-
1. Re: Bug with post data surviving form based login?
martin0 Mar 28, 2004 5:14 PM (in response to martin0)I've run this test with 3.2.4RC1 and it fails
I've also run the test with standalone tomcat 5.0.19 and it passes.
I will post this as a bug in the morning
Martin -
2. Re: Bug with post data surviving form based login?
rmaucher Mar 28, 2004 5:22 PM (in response to martin0)"Martin0" wrote:
I've run this test with 3.2.4RC1 and it fails
I've also run the test with standalone tomcat 5.0.19 and it passes.
I will post this as a bug in the morning
This does not make any sense to me, so I recommend testing again. -
3. Re: Bug with post data surviving form based login?
uhurusurfa Mar 28, 2004 6:01 PM (in response to martin0)I have had the same problem with the POST functionality. Some sales guy from JBOSS promise he would have the "engineers" have a look... that was 4 weeks ago or more.
Don't hold your breath.
SIMPLE BASIC functionality not working. -
4. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 2:00 AM (in response to martin0)The test is quite simple
form.html(unprotected) posts data to process.jsp(protected)
Files included below for convenience:
form.html<html>
<body>
<form action="process.jsp" method="post">
<input type="text" name="text1"/>
<input type="submit" value="OK"/>
</form>
</body>
</html>
process.jsp<html>
<body>
text1=<%=request.getParameter("text1")%>
</body>
</html>
web.xml<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE web-app PUBLIC "-//Sun Microsystems, Inc.//DTD Web Application 2.3//EN" "http://java.sun.com/dtd/web-app_2_3.dtd">
<web-app >
<session-config>
<session-timeout>2</session-timeout>
</session-config>
<security-constraint>
<web-resource-collection>
<web-resource-name>Signon</web-resource-name>
<description>Declarative security tests</description>
<!--url-pattern>/form.html</url-pattern-->
<url-pattern>/process.jsp</url-pattern>
<url-pattern>/login.html</url-pattern>
<http-method>HEAD</http-method>
<http-method>GET</http-method>
<http-method>POST</http-method>
<http-method>PUT</http-method>
<http-method>DELETE</http-method>
</web-resource-collection>
<auth-constraint>
<role-name>customer</role-name>
<role-name>merchant</role-name>
<role-name>admin</role-name>
</auth-constraint>
<user-data-constraint>
<description>no description</description>
<transport-guarantee>NONE</transport-guarantee>
</user-data-constraint>
</security-constraint>
<login-config>
<auth-method>FORM</auth-method>
<form-login-config>
<form-login-page>/login.html</form-login-page>
<form-error-page>/login.html</form-error-page>
</form-login-config>
</login-config>
<security-role>
<role-name>customer</role-name>
</security-role>
<security-role>
<role-name>merchant</role-name>
</security-role>
<security-role>
<role-name>admin</role-name>
</security-role>
</web-app>
jboss-web.xml<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE jboss-web PUBLIC "-//JBoss//DTD Web Application 2.3//EN" "http://www.jboss.org/j2ee/dtd/jboss-web_3_0.dtd">
<jboss-web>
<security-domain>java:/jaas/authtest</security-domain>
<!-- Resource Environment References -->
<!-- Resource references -->
<!-- EJB References -->
</jboss-web>
FYI, the loginmodule I'm using with JBoss is DatabaseServerLoginModule
RSVP
Martin -
5. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 2:01 AM (in response to martin0)form.html
<html>
<body>
<form action="process.jsp" method="post">
<input type="text" name="text1"/>
<input type="submit" value="OK"/>
</form>
</body>
</html> -
6. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 2:04 AM (in response to martin0)the forum can't display the html for my form
It's just a form, action is process.jsp, method is post
it has 1 input type text name text1
another input type submit, value OK
That's it -
7. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 2:08 AM (in response to martin0)As an aside, I see the the description tags also disappear in a quote block eg web.xml above
-
8. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 4:36 AM (in response to martin0)JBoss, please let me know what logging you would like turned on to supply further information if you are not able to reproduce this yourselves.
Thanks
Martin -
9. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 6:12 AM (in response to martin0)Something else that might throw more light on the situation....
the access log in jboss3.2.3 reports that the GET method is used to access process.jsp, where it should be the POST method.
This would explain why the post data is lost.
Martin -
10. Re: Bug with post data surviving form based login?
starksm64 Mar 29, 2004 9:40 AM (in response to martin0)Post a bug report to sourceforge with the sample war.
http://sourceforge.net/tracker/?group_id=22866&atid=376685 -
11. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 10:57 AM (in response to martin0) -
12. Re: Bug with post data surviving form based login?
martin0 Mar 29, 2004 12:58 PM (in response to martin0)Scott,
What is the process for getting a fix/workaround published, and informing people of it's timing?
Thanks
Martin -
13. Re: Bug with post data surviving form based login?
starksm64 Mar 30, 2004 7:13 PM (in response to martin0)Wait until its fixed by watching the bug report.
-
14. Re: Bug with post data surviving form based login?
martin0 Mar 31, 2004 7:14 AM (in response to martin0)Hi Remy,
It looks like this issue has been closed by you on sourceforge, with a resolution of "fixed".
Does this mean there will be some new code out soon that I can use to solve this problem? When will that be - the overnight CVS? If so, a pointer to the specifc file affected would be good - just enough to build the affected jar.
Thanks for your help
Martin