-
Bug
-
Resolution: Fixed
-
Medium
-
1.2.1
-
None
The HTTPAuthenticator before it sees if it should attempt an authentication request with crowd (via the session.lastvalidation property), should check to see that a valid Crowd Cookie exists for a given request.
If no valid token is found in the request, assume the request is not authenticated.