SEZ9 commented on issue #12594:
URL: https://github.com/apache/seatunnel/issues/12594#issuecomment-5945705887

   Thanks for the clear report and for routing through ASF Security first. 
Agreed this is hardening rather than a vulnerability given the documented trust 
boundary. A small PR replacing the comparison with a constant-time check (e.g. 
MessageDigest.isEqual on the UTF-8 bytes of both username and password, 
computing both results before combining with a non-short-circuiting operator) 
would be welcome.
   
   When implementing, please keep the behavior identical when basic auth is 
disabled or when username/password are null, and add a unit test for 
BasicAuthFilter covering correct creds, wrong username, and wrong password so 
the change is covered.
   
   Minor note: the code location cited is in the dev branch 
(seatunnel-engine-server/.../rest/filter/BasicAuthFilter.java); could you 
confirm whether the same comparison exists in the Web UI auth path so both can 
be fixed in one PR?
   
   <!-- streview-comment:1466 -->


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to