James Moger
2013-06-17 06b691211585fbe4049099b15fffb4cdc42cb728
Do not set cookies for sessions authenticated via certificate or container
1 files modified
5 ■■■■ changed files
src/main/java/com/gitblit/GitBlit.java 5 ●●●● patch | view | raw | blame | history
src/main/java/com/gitblit/GitBlit.java
@@ -929,7 +929,10 @@
        if (userService == null) {
            return;
        }
        if (userService.supportsCookies()) {
        GitBlitWebSession session = GitBlitWebSession.get();
        boolean standardLogin = session.authenticationType.isStandard();
        if (userService.supportsCookies() && standardLogin) {
            Cookie userCookie;
            if (user == null) {
                // clear cookie for logout