Re: [cas-user] Race condition between Moodle and CAS Server 3.5.1+

2014-08-25 Thread Jérôme LELEU
Hi, Thanks for sharing. The TerminateWebSessionListener is a great mechanism to limit memory consumption, but it can sometimes cause trouble with some specific configurations. Invalidating directly the session don't work, so that's why the session is marked to expire after x seconds. I'm surprise

Re: [cas-user] Race condition between Moodle and CAS Server 3.5.1+

2014-08-23 Thread Vallee Romain
Thank you John, 2014-08-22 19:38 GMT+02:00 John Gasper : > Hey all, > > I wanted to share an issue I found and the fix so that perhaps someone in > the community can benefit. Moodle's CAS auth code (in version 2.6 and > likely others) request a gateway authN request immediately before > reques

[cas-user] Race condition between Moodle and CAS Server 3.5.1+

2014-08-22 Thread John Gasper
Hey all, I wanted to share an issue I found and the fix so that perhaps someone in the community can benefit. Moodle's CAS auth code (in version 2.6 and likely others) request a gateway authN request immediately before requesting the standard authN request. In theory this causes two Java web sessi