Jody Garnett ( 
https://osgeo-org.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Ae422bb7f-4808-47e3-837f-13db0e6681e3
 ) *created* an issue

GeoServer ( 
https://osgeo-org.atlassian.net/browse/GEOS?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 ) / Bug ( 
https://osgeo-org.atlassian.net/browse/GEOS-10761?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 ) GEOS-10761 ( 
https://osgeo-org.atlassian.net/browse/GEOS-10761?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 ) Failed login with encrypt URL parameters setting results in 404 ( 
https://osgeo-org.atlassian.net/browse/GEOS-10761?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 )

Issue Type: Bug Affects Versions: 2.21.2, 2.22.0 Assignee: Unassigned 
Components: Wicket UI Created: 29/Nov/22 4:48 PM Environment:

Java 11, Tomcat 8.5

Priority: Medium Reporter: Jody Garnett ( 
https://osgeo-org.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Ae422bb7f-4808-47e3-837f-13db0e6681e3
 )

Failed login page inaccessible when encrypt URL parameters enabled:

* Login as admin
* Change Security Settings *Encrypt web admin URL parameters* (as described 
here ( 
https://docs.geoserver.org/latest/en/user/security/webadmin/settings.html#encryption
 ) )
* Logout, the home page has a random {{wicket-crypt= }}parameter to keep the 
sequence from being guessable
* Fail to login, and be redirected to 404 page:
http://localhost:8080/geoserver/web/wicket/bookmarkable/org.geoserver.web.GeoServerLoginPage?error=true
 ( 
http://localhost:8080/geoserver/web/wicket/bookmarkable/org.geoserver.web.GeoServerLoginPage?error=true
 )

See attached screen snap for comparison.

( 
https://osgeo-org.atlassian.net/browse/GEOS-10761#add-comment?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 ) Add Comment ( 
https://osgeo-org.atlassian.net/browse/GEOS-10761#add-comment?atlOrigin=eyJpIjoiNWMxMTkwNzJkMWU5NDk4YmEyMTEzN2I4MWVhNzE4NWUiLCJwIjoiaiJ9
 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( 
https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail
 ) or iOS ( 
https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8
 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100210- 
sha1:4037f92 )
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to