Uploaded image for project: 'Application Server 7'
  1. Application Server 7
  2. AS7-6489

Ensure JBoss 7.2.0-Alpha1 mgmt user session invalidated if user doesn't exist

    Details

      Description

      Had browser open much earlier today and logged into old JBoss 7.1.1.FINAL JBoss management console. Built/setup JBoss 7.2.0-Alpha1 from github jbossas/jboss-as master up-to-date as of earlier this morning. Started server and was no management user so it showed the page indicating that I could not login because there was no user. Added user and refreshed page and I was logged-in. I could be imagining things, but it might be good to check that current session is invalidated in management session if the user doesn't exist. (Also, there is no command to remove a user while the server is up that I can see; if there were, I'd try removing the user, hitting the page to validate I couldn't get in, and then hit it again to try to confirm; but, if no one has complained about the lack of remove-user, then I guess it isn't required.)

      Thanks!

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Assignee:
                dlofthouse Darran Lofthouse
                Reporter:
                garysweaver Gary Weaver
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: