Commit 0ec9f88c authored by Graham Leggett's avatar Graham Leggett
Browse files

mod_auth_form: Make sure that basic authentication is correctly

faked directly after login.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@690506 13f79535-47bb-0310-9956-ffa450edef68
parent fd9e1ad9
Loading
Loading
Loading
Loading
+3 −0
Changes for CHANGES: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -2,6 +2,9 @@
Changes with Apache 2.3.0
[ When backported to 2.2.x, remove entry from this file ]

  *) mod_auth_form: Make sure that basic authentication is correctly
     faked directly after login. [Graham Leggett]

  *) mod_session_cookie, mod_session_dbd: Make sure cookies are set both
     within the output headers and error output headers, so that the
     session is maintained across redirects. [Graham Leggett]
+1 −0
Changes for modules/aaa/mod_auth_form.c: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -972,6 +972,7 @@ static int authenticate_form_authn(request_rec * r)
        if (OK == rv) {
            rv = check_authn(r, sent_user, sent_pw);
            if (OK == rv) {
                fake_basic_authentication(r, conf, sent_user, sent_pw);
                set_session_auth(r, sent_user, sent_pw, conf->site);
                if (sent_loc) {
                    apr_table_set(r->headers_out, "Location", sent_loc);