This is an automated email from the ASF dual-hosted git repository.

jungm pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git


The following commit(s) were added to refs/heads/main by this push:
     new 827cb83c3e reject unenforceable auth settings in the tomcat hessian 
registry
827cb83c3e is described below

commit 827cb83c3ee8cc44731c1e6af7162ada8c843da8
Author: Markus Jung <[email protected]>
AuthorDate: Sat Aug 29 15:26:50 2026 +0200

    reject unenforceable auth settings in the tomcat hessian registry
---
 .../server/hessian/TomcatHessianRegistry.java      | 24 ++++++++++++++++++++--
 1 file changed, 22 insertions(+), 2 deletions(-)

diff --git 
a/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
 
b/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
index 2835b3b554..f9de1f75c9 100644
--- 
a/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
+++ 
b/server/openejb-hessian/src/main/java/org/apache/openejb/server/hessian/TomcatHessianRegistry.java
@@ -88,6 +88,7 @@ public class TomcatHessianRegistry implements HessianRegistry 
{
 
         final String contextRoot = contextName(app);
         Context context = Context.class.cast(host.findChild(contextRoot));
+        final boolean applicationContext = context != null && 
!fakeContexts.containsKey(contextRoot);
         if (context == null) {
             Pair<Context, Integer> fakeContext = fakeContexts.get(contextRoot);
             if (fakeContext != null) {
@@ -109,6 +110,23 @@ public class TomcatHessianRegistry implements 
HessianRegistry {
             }
         }
 
+        final String realAuthMethod = authMethod == null ? null : 
authMethod.toUpperCase();
+        if (applicationContext && realAuthMethod != null && 
!"NONE".equals(realAuthMethod)) {
+            // an existing web context keeps its own login configuration, only 
the BASIC valve can be added to it
+            if (!"BASIC".equals(realAuthMethod)) {
+                throw new IllegalArgumentException("authMethod '" + authMethod 
+ "' cannot be applied to the existing context '"
+                    + contextRoot + "', refusing to deploy hessian servlet '" 
+ name + "'");
+            }
+            if (transportGuarantee != null && 
!"NONE".equalsIgnoreCase(transportGuarantee)) {
+                throw new IllegalArgumentException("transportGuarantee '" + 
transportGuarantee + "' cannot be applied to the existing context '"
+                    + contextRoot + "', refusing to deploy hessian servlet '" 
+ name + "'");
+            }
+            if (!StandardContext.class.isInstance(context)) {
+                throw new IllegalArgumentException("authMethod '" + authMethod 
+ "' cannot be applied to context '"
+                    + contextRoot + "' (" + context.getClass().getName() + "), 
refusing to deploy hessian servlet '" + name + "'");
+            }
+        }
+
         final String servletMapping = generateServletPath(name);
 
         Wrapper wrapper = 
Wrapper.class.cast(context.findChild(servletMapping));
@@ -122,7 +140,7 @@ public class TomcatHessianRegistry implements 
HessianRegistry {
         context.addChild(wrapper);
         context.addServletMappingDecoded(servletMapping, wrapper.getName());
 
-        if ("BASIC".equals(authMethod) && 
StandardContext.class.isInstance(context)) {
+        if ("BASIC".equals(realAuthMethod) && 
StandardContext.class.isInstance(context)) {
             final StandardContext standardContext = 
StandardContext.class.cast(context);
 
             boolean found = false;
@@ -173,7 +191,7 @@ public class TomcatHessianRegistry implements 
HessianRegistry {
         if (transportGuarantee != null) {
             transportGuarantee = transportGuarantee.toUpperCase();
         }
-        if (authMethod != null & !"NONE".equals(authMethod)) {
+        if (authMethod != null && !"NONE".equals(authMethod)) {
             if ("BASIC".equals(authMethod) || "DIGEST".equals(authMethod) || 
"CLIENT-CERT".equals(authMethod)) {
 
                 //Setup a login configuration
@@ -200,6 +218,8 @@ public class TomcatHessianRegistry implements 
HessianRegistry {
                     context.addConstraint(sc);
                     context.addSecurityRole(role);
                 }
+            } else {
+                throw new IllegalArgumentException("Unsupported authMethod '" 
+ rAuthMethod + "': supported values are BASIC, DIGEST and CLIENT-CERT");
             }
 
             //Set the proper authenticator

Reply via email to