Michael Pasternak has submitted this change and it was merged.
Change subject: restapi : don't set jsessionid cookie when authentication
fails(#927140)
......................................................................
restapi : don't set jsessionid cookie when authentication fails(#927140)
Rest APi returns session id when authentication fails and the user
makes calls with "prefer: persistent-auth"
Change-Id: I84907ab56e99ebb875124f42345d691edad3cdbe
Bug-Url:
https://bugzilla.redhat.com/927140
Signed-off-by: Ravi Nori <rnori(a)redhat.com>
---
M
backend/manager/modules/restapi/interface/common/jaxrs/src/main/java/org/ovirt/engine/api/common/security/auth/Challenger.java
M
backend/manager/modules/restapi/interface/common/jaxrs/src/test/java/org/ovirt/engine/api/common/security/auth/ChallengerTest.java
2 files changed, 16 insertions(+), 11 deletions(-)
Approvals:
Michael Pasternak: Verified; Looks good to me, approved
--
To view, visit
http://gerrit.ovirt.org/14042
To unsubscribe, visit
http://gerrit.ovirt.org/settings
Gerrit-MessageType: merged
Gerrit-Change-Id: I84907ab56e99ebb875124f42345d691edad3cdbe
Gerrit-PatchSet: 2
Gerrit-Project: ovirt-engine
Gerrit-Branch: engine_3.2
Gerrit-Owner: Ravi Nori <rnori(a)redhat.com>
Gerrit-Reviewer: Michael Pasternak <mpastern(a)redhat.com>
Gerrit-Reviewer: Ravi Nori <rnori(a)redhat.com>