Return-Path: X-Original-To: apmail-hadoop-common-issues-archive@minotaur.apache.org Delivered-To: apmail-hadoop-common-issues-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 972ABD2CF for ; Mon, 18 Jun 2012 18:05:44 +0000 (UTC) Received: (qmail 28243 invoked by uid 500); 18 Jun 2012 18:05:43 -0000 Delivered-To: apmail-hadoop-common-issues-archive@hadoop.apache.org Received: (qmail 28169 invoked by uid 500); 18 Jun 2012 18:05:43 -0000 Mailing-List: contact common-issues-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: common-issues@hadoop.apache.org Delivered-To: mailing list common-issues@hadoop.apache.org Received: (qmail 27886 invoked by uid 99); 18 Jun 2012 18:05:43 -0000 Received: from issues-vm.apache.org (HELO issues-vm) (140.211.11.160) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 18 Jun 2012 18:05:43 +0000 Received: from isssues-vm.apache.org (localhost [127.0.0.1]) by issues-vm (Postfix) with ESMTP id 7A4CA142863 for ; Mon, 18 Jun 2012 18:05:43 +0000 (UTC) Date: Mon, 18 Jun 2012 18:05:43 +0000 (UTC) From: "Alejandro Abdelnur (JIRA)" To: common-issues@hadoop.apache.org Message-ID: <316986899.25893.1340042743503.JavaMail.jiratomcat@issues-vm> In-Reply-To: <1111000095.21265.1339819303134.JavaMail.jiratomcat@issues-vm> Subject: [jira] [Updated] (HADOOP-8512) AuthenticatedURL should reset the Token when the server returns other than OK on authentication MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/HADOOP-8512?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alejandro Abdelnur updated HADOOP-8512: --------------------------------------- Attachment: HADOOP-8512b1.patch attaching patch for branch-1, committed there as well. > AuthenticatedURL should reset the Token when the server returns other than OK on authentication > ----------------------------------------------------------------------------------------------- > > Key: HADOOP-8512 > URL: https://issues.apache.org/jira/browse/HADOOP-8512 > Project: Hadoop Common > Issue Type: Bug > Components: security > Affects Versions: 2.0.0-alpha > Reporter: Alejandro Abdelnur > Assignee: Alejandro Abdelnur > Priority: Minor > Fix For: 1.2.0, 2.0.1-alpha > > Attachments: HADOOP-8512.patch, HADOOP-8512b1.patch > > > Currently the token is not being reset and if using AuthenticatedURL, it will keep sending the invalid token as Cookie. There is not security concern with this, the main inconvenience is the logging being generated on the server side. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa For more information on JIRA, see: http://www.atlassian.com/software/jira