[JBoss JIRA] (ELY-1950) FORM authentication not working for URL encoded session IDs
by Darran Lofthouse (Jira)
[ https://issues.redhat.com/browse/ELY-1950?page=com.atlassian.jira.plugin.... ]
Darran Lofthouse updated ELY-1950:
----------------------------------
Fix Version/s: 1.13.0.CR1
(was: 1.12.1.CR1)
> FORM authentication not working for URL encoded session IDs
> -----------------------------------------------------------
>
> Key: ELY-1950
> URL: https://issues.redhat.com/browse/ELY-1950
> Project: WildFly Elytron
> Issue Type: Bug
> Components: HTTP
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Priority: Major
> Fix For: 1.13.0.CR1
>
>
> The session IDs are encoded as: -
> {code}
> /secure/j_security_check;jsessionid=kVzsBG9c3XxcOlzpa65ohiMeMNqXdSNQuOdvdpR3.flame
> {code}
> However the code that checks if this is a submission to j_security_check is: -
> {code:java}
> request.getRequestURI().getPath().endsWith(postLocation)
> {code}
> This code needs to trim the path at ';'
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
4 years, 7 months
[JBoss JIRA] (ELY-1974) Correct class names in ProviderFactory
by Darran Lofthouse (Jira)
[ https://issues.redhat.com/browse/ELY-1974?page=com.atlassian.jira.plugin.... ]
Darran Lofthouse updated ELY-1974:
----------------------------------
Fix Version/s: 1.13.0.CR1
(was: 1.12.1.CR1)
> Correct class names in ProviderFactory
> --------------------------------------
>
> Key: ELY-1974
> URL: https://issues.redhat.com/browse/ELY-1974
> Project: WildFly Elytron
> Issue Type: Bug
> Components: API / SPI
> Affects Versions: 1.12.0.Final
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Priority: Major
> Fix For: 1.13.0.CR1
>
>
> The following use an invalid package: -
> {code:java}
> "org.wildfly.security.http.bearer.WildFlyElytronHttpBearerProvider",
> "org.wildfly.security.http.bearer.WildFlyElytronHttpClientCertProvider",
> "org.wildfly.security.http.bearer.WildFlyElytronHttpDigestProvider",
> "org.wildfly.security.http.bearer.WildFlyElytronHttpFormProvider",
> "org.wildfly.security.http.bearer.WildFlyElytronHttpSpnegoProvider",
> {code}
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
4 years, 7 months