Uploaded image for project: 'Jackrabbit Content Repository'
  1. Jackrabbit Content Repository
  2. JCR-2045

Jcr-Server: missing-auth-mapping init parameter should have option for GuestCredential login

    XMLWordPrintableJSON

Details

    Description

      the missing-auth-mapping parameter of the servlets contained in jcr-server is defined as follows:

      <param-value>anonymous:anonymous</param-value>
      <description>
      Defines how a missing authorization header should be handled.
      1) If this init-param is missing, a 401 response is generated.
      This is suiteable for clients (eg. webdav clients) for which
      sending a proper authorization header is not possible if the
      server never sent a 401.
      2) If this init-param is present with an empty value,
      null-credentials are returned, thus forcing an null login
      on the repository.
      3) If this init-param has a 'user:password' value, the respective
      simple credentials are generated.
      </description>

      JCR 2.0 introduces GuestCredentials used to obtain a "anonymous" session.

      Therefore we should probably extend/modify the missing-auth-param in a way that
      allows to distinguish between

      • null-login
      • guest login

      in case of missing authorization header.

      Attachments

        1. JCR-2045.patch
          6 kB
          Angela Schreiber

        Activity

          People

            angela Angela Schreiber
            angela Angela Schreiber
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: