DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG 
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://nagoya.apache.org/bugzilla/show_bug.cgi?id=15163>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND 
INSERTED IN THE BUG DATABASE.

http://nagoya.apache.org/bugzilla/show_bug.cgi?id=15163

Session timeout does not redirect to login page

           Summary: Session timeout does not redirect to login page
           Product: Jetspeed
           Version: 1.4b2-dev / CVS
          Platform: Other
        OS/Version: Other
            Status: NEW
          Severity: Major
          Priority: Other
         Component: Security
        AssignedTo: [EMAIL PROTECTED]
        ReportedBy: [EMAIL PROTECTED]


If the user keeps the browser open until the session expires and then clicks 
any of the portal links, he/she should be redirected to the login page. 
Instead, the link is followed and, depending on security, certain  portlets are 
now shown with "You have no view permission" message. The user should be 
redirected to login page and message "Session expired, please login again" 
should be displayed.

--
To unsubscribe, e-mail:   <mailto:[EMAIL PROTECTED]>
For additional commands, e-mail: <mailto:[EMAIL PROTECTED]>

Reply via email to