I've got this weird problem with ajax redirect on a security constraint:
When an ajax call is made (by clicking on a sortable p:dataTable
column or when a p:poll
triggers) on a role-secured page after my session timed out, a <partial-response><redirect-url=...
XML from OmniFaces is shown on the screen.
When I remove OmniFaces, the ajax calls seem to fail silently and I don't get the XML shown.
Security is configured as following in web.xml:
<security-constraint>
<web-resource-collection>
<web-resource-name>Pages</web-resource-name>
<url-pattern>/*</url-pattern>
</web-resource-collection>
<auth-constraint>
<role-name>user</role-name>
</auth-constraint>
</security-constraint>
<security-constraint>
<web-resource-collection>
<web-resource-name>Resources</web-resource-name>
<url-pattern>/javax.faces.resource/*</url-pattern>
</web-resource-collection>
</security-constraint>
<login-config>
<auth-method>FORM</auth-method>
<realm-name>myRealm</realm-name>
<form-login-config>
<form-login-page>/login.xhtml</form-login-page>
<form-error-page>/login.xhtml?error=true</form-error-page>
</form-login-config>
</login-config>
<security-role>
<role-name>user</role-name>
</security-role>