Commit 2ab9bc65 authored by Graham Leggett's avatar Graham Leggett
Browse files

mod_auth_form: Make sure the logged in user is populated correctly

after a form login. Fixes a missing REMOTE_USER variable directly
following a login.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@690493 13f79535-47bb-0310-9956-ffa450edef68
parent 560aadc3
Loading
Loading
Loading
Loading
+4 −0
Changes for CHANGES: 4 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -2,6 +2,10 @@
Changes with Apache 2.3.0
[ When backported to 2.2.x, remove entry from this file ]

  *) mod_auth_form: Make sure the logged in user is populated correctly
     after a form login. Fixes a missing REMOTE_USER variable directly
     following a login. [Graham Leggett]

  *) mod_session_cookie: Make sure that cookie attributes are correctly
     included in the blank cookie when cookies are removed. This fixes an
     inability to log out when using mod_auth_form. [Graham Leggett]
+5 −0
Changes for modules/aaa/mod_auth_form.c: 5 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -941,6 +941,11 @@ static int authenticate_form_authn(request_rec * r)
                           &sent_user, &sent_pw, &sent_loc, &sent_method,
                           &sent_mimetype, &sent_body, conf);

        /* make sure any user detected within the subrequest is saved back to
         * the main request.
         */
        r->user = rr->user;

        /* insert the kept_body filter on the main request to guarantee the
         * input filter stack cannot be read a second time, optionally inject
         * a saved body if one was specified in the login form.