--------------------------------------- Http request/response log from FIREFOX. --------------------------------------- --- User request: http://192.168.252.5:8080/myOrbeonApp/ --- GET /myOrbeonApp/ HTTP/1.0 Host: 192.168.252.5:8080 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; it; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: it,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive Cookie: JSESSIONID=A8BB1B27EE7144F73CEB84E36A1DFB7B If-Modified-Since: Sun, 04 Apr 2010 23:50:12 GMT --- index.jsp (default page for site) response is "please authenticate yourself using NTLM" --- HTTP/1.1 401 Unauthorized Server: Apache-Coyote/1.1 WWW-Authenticate: NTLM Content-Type: text/html Date: Sun, 04 Apr 2010 23:51:29 GMT Connection: close Proxy-Support: Session-Based-Authentication --- FIREFOX request is NTLM Authorization request --- GET /myOrbeonApp/ HTTP/1.0 Host: 192.168.252.5:8080 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; it; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: it,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive Cookie: JSESSIONID=A8BB1B27EE7144F73CEB84E36A1DFB7B If-Modified-Since: Sun, 04 Apr 2010 23:50:12 GMT Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAGAbAdAAAADw== --- index.jsp response is "Gimmie a good token, based on my NTLM challenge message": --- HTTP/1.1 401 Unauthorized Server: Apache-Coyote/1.1 WWW-Authenticate: NTLM TlRMTVNTUAACAAAAAAAAACgAAAABggAAAAICAgAAAAAAAAAAAAAAAA== Content-Type: text/html Content-Length: 954 Date: Sun, 04 Apr 2010 23:51:29 GMT Connection: keep-alive Proxy-Support: Session-Based-Authentication Apache Tomcat/6.0.20 - Error report

HTTP Status 401 -


type Status report

message

description This request requires HTTP authentication ().


Apache Tomcat/6.0.20

--- FIREFOX request is "Ok, that's my token, please let-me-in" --- GET /myOrbeonApp/ HTTP/1.0 Host: 192.168.252.5:8080 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; it; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: it,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive Cookie: JSESSIONID=A8BB1B27EE7144F73CEB84E36A1DFB7B If-Modified-Since: Sun, 04 Apr 2010 23:50:12 GMT Authorization: NTLM TlRMTVNTUAADAAAAGAAYAHIAAAAYABgAigAAAAAAAABYAAAADAAMAFgAAAAOAA4AZAAAAAAAAACiAAAABYIAAgYBsB0AAAAPJGLdQ79Oo+oT/yOSxNx5GXAAYQBvAGwAbwBuAFAANABQAE8AVwBFAFIA9LW25mIhOJ7Gd/muC22Nc7bjQuNB1rei9LW25mIhOJ7Gd/muC22Nc7bjQuNB1rei --- index.jsp, when knows that client is "a good guy", redirects to "real" application page (http://192.168.252.5:8080/login) posting user name: --- HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Last-Modified: Sun, 04 Apr 2010 23:51:30 GMT Expires: Sun, 04 Apr 2010 23:51:30 GMT Cache-Control: public Pragma: Content-Type: text/html;charset=utf-8 Date: Sun, 04 Apr 2010 23:51:29 GMT Connection: close .... bla bla ... ------------------------------------------------------------------------ And now what happens after "connection close" due to keep-alive timeout: ------------------------------------------------------------------------ When I click on a listbox item (and don't release mouse): POST /myOrbeonApp/xforms-server HTTP/1.0 Host: 192.168.252.5:8080 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; it; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB6 (.NET CLR 3.5.30729) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: it,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive X-Requested-With: XMLHttpRequest Content-Type: application/xml; charset=UTF-8 Referer: http://192.168.252.5:8080/myOrbeonApp/ Content-Length: 467 Cookie: JSESSIONID=A8BB1B27EE7144F73CEB84E36A1DFB7B Pragma: no-cache ]> pers:60B31A4B-6176-B06D-4FB3-CCDEF3F4BF67 pers:D1CF75F7-2C09-599C-EF37-23F72D58BC5F HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Last-Modified: Sun, 04 Apr 2010 23:52:42 GMT Expires: Sun, 04 Apr 2010 23:52:42 GMT Cache-Control: public Pragma: Content-Type: application/xml;charset=utf-8 Date: Sun, 04 Apr 2010 23:52:42 GMT Connection: close pers:D1CF75F7-2C09-599C-EF37-23F72D58BC5F