Uploaded image for project: 'Shiro'
  1. Shiro
  2. SHIRO-406

Redirected to the wrong url after successful login

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Not A Problem
    • 1.2.1
    • None
    • None
    • None
    • jboss 7, hibernate 4, jsf2, primfaces

    Description

      Navigate to a secure page that requires the user to be logged in, the user is redirected to the login page, after successful login the user is redirected to a primfaces js page.

      Cause
      This occurs when the login page is contained within a secured url, if the login page contains any external links e.g. js,css one of these will end up being the saved request.

      I think this is the wrong behaviour, if the login page is treated as a special case (as it seems to be) then the request that caused it to be invoked should remain as the saved request, subsequent requests for secure content by the login page should not be saved or provided.

      As this is essentially user mis-configuration it could be prevented by not having the login page as a special case, if it is located at a secure url nothing will happen.

      Attachments

        Activity

          People

            Unassigned Unassigned
            set321go Alex Edwards
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: