Uploaded image for project: 'Application Server 3  4  5 and 6'
  1. Application Server 3 4 5 and 6
  2. JBAS-2320

Failed authorization does not clear caller identity

    XMLWordPrintable

Details

    Description

      If an authenticated caller fails a resource authorization check, the thread association from the authentication phase is not being cleared. This can result in the caller identity being leaked to subsequent requests that do not have any incoming authentication.

      Attachments

        Issue Links

          Activity

            People

              starksm64 Scott Stark (Inactive)
              starksm64 Scott Stark (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: