oasp / oasp4j

The Open Application Standard Platform for Java
Apache License 2.0
60 stars 303 forks source link

Fix for 456, 424 #500

Closed jomora closed 8 years ago

jomora commented 8 years ago

This PR fixes a critical bug in the authentication mechanism. The solution has been provided by @sroeger in #463. Due to merge problems I implemented the solution again to have a clear and concise PR. I will #463 now.

Please review the changes!

oasp-ci commented 8 years ago

Can one of the admins verify this patch?

hohwille commented 8 years ago

I also reworked the review comments to finally finalize this fix. @jomora Thanks for your PR!

hohwille commented 8 years ago

For the record: of course I also tested and verified that now login is only possible with correct pwd.