From bff58e38a386dd29097c4eb963b8728f7fac4b7f Mon Sep 17 00:00:00 2001 From: Michael Jumper Date: Thu, 31 Jan 2013 00:00:48 -0800 Subject: [PATCH] Should send "403 - Forbidden" if user not found. --- .../net/sourceforge/guacamole/net/basic/PermissionList.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/guacamole/src/main/java/net/sourceforge/guacamole/net/basic/PermissionList.java b/guacamole/src/main/java/net/sourceforge/guacamole/net/basic/PermissionList.java index fcb08ba11..d44fefcde 100644 --- a/guacamole/src/main/java/net/sourceforge/guacamole/net/basic/PermissionList.java +++ b/guacamole/src/main/java/net/sourceforge/guacamole/net/basic/PermissionList.java @@ -113,6 +113,8 @@ public class PermissionList extends AuthenticatingHttpServlet { // Get specific user User user = users.getUser(username); + if (user == null) + throw new GuacamoleSecurityException("No such user."); // Write XML content type response.setHeader("Content-Type", "text/xml");