-
Bug
-
Resolution: Fixed
-
Neutral
-
5.1
-
None
-
None
-
-
Empty show more show less
-
5.2-rc1
In Magnolia we currently have issues handling path parameters such as JSESSIONID. Path parameters are part of the URL and are preceded by a semicolon. The semicolon is a reserved character in URLs.
After MAGNOLIA-3716 we started seeing JSESSIONID appearing more often. We're now asking the servlet container to encode the redirect url before returning it, it will include the JSESSIONID if it thinks its needed.
Jetty has always included the JSESSIONID path parameter in the return from HttpServletRequest.getRequestURI(), as of version 6.0.33 Tomcat does too. See https://issues.apache.org/bugzilla/show_bug.cgi?id=51833 Arguably this is the correct behaviour. It is up to the web application to parse the returned uri and strip path parameters from it.
In Magnolia we need to make sure the JSESSIONID is stripped whenever we access the request object directly and ensure that it's stripped when populating the AggregationState / RenderingContext.
Mime types are not set correctly
In ContentTypeFilter we use the extension to lookup the correct mime type. However the extension we're looking for is jpg;JSESSIONID=123.
This was reported in MAGNOLIA-3841
ServletDispatchingFilter fails to map requests
When the URI contains a JSESSIONID ServletDispatchingFilter does not match it to the servlet.
It uses the uri in AggregationState if a WebContext is present, otherwise it takes it from getRequestURI(). See Mapping.findMatcher().
This is the cause of MAGNOLIA-4911. It was however fixed by using the Servlet 3.0 feature tracking-mode=cookie, this needs to be reverted, see MAGNOLIA-5356
Page rendering fails with 404
When a JSESSIONID is present in the URI AggregatorFilter can't find the content because its looking for a node having it in its name.
Note that this only happens when not using an extension, this is because URI2RepositoryMapping#getHandle strips of the extension and with it the path parameters.
http://demopublic.magnolia-cms.com/demo-project;jsessionid=EE3DB6042B1B57AD55C2633428F44496
Install filter does start Magnolia
When there's a JSESSIONID present the InstallFilter does not recognize the start action in the URI and returns 500
See http://localhost:8080/.magnolia/installer/start;JSESSIONID=123
ContextFilter puts JSESSIONID into MDC
Needs to strip path parameters
BasePatternVoter and subclasses fail to match
When its subclasses URIPatternVoter and URIRegexVoter are used with HttpServletRequest they will not match if a JSESSIONID is present
RequestAttributeStrategy returns uri with JSESSIONID
When asked for the constant "requestURI" it will return it with the JSESSIONID
RedirectClientCallback fails to check if at target
If there's a JSESSIONID in the path the check to see if it's already at the target won't have effect.
RangeSupportFilter includes JSESSIONID in ETag
It needs to be stripped before extracting the file name from the request URI.
- is depended upon by
-
MAGNOLIA-5356 Web.xml uses 2.5 and 3.0 features but specifies 2.4
- Closed
-
MGNLADMLEG-26 AdminTreeMVCServlet fails to find TreeHandler when JSESSIONID is present in URI
- Closed
-
MGNLDAM-322 DamDownloadServlet goes into redirect loop when JSESSIONID present in URI
- Closed
-
MGNLUI-2291 Admincentral fails to start when JSESSIONID present in URI
- Closed
- is duplicated by
-
MAGNOLIA-4003 info.magnolia.module.admininterface.PageMVCServlet#getHandler can be broken with recent tomcat versions
- Closed
- is related to
-
MAGNOLIA-4911 Sticky "jsessionid" URL parameter causes 404 right after login
- Closed
-
MAGNOLIA-3843 Cannot find MIME type for extension "html;jsessionid=(...)"
- Closed
- supersedes
-
MAGNOLIA-3841 Mime type resolution fails when running in jetty due to ;jsessionid being included in the path
- Closed
- mentioned in
-
Wiki Page Loading...