This is an automated email from the ASF dual-hosted git repository.
jungm pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git
The following commit(s) were added to refs/heads/main by this push:
new 827cb83c3e reject unenforceable auth settings in the tomcat hessian
registry
827cb83c3e is described below
commit 827cb83c3ee8cc44731c1e6af7162ada8c843da8
Author: Markus Jung <[email protected]>
AuthorDate: Sat Aug 29 15:26:50 2026 +0200
reject unenforceable auth settings in the tomcat hessian registry
---
.../server/hessian/TomcatHessianRegistry.java | 24 ++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git
a/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
b/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
index 2835b3b554..f9de1f75c9 100644
---
a/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
+++
b/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
@@ -88,6 +88,7 @@ public class TomcatHessianRegistry implements HessianRegistry
{
final String contextRoot = contextName(app);
Context context = Context.class.cast(host.findChild(contextRoot));
+ final boolean applicationContext = context != null &&
!fakeContexts.containsKey(contextRoot);
if (context == null) {
Pair<Context, Integer> fakeContext = fakeContexts.get(contextRoot);
if (fakeContext != null) {
@@ -109,6 +110,23 @@ public class TomcatHessianRegistry implements
HessianRegistry {
}
}
+ final String realAuthMethod = authMethod == null ? null :
authMethod.toUpperCase();
+ if (applicationContext && realAuthMethod != null &&
!"NONE".equals(realAuthMethod)) {
+ // an existing web context keeps its own login configuration, only
the BASIC valve can be added to it
+ if (!"BASIC".equals(realAuthMethod)) {
+ throw new IllegalArgumentException("authMethod '" + authMethod
+ "' cannot be applied to the existing context '"
+ + contextRoot + "', refusing to deploy hessian servlet '"
+ name + "'");
+ }
+ if (transportGuarantee != null &&
!"NONE".equalsIgnoreCase(transportGuarantee)) {
+ throw new IllegalArgumentException("transportGuarantee '" +
transportGuarantee + "' cannot be applied to the existing context '"
+ + contextRoot + "', refusing to deploy hessian servlet '"
+ name + "'");
+ }
+ if (!StandardContext.class.isInstance(context)) {
+ throw new IllegalArgumentException("authMethod '" + authMethod
+ "' cannot be applied to context '"
+ + contextRoot + "' (" + context.getClass().getName() + "),
refusing to deploy hessian servlet '" + name + "'");
+ }
+ }
+
final String servletMapping = generateServletPath(name);
Wrapper wrapper =
Wrapper.class.cast(context.findChild(servletMapping));
@@ -122,7 +140,7 @@ public class TomcatHessianRegistry implements
HessianRegistry {
context.addChild(wrapper);
context.addServletMappingDecoded(servletMapping, wrapper.getName());
- if ("BASIC".equals(authMethod) &&
StandardContext.class.isInstance(context)) {
+ if ("BASIC".equals(realAuthMethod) &&
StandardContext.class.isInstance(context)) {
final StandardContext standardContext =
StandardContext.class.cast(context);
boolean found = false;
@@ -173,7 +191,7 @@ public class TomcatHessianRegistry implements
HessianRegistry {
if (transportGuarantee != null) {
transportGuarantee = transportGuarantee.toUpperCase();
}
- if (authMethod != null & !"NONE".equals(authMethod)) {
+ if (authMethod != null && !"NONE".equals(authMethod)) {
if ("BASIC".equals(authMethod) || "DIGEST".equals(authMethod) ||
"CLIENT-CERT".equals(authMethod)) {
//Setup a login configuration
@@ -200,6 +218,8 @@ public class TomcatHessianRegistry implements
HessianRegistry {
context.addConstraint(sc);
context.addSecurityRole(role);
}
+ } else {
+ throw new IllegalArgumentException("Unsupported authMethod '"
+ rAuthMethod + "': supported values are BASIC, DIGEST and CLIENT-CERT");
}
//Set the proper authenticator