Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-4099

Calling isUserInRole wipes out run-as info

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.0.x, 2.1.x, 2.2
    • 2.1.2, 2.2
    • Tomcat
    • Security Level: public (Regular issues)
    • None

    Description

      TomcatGeronimoRealm.hasRole sets callers which it has no business doing. These were already set during authentication. This wipes out the run-as info which was set earlier. Checking the principal is also unrelated to role checks in geronimo and should be omitted.

      Attachments

        Activity

          People

            djencks David Jencks
            djencks David Jencks
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: