From 62e0259129fa7147a3899244569c05f4e7fd3b7c Mon Sep 17 00:00:00 2001
From: Joel Johnson <joel.johnson@issinc.com>
Date: Tue, 14 Jul 2015 15:59:29 -0400
Subject: [PATCH] prevent session fixation for external authentication
---
src/main/java/com/gitblit/utils/HttpUtils.java | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/src/main/java/com/gitblit/utils/HttpUtils.java b/src/main/java/com/gitblit/utils/HttpUtils.java
index ffea81c..818ed49 100644
--- a/src/main/java/com/gitblit/utils/HttpUtils.java
+++ b/src/main/java/com/gitblit/utils/HttpUtils.java
@@ -80,7 +80,7 @@
String context = request.getContextPath();
String forwardedContext = request.getHeader("X-Forwarded-Context");
- if (forwardedContext != null) {
+ if (StringUtils.isEmpty(forwardedContext)) {
forwardedContext = request.getHeader("X_Forwarded_Context");
}
if (!StringUtils.isEmpty(forwardedContext)) {
--
Gitblit v1.9.1