Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-516

GeronimoPolicy tries to use guaranteed open PolicyConfigurations as if they are in service

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.0-M3
    • None
    • security
    • None

    Description

      JACC spec 3.1.1.1 assures us that
      GeronimoPolicyConfiguration configuration = (GeronimoPolicyConfiguration)factory.getPolicyConfiguration(contextID, false);

      will always return a PolicyConfiguration that is in the open state.

      The next line is:

      if (configuration.inService()) {
      if (configuration.implies(domain, permission)) return true;

      This bug was hidden by the previous behavior of not opening configurations when getPolicyConfiguration was called.

      Attachments

        Activity

          People

            maguro Alan Cabrera
            djencks David Jencks
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: