Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-4124

Tomcat jacc usage is messed up

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.0.2, 2.1.1, 2.1.4, 2.2
    • 2.2
    • Tomcat
    • Security Level: public (Regular issues)
    • None

    Description

      Several problems:
      1. UserDataPermissions are not getting evaluated by jacc due to the check for Subject in handler data.
      2. Subject is never set into handler data (also a problem in jetty, dunno about openejb).

      3. TomcatGeronimoRealm is calling ContextManager.setCallers before permission checks. This is wrong.

      Attachments

        Activity

          People

            djencks David Jencks
            djencks David Jencks
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: