Uploaded image for project: 'WildFly Core'
  1. WildFly Core
  2. WFCORE-4659

Partial revert of *not* having static default authentication context


    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 10.0.0.Beta9, 10.0.0.Final
    • 10.0.0.Beta4, 10.0.0.Beta6
    • Security
    • None

      The definition of the default security context was removed to be static https://github.com/wildfly/wildfly-core/pull/3892/commits/4f34c962fec06e81673c17f8f37b4122c1034623#diff-8396de3001749ce06e45825a9bea821dR439 as it could cause defective behaviour. To quote Stuart:

      The 'standard' default is basically random, as it can vary based on what the first TCCL to access it is.

      But removing the static default authentication context makes troubles for the transaction recovery which does not have an authentication context specified. Recovery can use only global one and while it's a workaround to the real issue of recovery has not defined any, it was a working solution. With the mentioned change this solution stopped to work.

      Loading of the static authentication context should be reverted back and later fix properly.

            ochaloup@redhat.com Ondrej Chaloupka (Inactive)
            ochaloup@redhat.com Ondrej Chaloupka (Inactive)
            0 Vote for this issue
            3 Start watching this issue