Uploaded image for project: 'Magnolia'
  1. Magnolia
  2. MAGNOLIA-4389

URISecurityFilter#isAllowed does not set proper status code for anonymous user

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 4.5.3
    • 4.5.2
    • security
    • None

      BasicAuthentication's prompting for credentials is only triggered when status is set to HttpServletResponse.SC_UNAUTHORIZED.
      We should set status HttpServletResponse.SC_UNAUTHORIZED for anonymous user - HttpServletResponse.SC_FORBIDDEN else.

        Acceptance criteria

              dlipp Daniel Lipp
              dlipp Daniel Lipp
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Bug DoR
                  Task DoD