The GitHub Actions job "SiteMesh 2 Compatibility" on 
grails-core.git/fix/scaffolding-favicon-session-8.0.x has succeeded.
Run started by GitHub user matrei (triggered by matrei).

Head commit for run:
8168649123127be8a41becdadd751dde23c4e700 / Mattias Reichel 
<[email protected]>
test: keep the browser's favicon fetch out of the scaffolding example's login 
flow

Spring Security's generated login and logout pages declare no icon, so the 
browser
fetches /favicon.ico for them on its own, at low priority and often well after 
the
page has loaded. Under Boot's default chain that fetch is bounced through 
/login,
which renders a CSRF token and so starts a session of its own whenever the 
cookie
it carries is stale: a login has just changed the session id, or a logout has 
just
invalidated it. The Set-Cookie of that background request then overwrites the
session the user has just signed in to, and the next page is the login page 
again,
pristine and without an error. UserControllerSpec timed out on exactly that 
page in
CI whenever the stale fetch landed between the login redirect and the page it 
led to.

The example now permits /favicon.ico and /assets/** on an otherwise default 
chain and
maps /favicon.ico to the icon the layout already serves through the asset 
pipeline.
Permitting alone is not enough: the 404 Grails would answer is forwarded to 
/error,
and that dispatch goes through the chain again.

Report URL: https://github.com/apache/grails-core/actions/runs/35732573828

With regards,
GitHub Actions via GitBox

Reply via email to