Joel Johnson
2015-06-30 71b07b4daa6ec6a4b744dafec3b525a7c73d9d9f
src/main/java/com/gitblit/wicket/pages/SessionPage.java
@@ -96,7 +96,12 @@
               .getAttribute(Constants.AUTHENTICATION_TYPE);
         // issue 62: fix session fixation vulnerability
         session.replaceSession();
         // but only if authentication was done in the container.
         // It avoid double change of session, that some authentication method
         // don't like
         if (AuthenticationType.CONTAINER != authenticationType) {
            session.replaceSession();
         }
         session.setUser(user);
         request.getSession().setAttribute(Constants.AUTHENTICATION_TYPE, authenticationType);