Uploaded image for project: 'Application Server 7'
  1. Application Server 7
  2. AS7-6489

Ensure JBoss 7.2.0-Alpha1 mgmt user session invalidated if user doesn't exist

    XMLWordPrintable

Details

    Description

      Had browser open much earlier today and logged into old JBoss 7.1.1.FINAL JBoss management console. Built/setup JBoss 7.2.0-Alpha1 from github jbossas/jboss-as master up-to-date as of earlier this morning. Started server and was no management user so it showed the page indicating that I could not login because there was no user. Added user and refreshed page and I was logged-in. I could be imagining things, but it might be good to check that current session is invalidated in management session if the user doesn't exist. (Also, there is no command to remove a user while the server is up that I can see; if there were, I'd try removing the user, hitting the page to validate I couldn't get in, and then hit it again to try to confirm; but, if no one has complained about the lack of remove-user, then I guess it isn't required.)

      Thanks!

      Attachments

        Activity

          People

            darran.lofthouse@redhat.com Darran Lofthouse
            garysweaver_jira Gary Weaver (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: