Bug #7737
closed
Change for issue 6999 broke logout for PAM-based (intercept) authentication
Added by Jan Pazdziora about 10 years ago.
Updated over 6 years ago.
Description
The change that went into Foreman as 4e3a7e7a2a5 prevents /users/logout to be called as GET. Alas, app/services/sso/form_intercept.rb defines controller.main_app.logout_users_path as logout_url. Logging out from user session which was started via PAM-based (intercepted) logon form login fails with
The page you were looking for doesn't exist.
You may have mistyped the address or the page may have moved.
- Status changed from New to Ready For Testing
- Target version set to 1.7.3
- Pull request https://github.com/theforeman/foreman/pull/1807 added
- Pull request deleted (
)
- Related to Bug #6999: CVE-2014-3590 - User logout susceptible to CSRF attack added
- Related to Bug #7738: Some SSO methods may fail added
- Subject changed from Change for issue 6999 broke logout for external authentication to Change for issue 6999 broke logout for PAM-based (intercept) authentication
- Translation missing: en.field_release set to 22
- Target version changed from 1.7.3 to 1.7.2
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
Also available in: Atom
PDF