Uploaded image for project: 'CXF-Fediz'
  1. CXF-Fediz
  2. FEDIZ-243

Fediz tomcat valve is broken with recent tomcat version

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 1.4.6
    • 1.5.0
    • Plugin

    Description

      Since 8.5.50 and 9.0.30, the fediz tomcat valve stop working.

      With these versions of tomcat the authentication never succeed, even with correct credentials, and fall in an infinite redirect loop between tomcat and the IDP server. 

      This behavior is due to matchRequest from FormAuthenticator is always returning false.

      A security fix has been applied to FormAuthenticator:

      Refactor FORM authentication to reduce duplicate code and to ensure that the authenticated Principal is not cached in the session when caching is disabled. (markt)

      Which has been done with this commit 

      https://github.com/apache/tomcat/commit/1ecba14e690cf5f3f143eef6ae7037a6d3c16652#diff-d3a23672da52a023e04cefd774dbe896

       

      Attachments

        Issue Links

          Activity

            People

              coheigea Colm O hEigeartaigh
              amergey Arnaud MERGEY
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 10m
                  10m