[
https://issues.jboss.org/browse/WFLY-5484?page=com.atlassian.jira.plugin....
]
Paul Ferraro commented on WFLY-5484:
------------------------------------
This issue seems to be due to a conflict between Undertow's
CachedAuthenticatedSessionMechanism and SingleSignOnMechanism. If the
CachedAuthenticatedSessionMechanism detects an AuthenticatedSession in the HttpSession,
the SingleSignOnMechanism never has the chance to register a security notification
listener, thus the SSO is not invalidated on logout. Reassigning this to [~swd847] as
this is clearly an issue with Undertow security, not with clustering SSO management.
Calling HttpServletRequest.logout() with single sign-on enabled only
works every second time
--------------------------------------------------------------------------------------------
Key: WFLY-5484
URL:
https://issues.jboss.org/browse/WFLY-5484
Project: WildFly
Issue Type: Bug
Components: Clustering, Web (Undertow)
Reporter: Richard JanÃk
Assignee: Paul Ferraro
Priority: Blocker
Fix For: 10.0.0.CR5
Attachments: reproducer-jbeap-1282.zip
See "Steps to Reproduce". Logging out from an application only works every
second time, e.g. HttpRequestServlet.logout() has to be called twice in order to have any
effect
This doesn't occur without <single-sign-on/> enabled - logout() has the
expected effect. The issue is security related, thus I'm adding our security team
members as watchers.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)