-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/28755/
-----------------------------------------------------------
(Updated Dec. 8, 2014, 6:35 p.m.)
Review request for shindig.
Changes
-------
I discovered that all oauth2 redirect calls are already setting strictNoCache.
The RequestPipeline was not looking at this when deciding if to cache or not
and it should be. So I added the check and now all oauth2 redirect calls
(including the one that returns the approval url) is not cached. I tweaked the
unit test to test the strictNoCache functionality instead of just the approval
url.
Bugs: SHINDIG-1984
https://issues.apache.org/jira/browse/SHINDIG-1984
Repository: shindig
Description
-------
When doing an OAUTH2 flow the first request to the service that returns the
oauthApprovalUrl probably shouldn’t be cached or set in the staleResponse,
because then it could possibly be used on the response for the ACTUAL request
if it returns a 500. Thus an endless loop of display the approval url and
making the service call.
Diffs (updated)
-----
trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/http/DefaultRequestPipeline.java
1642996
trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/http/DefaultRequestPipelineTest.java
1642996
Diff: https://reviews.apache.org/r/28755/diff/
Testing
-------
Thanks,
Doug Davies