[JBoss JIRA] (ELY-1953) Elytron tool command execution fails with java.nio.file.NoSuchFileException
by Darran Lofthouse (Jira)
[ https://issues.redhat.com/browse/ELY-1953?page=com.atlassian.jira.plugin.... ]
Darran Lofthouse updated ELY-1953:
----------------------------------
Fix Version/s: 1.12.0.CR2
(was: 1.12.0.CR1)
> Elytron tool command execution fails with java.nio.file.NoSuchFileException
> ----------------------------------------------------------------------------
>
> Key: ELY-1953
> URL: https://issues.redhat.com/browse/ELY-1953
> Project: WildFly Elytron
> Issue Type: Bug
> Components: Command-Line Tool
> Affects Versions: 1.11.3.Final
> Reporter: Ricardo Martin Camarero
> Assignee: Ricardo Martin Camarero
> Priority: Blocker
> Labels: regression
> Fix For: 1.12.0.CR2
>
>
> This is a regression in behavior of *elytron-tool.sh* with respect to 7.3.0.GA-CR4.
> Basically, it was noticed that some commands involving a custom credential store returned a exit code of *0* and no error when executed against 7.3.0.GA-CR4 distribution, while the same commands are failing with various error codes against 7.4.0.CD19-CR1.
> See _Steps to Reproduce_ for an example.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 5 months
[JBoss JIRA] (ELY-1950) FORM authentication not working for URL encoded session IDs
by Darran Lofthouse (Jira)
[ https://issues.redhat.com/browse/ELY-1950?page=com.atlassian.jira.plugin.... ]
Darran Lofthouse updated ELY-1950:
----------------------------------
Fix Version/s: 1.12.0.CR2
(was: 1.12.0.CR1)
> FORM authentication not working for URL encoded session IDs
> -----------------------------------------------------------
>
> Key: ELY-1950
> URL: https://issues.redhat.com/browse/ELY-1950
> Project: WildFly Elytron
> Issue Type: Bug
> Components: HTTP
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Priority: Major
> Fix For: 1.12.0.CR2
>
>
> The session IDs are encoded as: -
> {code}
> /secure/j_security_check;jsessionid=kVzsBG9c3XxcOlzpa65ohiMeMNqXdSNQuOdvdpR3.flame
> {code}
> However the code that checks if this is a submission to j_security_check is: -
> {code:java}
> request.getRequestURI().getPath().endsWith(postLocation)
> {code}
> This code needs to trim the path at ';'
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
5 years, 5 months