The current API requires a InetAddress parameter to be passed in which in many cases is NULL. This renders simple forms of authentication such as HTTP basic authentication scheme incapable of distinguishing one protection realm from another.
- relates to
-
JDK-4281222 Authorization string exposed outside of authenticated realm
-
- Resolved
-