Description When an authorized request comes through for the hosted page resources, eg images, css files, the next valve in the chain is not called. A check should be implemented and if the user is authorized and the request is not a SAML request, then call the next valve in the chain. The hosted page itself is not affected, since it is explicitly served/handled by picketlink IDP valve. https://issues.jboss.org/browse/PLINK-412 reproduced on EAP 6.3 ( as per build on 03-june-2014) which uses picketlink 2.5.3.SP5 This needs to be fixed and backported to EAP 6.3 CP01 (as I understand no more blockers accepted for 6.3)
This issue should be fixed in EAP 6.4 release.
Pedro Igor <pigor.craveiro> updated the status of jira PLINK-412 to Resolved
Tom, Is this still an issue ? Also, PL IDP has a limitation where you must use pages in hosted directory in order to provide your welcome files. Regards.
Tested with EAP 6.4 DR8 with a picture located inside the hosted and with a pic outside that folder. => both working fine now ! cheers Tom
Thanks Tom!