https://issues.apache.org/bugzilla/show_bug.cgi?id=56545

--- Comment #2 from Konstantin Kolinko <knst.koli...@gmail.com> ---
4. On the login page, enter a username (role1) and password (see
tomcat-users.xml). Press "Login" button.
5. Look into logs/localhost.2014-05-20.log.
There is an exception thrown by Session attribute event listener.

org.apache.catalina.session.StandardSession.setAttribute Session attribute
event listener threw exception
 java.security.AccessControlException: access denied
("java.lang.RuntimePermission" "accessClassInPackage.org.apache.catalina.util")
at
java.security.AccessControlContext.checkPermission(AccessControlContext.java:372)
at java.security.AccessController.checkPermission(AccessController.java:559)
at java.lang.SecurityManager.checkPermission(SecurityManager.java:549)
at java.lang.SecurityManager.checkPackageAccess(SecurityManager.java:1525)
at sun.misc.Launcher$AppClassLoader.loadClass(Launcher.java:305)
at java.lang.ClassLoader.loadClass(ClassLoader.java:412)
at java.lang.ClassLoader.loadClass(ClassLoader.java:358)
at org.apache.catalina.users.MemoryUser.toString(MemoryUser.java:312)
at javax.security.auth.Subject.toString(Subject.java:842)
at javax.security.auth.Subject.toString(Subject.java:825)
at java.lang.String.valueOf(String.java:2854)
at java.lang.StringBuilder.append(StringBuilder.java:128)
at listeners.SessionListener.attributeAdded(SessionListener.java:56)
at
org.apache.catalina.session.StandardSession.setAttribute(StandardSession.java:1546)

6. Press logout link ("you can log off by clicking here.")
7. The same exception is thrown for "attributeRemoved" event.

>From the stacktrace (at
org.apache.catalina.users.MemoryUser.toString(MemoryUser.java:312)) my guess is
that it ties to call static method RequestUtil.filter(username).

-- 
You are receiving this mail because:
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to