Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-170

AuthenticatedSession should not be exposed to application as HttpSession attribute.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 1.0.0.Beta31
    • 1.0.0.Beta30
    • Core
    • None

      Currently, an application can change the identity and authorization of a user by setting the value of the "io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.AuthenticatedSession" session attribute.
      This is bad.

              sdouglas1@redhat.com Stuart Douglas (Inactive)
              pferraro@redhat.com Paul Ferraro
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: