Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-18460

[GSS](7.2.z) InputStream is empty if getParameter is called in deployment with Picketlink which causes fileupload to fail with sizes over 20k

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 7.2.7.CR2, 7.2.7.GA
    • 7.2.z.GA
    • Security
    • None
    • +
    • Hide

      Create a test user with group membership in "user".

      Use two attached reproducers (idp.war and reproducer.war) plus IDP and SP security-domains from:
      https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.1/html-single/how_to_set_up_sso_with_saml_v2/index#setting_up_idp
      i'm attaching my standalone.xml with this configured also.

      Then visit: http::<hostname:port>/reproducer, login and try to upload a file. A successful file upload will indicate 1 file uploaded, but failed ones show 0 files uploaded.

      Show
      Create a test user with group membership in "user". Use two attached reproducers (idp.war and reproducer.war) plus IDP and SP security-domains from: https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.1/html-single/how_to_set_up_sso_with_saml_v2/index#setting_up_idp i'm attaching my standalone.xml with this configured also. Then visit: http::<hostname:port>/reproducer, login and try to upload a file. A successful file upload will indicate 1 file uploaded, but failed ones show 0 files uploaded.

      This is a followup to JBEAP-18122 - https://issues.redhat.com/browse/JBEAP-18122

      The issue is that if using Picketlink authentication handlers AND you call getParameter before reading from getInputStream then the input will be empty if the file size is over 20k. Also, you need to have the one-off patch from https://issues.redhat.com/browse/JBEAP-17878 if running against 7.2.5. 7.2.7 also has these changes.

      Note this is the SAME test as in JBEAP-18122 except the request.getParameter call prior to the getInputStream.

      Attaching reproducer.

        1. idp.war
          2 kB
          Chris Dolphy
        2. reproducer.war
          147 kB
          Chris Dolphy
        3. roles.properties
          0.0 kB
          Chris Dolphy
        4. standalone.xml
          29 kB
          Chris Dolphy
        5. users.properties
          0.0 kB
          Chris Dolphy

            spyrkob Bartosz Spyrko-Smietanko
            rhn-support-cdolphy Chris Dolphy
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: