Uploaded image for project: 'Jackrabbit Content Repository'
  1. Jackrabbit Content Repository
  2. JCR-3293

AbstractLoginModule: get rid of trust_credentials_attribute

Attach filesAttach ScreenshotAdd voteVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 2.4
    • None
    • jackrabbit-core
    • None

    Description

      based on JCR-2355 we added a very simplistic way to indicate to the login module that the given credentials have
      been preauthenticated. as already stated in the original issue this poses a major security issue as it leaves the
      repository access untrusted.

      i would like to raise those security concern again and would therefore like to get rid of that hack in the long run.
      the suggested procedure:

      • deprecate the attribute (immediately)
      • log a warning if it is used (immediately)
      • document how to fix code that is currently relying on that attribute
      • remove support altogether for the next major release

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            angela Angela Schreiber

            Dates

              Created:
              Updated:

              Slack

                Issue deployment