Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-18889

org.wildfly.security.http.oidc.OidcRequestAuthenticator#loginRedirect() does not check for ajax request

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • None
    • JSF, Security
    • None
    • ---
    • ---

      Would it be possible and make sense that <partial-response><redirect url=...  is returned insted of 302 on ajax calls?

      I used Intellij Profiler to capture what happens when session expire and ajax button is clicked on JSF page.

      Included file jar_2024_01_06_110618.jfr contains stacktrace where this happens.

      I created similar ticket (https://issues.redhat.com/browse/WFLY-17900) but no one provided any response. Except that it is hard 
      to reproduce. 

      Please provide me a simple Keycloak instance and I will send you minimal application to reproduce the issue. Keycloak does not
      need external database or https, it can be run in DEV mode.

       

      link to code

        1. Screenshot from 2024-01-07 16-39-18.png
          197 kB
          Janez Puntar
        2. jar_2024_01_06_110618.jfr
          280 kB
          Janez Puntar

            jaslee@redhat.com Jason Lee
            janez.puntar Janez Puntar
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: