Uploaded image for project: 'Application Server 3  4  5 and 6'
  1. Application Server 3 4 5 and 6
  2. JBAS-2320

Failed authorization does not clear caller identity

XMLWordPrintable

      If an authenticated caller fails a resource authorization check, the thread association from the authentication phase is not being cleared. This can result in the caller identity being leaked to subsequent requests that do not have any incoming authentication.

            starksm64 Scott Stark (Inactive)
            starksm64 Scott Stark (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: