]
Darran Lofthouse updated SECURITY-255:
--------------------------------------
Fix Version/s: Negotiation_2.0.5
(was: Negotiation_2.0.4)
IdentityLoginModule Incomplete password-stacking useFirstPass
implementation
----------------------------------------------------------------------------
Key: SECURITY-255
URL:
https://jira.jboss.org/browse/SECURITY-255
Project: PicketBox (JBoss Security and Identity Management)
Issue Type: Bug
Security Level: Public(Everyone can see)
Components: Negotiation
Affects Versions: 2.0.2.CR6
Reporter: Darran Lofthouse
Fix For: Negotiation_2.0.5
The IdentityLoginModule has got an incomplete useFirstPass implementation.
The login() method does start with: -
if( super.login() == true )
return true;
To skip login if useFirstPass is set and authentication has already occurred.
However at the end of login() setting the principal in the shared state map should only
happen if useFirstPass was set.
Also for this to work a credential also needs to be stored in the sharedStateMap
otherwise other modules will assume authentication has not occurred.
--
This message is automatically generated by JIRA.
-
For more information on JIRA, see: