]> source.dussan.org Git - gitblit.git/commit
prevent session fixation for external authentication 908/head
authorJoel Johnson <joel.johnson@issinc.com>
Fri, 26 Jun 2015 22:10:54 +0000 (16:10 -0600)
committerJoel Johnson <mrjoel@lixil.net>
Tue, 14 Jul 2015 19:59:29 +0000 (13:59 -0600)
commit62e0259129fa7147a3899244569c05f4e7fd3b7c
tree02747b84d28c32ead796bc70c03276e50eec4153
parent4dfbfdd4681cfad922725f8989450c24eaed64f5
prevent session fixation for external authentication

  + use request instead of session to flag authentication status
    and user, for external authentication types
src/main/java/com/gitblit/Constants.java
src/main/java/com/gitblit/manager/AuthenticationManager.java
src/main/java/com/gitblit/wicket/pages/RootPage.java
src/main/java/com/gitblit/wicket/pages/SessionPage.java