ICEfaces
  1. ICEfaces
  2. ICE-4179

Session Expired dialog causes security warning to display on IE6 when using HTTPS (SSL) connection

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Minor Minor
    • Resolution: Fixed
    • Affects Version/s: 1.7.2 SP1
    • Fix Version/s: 1.8RC2, 1.8
    • Component/s: Framework
    • Labels:
      None
    • Environment:
      Tomcat6 with SSL

      Description

      On IE6, when SSL is enabled and session is timeout a dialog box shows up with message: "This page contains both secure and nonsecure items. Do you want to display the nonsecure items?" clicking Yes will bring up the same dialog again. Keep clicking Yes the dialog box disappears and the entire page will be greyed out (nothing is click-able). Reloading the page by clicking the Reload button on top brings back the application. Normally, a User Sesson Expired popup message should show up instead.

      (This only happens to IE6. IE7 and IE8 work fine.)

        Activity

        Joanne Bai created issue -
        Hide
        Joanne Bai added a comment -

        Test application used: Component showcase facelets-enhanced version

        Show
        Joanne Bai added a comment - Test application used: Component showcase facelets-enhanced version
        Ken Fyten made changes -
        Field Original Value New Value
        Summary Session expires differently on IE6 when SSL is enabled Session Expired dialog causes security warning to display on IE6 when using HTTPS (SSL) connection
        Salesforce Case []
        Fix Version/s 1.8 [ 10161 ]
        Assignee Priority P2
        Affects Version/s 1.7.2 SP1 [ 10144 ]
        Affects Version/s 1.8 [ 10161 ]
        Security Private [ 10001 ]
        Assignee Yip Ng [ yip.ng ]
        Priority Major [ 3 ] Minor [ 4 ]
        Repository Revision Date User Message
        ICEsoft Public SVN Repository #18491 Fri Mar 06 10:28:24 MST 2009 yip.ng ICE-4179
        Changed value of iframe src attribute to prevent security warning in IE6.
        Files Changed
        Commit graph MODIFY /icefaces/trunk/icefaces/bridge/src/status.js
        yip.ng made changes -
        Attachment ScreenHunter_01 Mar. 06 10.52.jpg [ 11562 ]
        Hide
        yip.ng added a comment -

        There are actually two problems here. One is the security warning, which has now been fixed. The other problem is that the reload dialog doesn't appear at all. This problem happens even with a non-SSL connection. And it happens in the component showcase demo on our website. See attached screenshot. Has it ever worked at all before? The z-indexes are OK, otherwise it would not work in IE7 or Firefox.

        Show
        yip.ng added a comment - There are actually two problems here. One is the security warning, which has now been fixed. The other problem is that the reload dialog doesn't appear at all. This problem happens even with a non-SSL connection. And it happens in the component showcase demo on our website. See attached screenshot. Has it ever worked at all before? The z-indexes are OK, otherwise it would not work in IE7 or Firefox.
        Hide
        Joanne Bai added a comment -

        Here are the test results from the previous releases:

        on ICEfaces-1.7.2-SP1

        • without SSl: no dialog or message box appears. The page just turns gray itself when session is timeout
        • with SSL: Security warning shows and no reload dialog (the same as on 1.8.0)

        on ICEfaces-1.8.0-DR2: the same as on ICEfaces-1.7.2-SP1

        Show
        Joanne Bai added a comment - Here are the test results from the previous releases: on ICEfaces-1.7.2-SP1 without SSl: no dialog or message box appears. The page just turns gray itself when session is timeout with SSL: Security warning shows and no reload dialog (the same as on 1.8.0) on ICEfaces-1.8.0-DR2: the same as on ICEfaces-1.7.2-SP1
        Hide
        yip.ng added a comment -

        New JIRA created for second problem: ICE-4188.

        Show
        yip.ng added a comment - New JIRA created for second problem: ICE-4188 .
        yip.ng made changes -
        Status Open [ 1 ] Resolved [ 5 ]
        Resolution Fixed [ 1 ]
        Hide
        Joanne Bai added a comment -

        QA verified that on 1.8.0 build 7 + IE 6

        • with SSL: the security warning no longer shows up. Page just turns gray itself when session is timeout and no reload dialog appears (which is addressed by JIRA ICE-4188).
        • without SSL: the behavior is the same as with SSL
        Show
        Joanne Bai added a comment - QA verified that on 1.8.0 build 7 + IE 6 with SSL: the security warning no longer shows up. Page just turns gray itself when session is timeout and no reload dialog appears (which is addressed by JIRA ICE-4188 ). without SSL: the behavior is the same as with SSL
        Ken Fyten made changes -
        Fix Version/s 1.8RC2 [ 10163 ]
        Fix Version/s 1.8 [ 10161 ]
        Ken Fyten made changes -
        Fix Version/s 1.8 [ 10161 ]
        Assignee Priority P2
        Ken Fyten made changes -
        Status Resolved [ 5 ] Closed [ 6 ]
        Assignee Yip Ng [ yip.ng ]

          People

          • Assignee:
            Unassigned
            Reporter:
            Joanne Bai
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: