Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-10290

Every request renews sling.formauth token

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    Description

      When using Apache Sling Form Based Authentication Handler
      Every request and subrequest sets a new value for `sling.formauth`

      Analyzing the code indicates that it not the intended behavior,
      and the cookie value of `sling.formauth` should be consistent for 30 minutes
      according to the default value of form.auth.timeout

      Debugging shows that the method getCookieAuthData always returns null.... AuthenticationInfo properties are user.jcr.credentials, sling.authType and user.name. But this is not a property called sling.formauth

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            enorman Eric Norman
            cris Cris Rockwell
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1.5h
                1.5h

                Slack

                  Issue deployment