[JBoss JIRA] Created: (GTNPORTAL-1137) Permission settings in application registry not preventing unauthorized access
by Matt Wringe (JIRA)
Permission settings in application registry not preventing unauthorized access
------------------------------------------------------------------------------
Key: GTNPORTAL-1137
URL: https://jira.jboss.org/jira/browse/GTNPORTAL-1137
Project: GateIn Portal
Issue Type: Bug
Security Level: Public (Everyone can see)
Reporter: Matt Wringe
In the application registry, it possible to set access permission for portlets and gadgets, but this doesn't seem to work. I can change the permission of a portlet and still have an unauthorized user view its content.
It does seem to prevent a user from viewing a gadget as a portlet on the dashboard page, but they can still add the gadget as a gadget to the dashboard page.
Steps to reproduce:
1) log in as root
2) import a portlet through the application registry
3) set the premissions for the portlet
4) add the portlet to a page
5) logout and access the page
6) the unauthorized user can view the portlet
expected results: the user shouldn't be able to see the portlet.
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: https://jira.jboss.org/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira
15 years, 5 months
[JBoss JIRA] Created: (GTNPORTAL-996) GateIn+JOSSO integration: Problems with logout
by Marek Posolda (JIRA)
GateIn+JOSSO integration: Problems with logout
----------------------------------------------
Key: GTNPORTAL-996
URL: https://jira.jboss.org/jira/browse/GTNPORTAL-996
Project: GateIn Portal
Issue Type: Bug
Security Level: Public (Everyone can see)
Affects Versions: 3.0.0-GA
Environment: GateIn-3.0.0-GA+JBoss 5.1 bundle (port 8080 for HTTP),
JOSSO-1.8.1+Tomcat 6.0.18 bundle (port 8888 for HTTP),
Reporter: Marek Posolda
After integrating GateIn portal with JOSSO, I did these steps:
- Click to "Sign in" in GateIn
- Login as root in JOSSO console
- Logout in GateIn
- Click to "Sign in" link again. Now I am directly authenticated to GateIn which is not correct to me because now I am not able to login as different user in this web session.
Problem is that JOSSO cookie is not cleared from browser when doing logout from GateIn. I am able to login as different user after clearing the cookie directly from web browser via browser cookie manager.
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: https://jira.jboss.org/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira
15 years, 5 months