: comparing strings with ==.
- Language: Java
- Layer: Backend
- Difficulty: Easy
- Concepts: Strings, Equality
- Modelled on: Java == lore
- Visible tests: equal content from different objects matches; different tokens never match
- Reward: 50 XP for a complete fix
Briefing
Inspired by the session-mixup incidents that follow Java's most classic beginner-to-production bug: comparing strings with ==. It works in unit tests (interned literals!), then fails in production the moment tokens arrive off the wire as fresh objects.
SessionStore.java decides whether a request's token matches the session owner.
Bug report
BUG-EQEQ · Priority: Critical (auth) · Reported by: security review
isOwner(sessionToken, requestToken):
- equal CONTENT means owner — regardless of object identity
- null request tokens are never the owner (and must not throw)
Observed: valid tokens read from the network are rejected (== compares references), so a "helpful" fallback upstream started letting requests through unchecked.
Logs
[auth] token match failed for identical strings; fallback path engaged (!!)The code as shipped
SessionStore.java (editable)
class SessionStore {
static boolean isOwner(String sessionToken, String requestToken) {
return sessionToken == requestToken;
}
}Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Java bug hunts.