SEZ9 commented on issue #12594: URL: https://github.com/apache/seatunnel/issues/12594#issuecomment-5945705887
Thanks for the clear report and for routing through ASF Security first. Agreed this is hardening rather than a vulnerability given the documented trust boundary. A small PR replacing the comparison with a constant-time check (e.g. MessageDigest.isEqual on the UTF-8 bytes of both username and password, computing both results before combining with a non-short-circuiting operator) would be welcome. When implementing, please keep the behavior identical when basic auth is disabled or when username/password are null, and add a unit test for BasicAuthFilter covering correct creds, wrong username, and wrong password so the change is covered. Minor note: the code location cited is in the dev branch (seatunnel-engine-server/.../rest/filter/BasicAuthFilter.java); could you confirm whether the same comparison exists in the Web UI auth path so both can be fixed in one PR? <!-- streview-comment:1466 --> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
