[#2704] [#2710] [3.x] Fixed Session fixation-related regressions#2711
[#2704] [#2710] [3.x] Fixed Session fixation-related regressions#2711lprimak wants to merge 2 commits into
Conversation
|
I backported the fix to 2.22.0 locally and tested with Apache Camel (the project which reported the issue initially). it is working fine on Camel side. I tried with main branch 3.x with Apache Camel but there is a differnt error: The provided value for the Ini.loadFromPath is src/test/resources/securityconfig.ini A last note is that when backporting to 2.20, it is working fine for Camel as I mentioned but I have tests failures in Apache Shiro (but maybe I have not backported correctly?): here is the branch I used for the backport: https://github.com/apupier/shiro/pull/new/backport-session-fixation |
|
That is not going to be an issue as
|
Session fixation enhancements caused regressions.
Affects native session management only
fixes #2704
fixes #2710
Following this checklist to help us incorporate your contribution quickly and easily:
for the change (usually before you start working on it). Trivial changes like typos do not
require a GitHub issue. Your pull request should address just this issue, without pulling in other changes.
[#XXX] - Fixes bug in SessionManager,where you replace
#XXXwith the appropriate GitHub issue. Best practiceis to use the GitHub issue title in the pull request title and in the first line of the commit message.
fixes #XXXif merging the PR should close a related issue.mvn verifyto make sure basic checks pass. A more thorough check will be performed on your pull request automatically.Trivial changes like typos do not require a GitHub issue (javadoc, comments...).
In this case, just format the pull request title like
[DOC] - Add javadoc in SessionManager.If this is your first contribution, you have to read the Contribution Guidelines
If your pull request is about ~20 lines of code you don't need to sign an Individual Contributor License Agreement
if you are unsure please ask on the developers list.
To make clear that you license your contribution under the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.