Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-24792

Don't challenge clients with basic auth on api calls with invalid credentials

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Duplicate
    • Affects Version/s: 9.10, 10.1
    • Fix Version/s: None
    • Component/s: Rest API

      Description

      The server responds with 401 and includes the header WWW-Authenticate: Basic realm="Nuxeo Automation"

      When using webui and the session timeouts, this triggers the browser basic auth dialog which makes no sense if another authentication system is used (like SAML)

      The same issue can also be observed in the new Adobe CC connector.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                6 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: