Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-27368

[GSS](7.4.z) UNDERTOW-2418 - Adjust properly session timeout also in case when FORM is combined with other mechanisms

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • 7.4.17.GA
    • Undertow
    • None

      If the FORM mechanism is used in conjunction with another, then the short session timeout from UNDERTOW-2378 / UNDERTOW-2264 is still seen after login. This is because the FORM mech will set its short timeout through the challenge phase, but it is not guaranteed that ServletFormAuthenticationMechanism.authenticate will be called. The client may authenticate with one of the other available mechanisms, leaving the short session timeout.

            flaviarnn Flavia Rainone
            rhn-support-aogburn Aaron Ogburn
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: