[jboss-jira] [JBoss JIRA] Created: (SECURITY-255) IdentityLoginModule Incomplete password-stacking useFirstPass implementation

Darran Lofthouse (JIRA) jira-events at lists.jboss.org
Mon Jun 30 06:07:32 EDT 2008


IdentityLoginModule Incomplete password-stacking useFirstPass implementation
----------------------------------------------------------------------------

                 Key: SECURITY-255
                 URL: http://jira.jboss.com/jira/browse/SECURITY-255
             Project: JBoss Security and Identity Management
          Issue Type: Bug
      Security Level: Public (Everyone can see)
          Components: JBossSX
    Affects Versions: 2.0.2.CR6
            Reporter: Darran Lofthouse
         Assigned To: Darran Lofthouse
             Fix For: 2.0.3.Beta2


The IdentityLoginModule has got an incomplete useFirstPass implementation.

The login() method does start with: -

  if( super.login() == true )
         return true;

To skip login if useFirstPass is set and authentication has already occurred.

However at the end of login() setting the principal in the shared state map should only happen if useFirstPass was set.  

Also for this to work a credential also needs to be stored in the sharedStateMap otherwise other modules will assume authentication has not occurred.  

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.jboss.com/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        



More information about the jboss-jira mailing list