[jira] [Commented] (SLING-3443) Parameter based redirection in FormAuthenticationHandler should not handle absolute urls
[ https://issues.apache.org/jira/browse/SLING-3443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13930183#comment-13930183 ] ASF GitHub Bot commented on SLING-3443: --- Github user bond- closed the pull request at: https://github.com/apache/sling/pull/12 Parameter based redirection in FormAuthenticationHandler should not handle absolute urls Key: SLING-3443 URL: https://issues.apache.org/jira/browse/SLING-3443 Project: Sling Issue Type: Bug Components: Authentication Affects Versions: Form Based Authentication 1.0.2 Reporter: Ravi Teja Assignee: Carsten Ziegeler Priority: Critical Fix For: Form Based Authentication 1.0.6 Original Estimate: 48h Remaining Estimate: 48h Suppose your login url is: http://blah/blah?resource=http://www.google.com Then after login succeeds, user would be redirected to http://www.google.com Will be submitting a pull request for this. -- This message was sent by Atlassian JIRA (v6.2#6252)
[jira] [Commented] (SLING-3443) Parameter based redirection in FormAuthenticationHandler should not handle absolute urls
[ https://issues.apache.org/jira/browse/SLING-3443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13925622#comment-13925622 ] Ravi Teja commented on SLING-3443: -- Yeah and I also think that the new code that has been added should be covered by tests. It's the best way to make sure that we don't hit any regressions. :) Parameter based redirection in FormAuthenticationHandler should not handle absolute urls Key: SLING-3443 URL: https://issues.apache.org/jira/browse/SLING-3443 Project: Sling Issue Type: Bug Components: Authentication Affects Versions: Form Based Authentication 1.0.2 Reporter: Ravi Teja Priority: Critical Original Estimate: 48h Remaining Estimate: 48h Suppose your login url is: http://blah/blah?resource=http://www.google.com Then after login succeeds, user would be redirected to http://www.google.com Will be submitting a pull request for this. -- This message was sent by Atlassian JIRA (v6.2#6252)
[jira] [Commented] (SLING-3443) Parameter based redirection in FormAuthenticationHandler should not handle absolute urls
[ https://issues.apache.org/jira/browse/SLING-3443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13925640#comment-13925640 ] Carsten Ziegeler commented on SLING-3443: - Yepp, I agree - I'Ve added your test and adapted it Parameter based redirection in FormAuthenticationHandler should not handle absolute urls Key: SLING-3443 URL: https://issues.apache.org/jira/browse/SLING-3443 Project: Sling Issue Type: Bug Components: Authentication Affects Versions: Form Based Authentication 1.0.2 Reporter: Ravi Teja Priority: Critical Original Estimate: 48h Remaining Estimate: 48h Suppose your login url is: http://blah/blah?resource=http://www.google.com Then after login succeeds, user would be redirected to http://www.google.com Will be submitting a pull request for this. -- This message was sent by Atlassian JIRA (v6.2#6252)
[jira] [Commented] (SLING-3443) Parameter based redirection in FormAuthenticationHandler should not handle absolute urls
[ https://issues.apache.org/jira/browse/SLING-3443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13925648#comment-13925648 ] Ravi Teja commented on SLING-3443: -- Just a suggestion. I think you might want to fix your build on: https://travis-ci.org/apache/sling/ Is there someother CI that is in use? Parameter based redirection in FormAuthenticationHandler should not handle absolute urls Key: SLING-3443 URL: https://issues.apache.org/jira/browse/SLING-3443 Project: Sling Issue Type: Bug Components: Authentication Affects Versions: Form Based Authentication 1.0.2 Reporter: Ravi Teja Priority: Critical Original Estimate: 48h Remaining Estimate: 48h Suppose your login url is: http://blah/blah?resource=http://www.google.com Then after login succeeds, user would be redirected to http://www.google.com Will be submitting a pull request for this. -- This message was sent by Atlassian JIRA (v6.2#6252)