Uploaded image for project: 'Grouper'
  1. Grouper
  2. GRP-265

UI does not enforce role in auth-constraint

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Minor
    • 1.4.2
    • 1.4.0
    • UI
    • None

    Description

      By default the UI only applies a security constraint to /login.do. This allows alternative authentication schemes to easily bypass this URL. The web.xml defines a role - grouper_user which it applies to the auth-constraint thus limiting who can login to those with teh role 'grouper_user'. However, if, after the initial error, a user removes 'login.do' from the url they are able to access the application. This is possible because authentication was successful - a remote user is available - but the UI code does not enforce the role.

      Attachments

        Activity

          People

            isgwb Gary Brown (Inactive)
            isgwb Gary Brown (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: