Skip to content

Conversation

@alaboso
Copy link
Contributor

@alaboso alaboso commented Oct 21, 2025

Description of what I changed

The AuthorizationFilter of webservices.REST module throws a 401 with message Session timed out . This is because in the AuthenticationSession of authentication module, the session is invalidated and a new one generated (regenerateHttpSession()). This PR introduces a check for a possibly new session

Issue I worked on

https://openmrs.atlassian.net/browse/O3-5144

Checklist: I completed these to help reviewers :)

  • My IDE is configured to follow the code style of this project.

    No? Unsure? -> configure your IDE, format the code and add the changes with git add . && git commit --amend

  • I have added tests to cover my changes. (If you refactored
    existing code that was well tested you do not have to add tests)

    No? -> write tests and add them to this commit git add . && git commit --amend

  • I ran mvn clean package right before creating this pull request and
    added all formatting changes to my commit.

    No? -> execute above command

  • All new and existing tests passed.

    No? -> figure out why and add the fix to your commit. It is your responsibility to make sure your code works.

  • My pull request is based on the latest changes of the master branch.

    No? Unsure? -> execute command git pull --rebase upstream master

… addition to checking validity of request session ID
@alaboso alaboso requested review from dkayiwa and ibacher October 21, 2025 11:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant