[Issue 3590] New - Hudson build-in user management creates a user for each failed login

classic Classic list List threaded Threaded
4 messages Options
Reply | Threaded
Open this post in threaded view
|

[Issue 3590] New - Hudson build-in user management creates a user for each failed login

kukudas-2
https://hudson.dev.java.net/issues/show_bug.cgi?id=3590
                 Issue #|3590
                 Summary|Hudson build-in user management creates a user for eac
                        |h failed login
               Component|hudson
                 Version|current
                Platform|All
              OS/Version|Windows XP
                     URL|
                  Status|NEW
       Status whiteboard|
                Keywords|
              Resolution|
              Issue type|DEFECT
                Priority|P3
            Subcomponent|other
             Assigned to|issues@hudson
             Reported by|kukudas






------- Additional comments from [hidden email] Wed Apr 29 07:15:12 +0000 2009 -------
i'm using the build-in user management from hudson. Every user can do everything
when he is logged in. If somebody enters a username that does not exists the
login fails as expected. However this user gets added on the user list an can
only be deleted by restarting hudson (so i'm guessing hudson holds him in the
memory)

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

[Issue 3590] Hudson build-in user management creates a user for each failed login

Alan Harder-2
https://hudson.dev.java.net/issues/show_bug.cgi?id=3590



User mindless changed the following:

                What    |Old value                 |New value
================================================================================
             Assigned to|issues@hudson             |mindless
--------------------------------------------------------------------------------




------- Additional comments from [hidden email] Sun Jul  5 20:15:35 +0000 2009 -------
started

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

[Issue 3590] Hudson build-in user management creates a user for each failed login

scm_issue_link
In reply to this post by kukudas-2
https://hudson.dev.java.net/issues/show_bug.cgi?id=3590



User scm_issue_link changed the following:

                What    |Old value                 |New value
================================================================================
                  Status|NEW                       |RESOLVED
--------------------------------------------------------------------------------
              Resolution|                          |FIXED
--------------------------------------------------------------------------------




------- Additional comments from [hidden email] Sun Jul  5 20:17:58 +0000 2009 -------
Code changed in hudson
User: : mindless
Path:
 trunk/hudson/main/core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java
http://fisheye4.cenqua.com/changelog/hudson/?cs=19411
Log:
[FIXED HUDSON-3590] don't create new in-memory user when someone attempts
login with invalid username


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Reply | Threaded
Open this post in threaded view
|

[Issue 3590] Hudson build-in user management creates a user for each failed login

scm_issue_link
In reply to this post by kukudas-2
https://hudson.dev.java.net/issues/show_bug.cgi?id=3590






------- Additional comments from [hidden email] Sun Jul  5 23:59:08 +0000 2009 -------
Code changed in hudson
User: : mindless
Path:
 trunk/hudson/main/core/src/main/java/hudson/model/User.java
http://fisheye4.cenqua.com/changelog/hudson/?cs=19412
Log:
[HUDSON-3590] load user when create flag is false if user has a config file
(this should not be considered "creating" the user), so login works even if
User.getAll has not yet been called.  fixes regression from r19411


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]