[Geoserver-devel] [jira] (GEOS-5921) Disabling anonymous authentication for the GUI results in an HTTP redirect loop

Christian Mueller created BugGEOS-5921
Disabling anonymous authentication for the GUI results in an HTTP redirect loop

Issue Type:

BugBug

Affects Versions:

2.3.4, 2.4-beta

Assignee:

Christian Mueller

Components:

Security

Created:

23/Jul/13 8:43 AM

Description:

GeoServer needs an existing authentication to work properly. If the anonymous authentication filter is removed from the web filter chain (GUI), it is not possible to log in.

This is a chicken and egg problem. The GeoServerLoginPage itself is protected by the web filter chain.

Solution:
Make the GeoServerLoginPage and needed resources (png,gif,…) public. (Accessible without any authentication).

Project:

GeoServer

Priority:

MajorMajor

Reporter:

Christian Mueller

This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: [http://www.atlassian.com/software/jira](http://www.atlassian.com/software/jira)