[ 
https://issues.apache.org/jira/browse/SHINDIG-1382?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12887763#action_12887763
 ] 

Mat Mannion commented on SHINDIG-1382:
--------------------------------------

Yes, we encountered this issue ourselves when we were injecting the 
BasicHttpFetcher into custom code, although I didn't really have time to 
investigate whether it affected other parts of Shindig; though I don't see why 
not.

I think this is important to go in, but I'm just a lowly user and part-time 
contributor. The dev list may have more of an opinion

> MakeRequestHandler keeps and sends cookies regardless of contexes / users 
> etc. 
> -------------------------------------------------------------------------------
>
>                 Key: SHINDIG-1382
>                 URL: https://issues.apache.org/jira/browse/SHINDIG-1382
>             Project: Shindig
>          Issue Type: Bug
>          Components: Java
>    Affects Versions: 2.0.0-RC1
>         Environment: N/A
>            Reporter: Hasan Ceylan
>            Priority: Critical
>         Attachments: shindig-cookie.patch
>
>
> AFAIK, shindig switched to http-comps as the http library. 
> This library by default just like a browser caches the cookies returned by 
> the backend servers and re-uses those cookies all the time.
> Attached patch resolves the issues by rejecting validation of cookies with a 
> custom cookie policy.
> Regards,
> Hasan Ceylan  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to