[
https://issues.jboss.org/browse/SECURITY-255?page=com.atlassian.jira.plug...
]
Darran Lofthouse updated SECURITY-255:
--------------------------------------
Fix Version/s: Negotiation_2_1_7
(was: Negotiation_2_1_6)
IdentityLoginModule Incomplete password-stacking useFirstPass
implementation
----------------------------------------------------------------------------
Key: SECURITY-255
URL:
https://issues.jboss.org/browse/SECURITY-255
Project: PicketBox
Issue Type: Bug
Security Level: Public(Everyone can see)
Components: Negotiation
Affects Versions: 2.0.2.CR6
Reporter: Darran Lofthouse
Fix For: Negotiation_2_1_7
The IdentityLoginModule has got an incomplete useFirstPass implementation.
The login() method does start with: -
if( super.login() == true )
return true;
To skip login if useFirstPass is set and authentication has already occurred.
However at the end of login() setting the principal in the shared state map should only
happen if useFirstPass was set.
Also for this to work a credential also needs to be stored in the sharedStateMap
otherwise other modules will assume authentication has not occurred.
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see:
http://www.atlassian.com/software/jira