[
https://jira.jboss.org/browse/SECURITY-433?page=com.atlassian.jira.plugin...
]
Darran Lofthouse updated SECURITY-433:
--------------------------------------
Fix Version/s: Negotiation_2.0.3.SP4
(was: Negotiation_2.0.3.SP3)
Calls to getCallerPrincipal() return session ID
-----------------------------------------------
Key: SECURITY-433
URL:
https://jira.jboss.org/browse/SECURITY-433
Project: PicketBox (JBoss Security and Identity Management)
Issue Type: Task
Security Level: Public(Everyone can see)
Components: Negotiation
Affects Versions: Negotiation_2.0.3.SP1
Reporter: Darran Lofthouse
Assignee: Darran Lofthouse
Fix For: Negotiation_2.0.3.SP4
After SPNEGO based authentication the caller principal is the session ID - it should be
possible to switch this to the name of the authenticated user.
Also add an option to either return the full principal name or remove the realm.
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
https://jira.jboss.org/secure/Administrators.jspa
-
For more information on JIRA, see:
http://www.atlassian.com/software/jira