-
Bug
-
Resolution: Done
-
Major
-
7.0.0.DR12
-
None
The class org.jboss.metadata.parser.jbossweb.JBossWebMetaDataParser doesn't support reading "flushOnSessionInvalidation" attribute on "security-domain" element. And also the schema files for jboss-web.xml doesn't mention this attribute.
The class org.jboss.metadata.web.jboss.JBossWebMetaData contains the attribute flushOnSessionInvalidation, which comes from old JBoss versions (3.2 and 4.0). The description says:
The jboss-web.xml security-domain element now supports a flushOnSessionInvalidation boolean attribute that when true, will flush the security-domain JAAS authentication cache for the associated user principal.
This attribute is also supported in WildFly integration with Undertow (look at source), but the code is never reached as the flushOnSessionInvalidation attribute value stays always false.
- clones
-
WFLY-5546 The flushOnSessionInvalidation is not parsed correctly from jboss-web.xml
- Closed
- is blocked by
-
JBEAP-9564 (7.1.x) Upgrade JBoss Metadata from 10.0.0.Final to 10.0.2.Final
- Closed
- is caused by
-
JBMETA-392 The flushOnSessionInvalidation attribute is missing in the jboss-web schema and the parser
- Resolved
- is cloned by
-
JBEAP-11648 [GSS](7.0.z) The flushOnSessionInvalidation is not parsed correctly from jboss-web.xml
- Closed
- relates to
-
JBEAP-10569 HttpSession.invalidate() requires additional permissions if Security Manager is enabled
- Closed