[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-17 Thread m_bro...@java.net (JIRA)














































m_broida
 commented on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session















I apologize for not reading the earlier posts in more detail.
I added the LogRecorder and the logger as described above.
When I logout and back in, this (among other detail) shows in the log:

Mar 17, 2014 3:49:09 PM FINE org.acegisecurity.ui.rememberme.TokenBasedRememberMeServices loginSuccess
Added remember-me cookie for user 'michael.broida', expiry: 'Mon Mar 31 15:49:09 GMT 2014'

So its set to expire in two weeks: Mar 31 - Mar 17 = 14 days.
My system time was about 10:49AM (US CDT) and the Jenkins Master node time was: 3:49:09PM (UTC).  So those line up correctly: US CDT = UTC-5.
I see log entries like this one cleansed, apparently every time I click a Jenkins link:

  Mar 17, 2014 3:49:09 PM FINE org.acegisecurity.ui.rememberme.RememberMeProcessingFilter doFilter
  SecurityContextHolder not populated with remember-me token, as it already contained: 'org.acegisecurity.providers.UsernamePasswordAuthenticationToken@f05122ff: Username: org.acegisecurity.userdetails.User@0: Username: michael.broida; Password: PROTECTED; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: authenticated, USER, admin; Password: PROTECTED; Authenticated: true; Details: org.acegisecurity.ui.WebAuthenticationDetails@957e: RemoteIpAddress: nn.nn.nn.nn; SessionId: 178z3b1pbslvm1hyjg8qchd6wo; Granted Authorities: authenticated, USER, admin'

Chrome shows an ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie with same Mar 31 expiration as above.

We'll see if Jenkins logs me out in the next couple of hours



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-13 Thread m_bro...@java.net (JIRA)














































m_broida
 commented on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session















On 30/Jul/13, he said he still has to login 10 times a day.
That doesn't sound "resolved" to me.

I'm using Jenkins 1.542, and several times a day Jenkins forgets that I'm logged in.
Browser (Chrome) stays open, but refreshed page is suddenly logged out.

We do not use ActiveDirectory, so this is not related to JENKINS-9258.
We use a local script for authentication.




























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-13 Thread m_bro...@java.net (JIRA)












































 
m_broida
 edited a comment on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session
















His last comment (30/Jul/13) says he still has to login 10 times a day.
That doesn't sound "resolved" to me.

I'm using Jenkins 1.542, and several times a day Jenkins forgets that I'm logged in.
Browser (Chrome) stays open, but refreshed page is suddenly logged out.

We do not use ActiveDirectory, so this is not related to JENKINS-9258.
We use a local script for authentication.




























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-13 Thread m_bro...@java.net (JIRA)












































 
m_broida
 edited a comment on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session
















His last comment (30/Jul/13) says he still has to login 10 times a day.
That doesn't sound "resolved" to me.

I'm using Jenkins 1.542, and several times a day Jenkins forgets that I'm logged in.
Browser (Chrome) stays open, but refreshed page is suddenly logged out.

We do not use ActiveDirectory, so this is not related to JENKINS-9258.
We use a local script for authentication.

Oh, _)%  While typing this entry, Jenkins logged me out AGAIN.  Why?



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-13 Thread hendrik.mill...@tu-clausthal.de (JIRA)














































Hendrik Millner
 commented on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session















It would be great to have some insight into your org.acegisecurity.ui.rememberme log (as described above, 20/Feb/13 3:33 PM), your ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE metadata (time of expiration, ...), the exact Jenkins server time when the cookie is issued (when you perform the login with checked 'remember me'), and finally your system time when you perform the login.



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2014-03-11 Thread k...@kohsuke.org (JIRA)















































Kohsuke Kawaguchi
 resolved  JENKINS-16278 as Fixed


Remember me on this computer does not work, cookie is not accepted in new session
















The last comment from Alexander Artemov seems to indicate the problem is resolved, so I'm marking it closed until we hear otherwise.





Change By:


Kohsuke Kawaguchi
(11/Mar/14 5:04 PM)




Status:


Reopened
Resolved





Resolution:


Fixed



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[JIRA] [security] (JENKINS-16278) Remember me on this computer does not work, cookie is not accepted in new session

2013-07-30 Thread artemov.alexa...@gmail.com (JIRA)














































Alexander Artemov
 commented on  JENKINS-16278


Remember me on this computer does not work, cookie is not accepted in new session















Now I have correct date 2 weeks in the future, but anyway I have to login 10 times a day because I often become logged out.



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.