Back to bug 1368525

Who When What Removed Added
Ben Bennett 2016-08-19 16:57:57 UTC Assignee bbennett mnewby
Eric Rich 2016-08-19 17:15:12 UTC Status NEW ON_QA
CC erich, mnewby
Flags needinfo?(mnewby)
Josep 'Pep' Turro Mauri 2016-08-19 17:20:35 UTC Status ON_QA NEW
Flags needinfo?(mnewby) needinfo?(erich)
Eric Rich 2016-08-19 17:26:48 UTC Flags needinfo?(erich)
Maru Newby 2016-08-19 17:57:14 UTC Link ID Origin (Github) 10544
Eric Paris 2016-08-19 18:06:38 UTC Status NEW POST
CC eparis
Ben Bennett 2016-08-19 19:42:06 UTC Status POST MODIFIED
CC bbennett
Eric Paris 2016-08-22 14:10:39 UTC Status MODIFIED ON_QA
Meng Bo 2016-08-23 08:13:11 UTC Status ON_QA VERIFIED
CC bmeng
Troy Dawson 2016-09-07 20:35:26 UTC CC tdawson
Maru Newby 2016-09-19 23:12:43 UTC Doc Text Cause: When an edge-terminated Route had insecureEdgeTerminationPolicy set to Allow — meaning that the Route could be accessed by both http and https — the inserted session cookie was always flagged as Secure.

Consequence: When a client connected over http the secure cookie would be dropped, breaking session persistence.

Fix: Cookies for edge-terminated routes that allow insecure connections are set to be non-secure.

Result: Session persistence for such routes is maintained.
Doc Type If docs needed, set a value Bug Fix
Maru Newby 2016-09-21 13:34:51 UTC Target Release --- 3.3.0
errata-xmlrpc 2016-09-27 00:33:48 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2016-09-27 09:45:14 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2016-09-27 05:45:14 UTC
Dan McPherson 2017-03-08 18:26:17 UTC Target Release 3.3.0
Miciah Dashiel Butler Masters 2022-08-04 22:20:48 UTC Sub Component router
Component Routing Networking

Back to bug 1368525