Uploaded image for project: '[Read Only] - Hippo Site Toolkit 2'
  1. [Read Only] - Hippo Site Toolkit 2
  2. HSTTWO-1938

In the CmsSecurityValve clear up the jcr SSOSession after each call and login a new one for each new request

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • None
    • 2.24.03, 2.25.04-alpha
    • None
    • None

    Description

      To make the CmsSecurityValve more robust, and make sure that the HttpSession binded jcr session cannot be out-of-sync (which we seemed to have in a clustered environment with concurrent copying hst config for same subsite), we need to logout the JCR session at the end, and login + refresh at the beginning (refresh just to make sure all latest changes from the repo has been synced in clustered env)

      Attachments

        Activity

          People

            jsheriff Junaidh Kadhar Sheriff
            aschrijvers Ard Schrijvers
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: