From: Mathieu Baudier Date: Sun, 22 Nov 2015 11:33:30 +0000 (+0000) Subject: Prevent anonymous session to be authenticated X-Git-Tag: argeo-commons-2.1.30~8 X-Git-Url: https://git.argeo.org/?a=commitdiff_plain;h=ae0971ce77c7a7d5daaed3b84ae4a277f97449e2;p=lgpl%2Fargeo-commons.git Prevent anonymous session to be authenticated git-svn-id: https://svn.argeo.org/commons/trunk@8584 4cfe0d0a-d680-48aa-b62c-e0a02a3f76cc --- diff --git a/org.argeo.cms/src/org/argeo/cms/auth/UserAdminLoginModule.java b/org.argeo.cms/src/org/argeo/cms/auth/UserAdminLoginModule.java index 53b4242ef..db677f57e 100644 --- a/org.argeo.cms/src/org/argeo/cms/auth/UserAdminLoginModule.java +++ b/org.argeo.cms/src/org/argeo/cms/auth/UserAdminLoginModule.java @@ -126,7 +126,7 @@ public class UserAdminLoginModule implements LoginModule, AuthConstants { public boolean commit() throws LoginException { Authorization authorization = subject .getPrivateCredentials(Authorization.class).iterator().next(); - if (request != null) { + if (request != null && authorization.getName() != null) { request.setAttribute(HttpContext.REMOTE_USER, authorization.getName()); request.setAttribute(HttpContext.AUTHORIZATION, authorization);