Nisha_Shah
13 years agoOccasional Contributor
4.5.0: HTTP session maintained even when option unchecked
Hello,
I am trying soapUI-Pro 4.5.0.
For a negative login test case, I *unchecked* "Maintain HTTP Session" under test case options. However, it appears that the session is still being maintained, and cookies are being generated. I looked in wireshark and the behavior of the cookies is exactly the same whether "Maintain HTTP Session" is checked or not.
This is leading to a false positive in my login test case, and allowing the user to login when he should not.
If I go back to soapUI-Pro 4.0.1, the login test case fails as expected, when "Maintain HTTP Session" is unchecked.
Can you please confirm/fix the bug in soapUI-Pro 4.5.0?
Thanks
Nisha
I am trying soapUI-Pro 4.5.0.
For a negative login test case, I *unchecked* "Maintain HTTP Session" under test case options. However, it appears that the session is still being maintained, and cookies are being generated. I looked in wireshark and the behavior of the cookies is exactly the same whether "Maintain HTTP Session" is checked or not.
This is leading to a false positive in my login test case, and allowing the user to login when he should not.
If I go back to soapUI-Pro 4.0.1, the login test case fails as expected, when "Maintain HTTP Session" is unchecked.
Can you please confirm/fix the bug in soapUI-Pro 4.5.0?
Thanks
Nisha