Uploaded image for project: 'atlassian-seraph'
  1. atlassian-seraph
  2. SER-95

Cookie login fails if a previous filter creates a session


    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.5.2
    • 0.7.20
    • None
    • JDK 1.4.2, Tomcat 5.5.25

    • false

      If a Filter prior to LoginFilter/SecurityFilter creates a session with request.getSession(), then cookie-based autologin will fail.

      This is because DefaultAuthenticator.getUser(request, response) tests for an existing session. Upon finding one, it assumes that this session was created by Seraph and looks for the user. If it finds none, then it skips cookie auth and tries basic auth.

      It would be better to try cookie auth if no sessionUser is found and not assume the existence of a session means Seraph had a go at the authentication already.

            gsmith@atlassian.com Graeme Smith
            71287a7980d2 Matt Bishop
            0 Vote for this issue
            2 Start watching this issue

              12 years, 35 weeks, 5 days ago