Remy, I have to -1 your change in AuthenticatorBase 1.13. You broke a larger case than you fixed -- Mozilla may work now but IE doesn't. See bugs 34083, 27122, 28662, 29336, 29975, and 30618 for the IE problem. Mozilla should be fixed in a way compatible with IE.

By uncommenting !isSecure, my change in 1.26 and on can all be backed out.

If no one else is concerned that Tomcat 5.5 doesn't work by default with IE under SSL, then I'll withdraw my veto and rename the attribute I added to 'securePagesWithPragma' and make the pragma conditional, with a default of being included.


Remy Maucherat wrote:
I see more and more people trying to shove down people's throat whatever defaults they like best.

:-) me too

