Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-2655

Disallow Userinfo in KnoxSSO originalURL Query Param

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.6.0
    • KnoxSSO
    • None

    Description

      There is no valid reason that I can think of to allow userinfo in a URL for an application/UI that is participating in KnoxSSO. The userinfo is used to login to hosts/pages that are protected by HTTP Basic. This is contradictory to the use of KnoxSSO to begin with and complicates the regex pattern required to indicate those URLs that are allowed for redirect and/or dispatch.

      Attachments

        Issue Links

          Activity

            People

              lmccay Larry McCay
              lmccay Larry McCay
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2h 50m
                  2h 50m