SEC-1410: Remember Me doesn't work with OpenID urls contatining "https://" #1646

spring-issuemaster opened this Issue Feb 15, 2010 · 1 comment


None yet

1 participant


Artem Troitskiy (Migrated from SEC-1410) said:

As of 3.0.1, AbstractRememberMeServices.decodeCookie() treats usernames with "http://" as a special case for compatibility with OpenID. But some OpenID providers use "https://..." in their identity urls, and cookies with such usernames are decoded incorrectly.


Luke Taylor said:

Thanks. I've changed it to check for usernames starting with "https" as well as "http".

@spring-issuemaster spring-issuemaster added this to the 3.0.2 milestone Feb 5, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment