Uploaded image for project: 'Application Server 3  4  5 and 6'
  1. Application Server 3 4 5 and 6
  2. JBAS-2537

JaasSecurityManager makes false assumptions about used cache policy

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Major Major
    • No Release
    • JBossAS-4.0.3 SP1
    • Security
    • None

      The JaasSecurityManagerService allow setting an alternative JNDI-Name for the discovery of the authentication cache policy.
      Afterwards the JaasSecurityManager makes an assumption about the used cached policy that works only with TimedCachePolicy by defining the inner class "public static class DomainInfo implements TimedCachePolicy.TimedEntry" and inserting instances of this class into the cache.
      JaasSecurityManager should only rely on CachePolicy.

              starksm64 Scott Stark (Inactive)
              fudeus Stephan Fudeus (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: