ICEfaces
  1. ICEfaces
  2. ICE-3048

InputFile servlet handler loses security context

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 1.7
    • Fix Version/s: 1.7.2
    • Component/s: ICE-Components
    • Labels:
      None
    • Environment:
      Spring 2.0.3

      Description

      Security context is lost when uploading files

        Issue Links

          Activity

          Hide
          Ken Fyten added a comment -

          Our internal tests are passing using ACEGI and Spring Security. What security configuration are you using? Can you send a test case or post in the forums?

          Show
          Ken Fyten added a comment - Our internal tests are passing using ACEGI and Spring Security. What security configuration are you using? Can you send a test case or post in the forums?
          Hide
          Silvano Maffeis added a comment -

          Hi

          We are using a JAAS security provider under JBoss and we are setting the "enabledOnUserRole" attribute on "ice:menuItem".
          Apparently I'm not the only one still facing this issue with 1.7.2, see Stevi Deter's comments on this ticket.

          Regards,
          Silvano

          Show
          Silvano Maffeis added a comment - Hi We are using a JAAS security provider under JBoss and we are setting the "enabledOnUserRole" attribute on "ice:menuItem". Apparently I'm not the only one still facing this issue with 1.7.2, see Stevi Deter's comments on this ticket. Regards, Silvano
          Hide
          Matthias Roth added a comment -

          Hi same with me,

          we are using Oracle OC4J 10.1.3.x with a custom JAAS LoginModule. Like Silvano reportet, the problem occurs when the page is set with the ice:menuItem and it's attribute "enabledOnUserRole". I've upgraded to the latest prod release 1.7.2., but the Problem remains (i suggest due to the use of JAAS).

          Show
          Matthias Roth added a comment - Hi same with me, we are using Oracle OC4J 10.1.3.x with a custom JAAS LoginModule. Like Silvano reportet, the problem occurs when the page is set with the ice:menuItem and it's attribute "enabledOnUserRole". I've upgraded to the latest prod release 1.7.2., but the Problem remains (i suggest due to the use of JAAS).
          Hide
          Silvano Maffeis added a comment -

          Hi Matthias

          probably we should file a new support ticket. This one was closed. I asked to reopen it a couple of weeks ago but it remained closed.
          I think now its pretty clear what causes the exception (JAAS, ice:menuItem and attribute "enabledOnUserRole")
          so the ICEfaces team should be able to reproduce the bug and solve it. If they want.

          If you happen to open a fresh one, let me know at silvano@maffeis.com so I can add my comments and add my vote, too.

          Regards,
          Silvano

          Show
          Silvano Maffeis added a comment - Hi Matthias probably we should file a new support ticket. This one was closed. I asked to reopen it a couple of weeks ago but it remained closed. I think now its pretty clear what causes the exception (JAAS, ice:menuItem and attribute "enabledOnUserRole") so the ICEfaces team should be able to reproduce the bug and solve it. If they want. If you happen to open a fresh one, let me know at silvano@maffeis.com so I can add my comments and add my vote, too. Regards, Silvano
          Hide
          Silvano Maffeis added a comment -

          FileUpload component still does not work in ICEFaces 1.8.2 if the component resides on a JSF page protected by JAAS authentication. This issue has been around for so long now, very frustrating.

          Show
          Silvano Maffeis added a comment - FileUpload component still does not work in ICEFaces 1.8.2 if the component resides on a JSF page protected by JAAS authentication. This issue has been around for so long now, very frustrating.

            People

            • Assignee:
              Unassigned
              Reporter:
              Philip Breau
            • Votes:
              12 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: