[ http://nagoya.apache.org/jira/browse/GERONIMO-509?page=history ]
     
David Jencks resolved GERONIMO-509:
-----------------------------------

     Assign To: Alan Cabrera
    Resolution: Fixed

I've done the simplest possible fix for this in the jetty-deployer branch, rev 
109827.  This could use some review from the security experts for possible 
unfortunate side effects.

> policyConfigurationFactory.getPolicyConfiguration does not return open policy 
> configurations
> --------------------------------------------------------------------------------------------
>
>          Key: GERONIMO-509
>          URL: http://nagoya.apache.org/jira/browse/GERONIMO-509
>      Project: Apache Geronimo
>         Type: Bug
>   Components: security
>     Versions: 1.0-M3
>     Reporter: David Jencks
>     Assignee: Alan Cabrera

>
> JACC 1.0 spec 3.1.1.1 states that 
> policyConfigurationFactory.getPolicyConfiguration(contextId, remove) must 
> return a PolicyConfiguration in the Open state, even if it was in service or 
> deleted before the call.  Our implementation does not change the state of the 
> policy configuration it returns.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
   http://nagoya.apache.org/jira/secure/Administrators.jspa
-
If you want more information on JIRA, or have a bug to report see:
   http://www.atlassian.com/software/jira

Reply via email to