Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-170

AuthenticatedSession should not be exposed to application as HttpSession attribute.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 1.0.0.Beta31
    • 1.0.0.Beta30
    • Core
    • None

      Currently, an application can change the identity and authorization of a user by setting the value of the "io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.AuthenticatedSession" session attribute.
      This is bad.

            sdouglas1@redhat.com Stuart Douglas
            pferraro@redhat.com Paul Ferraro
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: