Bug 1131582 - [GSS] (6.3.x) PickletLink IdP Filter eating cookies added to response by other filters
Summary: [GSS] (6.3.x) PickletLink IdP Filter eating cookies added to response by othe...
Alias: None
Product: JBoss Enterprise Application Platform 6
Classification: JBoss
Component: Security
Version: 6.3.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: CR2
: EAP 6.3.2
Assignee: Peter Skopek
QA Contact: Ondrej Kotek
Depends On: 1131612
Blocks: 1123427 eap632-blockers, eap632-payload
TreeView+ depends on / blocked
Reported: 2014-08-19 15:27 UTC by Derek Horton
Modified: 2019-08-19 12:41 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 1131612 (view as bug list)
Last Closed: 2019-08-19 12:41:07 UTC
Type: Bug

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker PLINK-529 0 Major Resolved PickletLink IdP Filter eating cookies added to response by other filters 2017-04-20 21:29:03 UTC

Description Derek Horton 2014-08-19 15:27:51 UTC
Description of problem:

PickletLink IdP Filter eating cookies added to response by other filters

Steps to Reproduce:
1. create a filter that adds a cookie to the httpServletResponse (response.addCookie(...))
2. ensure that you are using IDPfilter

Regardless of which is mapped first (cookie filter or idpFilter), the cookies you add to the response will not be returned to the browser. Simply commenting out the IdPFilter mapping will allow the cookies to be properly returned to the browser.

This behavior appears to happen without regard to the presence of a SAML assertion in the incoming request (ie. it doesn't matter if you directly access the IdP or are redirected there from a trusted SP).

Comment 1 Derek Horton 2014-08-19 17:16:15 UTC
Upstream PR:

Comment 4 JBoss JIRA Server 2014-08-25 15:55:02 UTC
Pedro Igor <pigor.craveiro> updated the status of jira PLINK-529 to Resolved

Comment 5 Ondrej Kotek 2014-10-16 08:28:33 UTC
The fix does not work for me. For JBoss EAP 6.3.2.CR1:
  * a test filter is called twice (unlike JBoss EAP 6.3.0)
  * cookies created in the filter are not returned to the browser for base URI (like JBoss EAP 6.3.0)

See BZ 1133099. Backport of PLINK-558 helped. There is manual reproducer available.

BZ 1123427 (Upgrade PicketLink from 2.5.3.SP10-redhat-1 to 2.5.3.SP11-x) is verified but included commits are in wrong order. PLINK-558 commit is the important one and should be placed as the last one.

Comment 6 Ondrej Kotek 2014-10-16 08:37:10 UTC
To be precise: commits in PicketLink Bindings 2.5.3.SP11-redhat-1.

Comment 7 Ivo Studensky 2014-10-20 11:46:22 UTC
Fixed in 2.5.3.SP12.

Comment 8 Ondrej Kotek 2014-10-24 14:12:34 UTC
Verified for JBoss EAP 6.3.2.CR2

Note You need to log in before you can comment on or make changes to this bug.