Failed login with encrypt URL parameters setting results in 404

Description

Failed login page inaccessible when encrypt URL parameters enabled:

  1. Login as admin

  2. Change Security Settings Encrypt web admin URL parameters (as described here)

  3. Logout, the home page has a random wicket-crypt= parameter to keep the sequence from being guessable

  4. Fail to login, and be redirected to 404 page:
    http://localhost:8080/geoserver/web/wicket/bookmarkable/org.geoserver.web.GeoServerLoginPage?error=true

See attached screen snap for comparison.

Environment

Java 11, Tomcat 8.5

Attachments

2

Activity

Jody Garnett 
November 29, 2022 at 3:52 PM
(edited)

Not sure what the solution is here; the interaction of bookmarkable pages and wicket encripting web admin URL parameters has several settings:

Details

Assignee

Reporter

Affects versions

Components

Priority

Created November 29, 2022 at 3:48 PM
Updated November 29, 2022 at 4:53 PM