You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@knox.apache.org by "Laszlo Nardai (JIRA)" <ji...@apache.org> on 2018/06/24 13:46:00 UTC

[jira] [Created] (KNOX-1364) Cookie path should contain the topology name aswell

Laszlo Nardai created KNOX-1364:
-----------------------------------

             Summary: Cookie path should contain the topology name aswell
                 Key: KNOX-1364
                 URL: https://issues.apache.org/jira/browse/KNOX-1364
             Project: Apache Knox
          Issue Type: Improvement
    Affects Versions: 0.14.0
            Reporter: Laszlo Nardai


When using knox in PROXY only mode, cookies are set with the following domain and path.

*[https://sandbox-hdf.hortonworks.com:5443/gateway/local-hdf/ambari#/login*]
I login to ambari on this URL, and I get a cookie with
domain: sandbox-hdf.hortonworks.com
path: gateway

If I try to access another ambari instance through the same knox in the following URL:
*[https://sandbox-hdf.hortonworks.com:5443/gateway/local-hdf/ambari#/login*]
domain: sandbox-hdf.hortonworks.com
path: gateway

So basically this cookie will overwrite the previous one and will trigger a logout from the first ambari ui.

Proposed solution:
include the topology name in the cookie path:
domain: sandbox-hdf.hortonworks.com
path: gateway/local-hdf



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)