Uploaded image for project: 'Wicket'
  1. Wicket
  2. WICKET-6668

Sign out the existing session if a sign in attempt has failed

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 8.4.0, 7.13.0, 9.0.0-M2
    • 8.5.0, 9.0.0-M2, 7.14.0
    • wicket-auth-roles
    • None

    Description

      If a user is already authenticated but still (s)he goes to the login page and tries to sign in again with invalid credentials Wicket does not fail the attempt but continues successfully.

      The correct behavior would be to report the signIn failure with error feedback message and to sign out the already authenticated user.

      Attachments

        Activity

          People

            mgrigorov Martin Tzvetanov Grigorov
            mgrigorov Martin Tzvetanov Grigorov
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: