Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 31815 invoked from network); 16 Jan 2009 11:41:00 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 16 Jan 2009 11:41:00 -0000 Received: (qmail 76465 invoked by uid 500); 16 Jan 2009 11:40:43 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 76437 invoked by uid 500); 16 Jan 2009 11:40:42 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 76426 invoked by uid 99); 16 Jan 2009 11:40:42 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 16 Jan 2009 03:40:42 -0800 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of p@pidster.com designates 87.106.82.221 as permitted sender) Received: from [87.106.82.221] (HELO s15243851.onlinehome-server.info) (87.106.82.221) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 16 Jan 2009 11:40:34 +0000 Received: (qmail 3334 invoked from network); 16 Jan 2009 11:40:11 +0000 Received-SPF: neutral (s15243851.onlinehome-server.info: 78.86.122.68 is neither permitted nor denied by domain of pidster.com) client-ip=78.86.122.68; envelope-from=p@pidster.com; helo=Aerial.config; Received: from 78-86-122-68.zone2.bethere.co.uk (HELO Aerial.config) (78.86.122.68) by s15243851.onlinehome-server.info with SMTP; 16 Jan 2009 11:40:10 +0000 Message-ID: <49707219.6070906@pidster.com> Date: Fri, 16 Jan 2009 11:40:09 +0000 From: Pid Reply-To: p@pidster.com Organization: Pid Inc User-Agent: Thunderbird 2.0.0.19 (Macintosh/20081209) MIME-Version: 1.0 To: Tomcat Users List Subject: Re: Tomcat 6.x security-constraint redirection problem... please help! References: <21448079.post@talk.nabble.com> <496DC6EA.5060007@pidster.com> <496F6E22.3010809@christopherschultz.net> In-Reply-To: <496F6E22.3010809@christopherschultz.net> X-Enigmail-Version: 0.95.7 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on apache.org Christopher Schultz wrote: > Pid, > > Pid wrote: >> There's a couple of things that may be confusing the config below, which >> have some simple corrections. > >> I usually place "login.jsp" and "error.jsp" in "WEB-INF/login/", where >> they are protected from unwanted attention by default - this avoids the >> need to protect them with a security-contstraint. > > Agreed. I've found that when using Tomcat to serve static content, these > things tend to happen. The reason is that Tomcat saves the first > unauthorized request and then repeats it after successful > authentication. If the last request was for something like a CSS file > (say, because the CSS file was protected, but the main page wasn't), > then you'll end up being served the CSS file after login. It can be very > disorienting. > >> Tomcat returns the *first* file you requested inside the secured area >> after authentication is completed. So for some reason your browser is >> requesting a script or CSS file before the JSP page. > > For some reason, I thought it was the most recent request it saved. > First makes more sense; thanks for mentioning it. I have an app with a page which contains a flash object (displays a nice graph) that calls a groovy script periodically to get data. If the user session times out in between requests for the script then when it's requested it's the first one after de-auth, so it becomes the target that is re-established after re-login, (obviously not useful for users). I've been attempting to stop the periodic request by monitoring the session period, but haven't had time to properly address it yet. :( p > -chris > --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org