Uploaded image for project: 'Trusted authentication framework'
  1. Trusted authentication framework
  2. TRUSTAUTH-6

When using the cookie persistence store, authentication could be persisted excessively

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 1.2
    • 1.1
    • API
    • None

    Description

      The removal of the authentication cookie is not working properly in certain configuration (reproduced with jetty an tomcat), causing the authentication to be persisted when the user as requested a logout.

      To remove the cookie, I had trusted the XWikiResponse#removeCookie() method, but it doesn't seem to work properly.

      Attachments

        Activity

          People

            softec Denis Gervalle
            softec Denis Gervalle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: