This is an automated email from the ASF dual-hosted git repository.

jungm pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git


The following commit(s) were added to refs/heads/main by this push:
     new 1da8c89329 refuse deployment of unsupported jaxws/jaxrs configurations
1da8c89329 is described below

commit 1da8c89329078977b7883baf5e13a72f6744bbce
Author: Markus Jung <[email protected]>
AuthorDate: Sat Aug 29 21:26:48 2026 +0200

    refuse deployment of unsupported jaxws/jaxrs configurations
---
 .../apache/openejb/server/rest/RsRegistryImpl.java |  5 ++-
 .../server/rest/RsRegistryImplAuthTest.java        | 43 ++++++++++++++++++++++
 .../server/webservices/OpenEJBHttpWsRegistry.java  |  3 ++
 .../webservices/OpenEJBHttpWsRegistryAuthTest.java | 43 ++++++++++++++++++++++
 4 files changed, 93 insertions(+), 1 deletion(-)

diff --git 
a/server/openejb-rest/src/main/java/org/apache/openejb/server/rest/RsRegistryImpl.java
 
b/server/openejb-rest/src/main/java/org/apache/openejb/server/rest/RsRegistryImpl.java
index 3a93fe16f7..dd7d77c61c 100644
--- 
a/server/openejb-rest/src/main/java/org/apache/openejb/server/rest/RsRegistryImpl.java
+++ 
b/server/openejb-rest/src/main/java/org/apache/openejb/server/rest/RsRegistryImpl.java
@@ -36,8 +36,11 @@ public class RsRegistryImpl extends OpenEJBHttpRegistry 
implements RsRegistry {
 
         if ("BASIC".equals(auth)) { // important to wrap with basic wrapper 
before classloader wrapping
             addWrappedHttpListener(new BasicAuthHttpListenerWrapper(listener, 
realm), classLoader, path);
-        } else {
+        } else if (auth == null || "NONE".equals(auth)) {
             addWrappedHttpListener(listener, classLoader, path);
+        } else {
+            throw new IllegalArgumentException("The embedded HTTP transport 
only supports BASIC or NONE authentication, "
+                    + "refusing to publish '" + path + "' with auth method '" 
+ auth + "'");
         }
 
         addresses.put(address, path);
diff --git 
a/server/openejb-rest/src/test/java/org/apache/openejb/server/rest/RsRegistryImplAuthTest.java
 
b/server/openejb-rest/src/test/java/org/apache/openejb/server/rest/RsRegistryImplAuthTest.java
new file mode 100644
index 0000000000..f400b35a99
--- /dev/null
+++ 
b/server/openejb-rest/src/test/java/org/apache/openejb/server/rest/RsRegistryImplAuthTest.java
@@ -0,0 +1,43 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ *     contributor license agreements.  See the NOTICE file distributed with
+ *     this work for additional information regarding copyright ownership.
+ *     The ASF licenses this file to You under the Apache License, Version 2.0
+ *     (the "License"); you may not use this file except in compliance with
+ *     the License.  You may obtain a copy of the License at
+ *
+ *        http://www.apache.org/licenses/LICENSE-2.0
+ *
+ *     Unless required by applicable law or agreed to in writing, software
+ *     distributed under the License is distributed on an "AS IS" BASIS,
+ *     WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ *     See the License for the specific language governing permissions and
+ *     limitations under the License.
+ */
+package org.apache.openejb.server.rest;
+
+import org.apache.openejb.server.httpd.HttpListener;
+import org.junit.Test;
+
+import static org.junit.Assert.assertTrue;
+import static org.junit.Assert.fail;
+
+public class RsRegistryImplAuthTest {
+    private static final HttpListener NOOP_LISTENER = (request, response) -> {
+        // no-op
+    };
+
+    @Test
+    public void onlyBasicOrNoneAreAccepted() {
+        for (final String auth : new String[]{"DIGEST", "CLIENT-CERT"}) {
+            try {
+                new RsRegistryImpl().createRsHttpListener(
+                        "app", "web", NOOP_LISTENER, 
Thread.currentThread().getContextClassLoader(),
+                        "/rest/.*", "localhost", auth, "realm");
+                fail("auth method " + auth + " must be rejected");
+            } catch (final IllegalArgumentException expected) {
+                assertTrue(expected.getMessage().contains(auth));
+            }
+        }
+    }
+}
diff --git 
a/server/openejb-webservices/src/main/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistry.java
 
b/server/openejb-webservices/src/main/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistry.java
index 39e2bf54d3..69ed5729df 100644
--- 
a/server/openejb-webservices/src/main/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistry.java
+++ 
b/server/openejb-webservices/src/main/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistry.java
@@ -60,6 +60,9 @@ public class OpenEJBHttpWsRegistry extends 
OpenEJBHttpRegistry implements WsRegi
 
         if ("BASIC".equals(authMethod)) {
             httpListener = new BasicAuthHttpListenerWrapper(httpListener, 
realmName, true);
+        } else if (authMethod != null && !"NONE".equals(authMethod)) {
+            throw new IllegalArgumentException("The embedded HTTP transport 
only supports BASIC or NONE authentication, "
+                    + "refusing to publish '" + path + "' with auth method '" 
+ authMethod + "'");
         }
 
         final StringBuilder deployedPath = new StringBuilder("");
diff --git 
a/server/openejb-webservices/src/test/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistryAuthTest.java
 
b/server/openejb-webservices/src/test/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistryAuthTest.java
new file mode 100644
index 0000000000..3f44b5b737
--- /dev/null
+++ 
b/server/openejb-webservices/src/test/java/org/apache/openejb/server/webservices/OpenEJBHttpWsRegistryAuthTest.java
@@ -0,0 +1,43 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ *     contributor license agreements.  See the NOTICE file distributed with
+ *     this work for additional information regarding copyright ownership.
+ *     The ASF licenses this file to You under the Apache License, Version 2.0
+ *     (the "License"); you may not use this file except in compliance with
+ *     the License.  You may obtain a copy of the License at
+ *
+ *        http://www.apache.org/licenses/LICENSE-2.0
+ *
+ *     Unless required by applicable law or agreed to in writing, software
+ *     distributed under the License is distributed on an "AS IS" BASIS,
+ *     WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ *     See the License for the specific language governing permissions and
+ *     limitations under the License.
+ */
+package org.apache.openejb.server.webservices;
+
+import org.apache.openejb.server.httpd.HttpListener;
+import org.junit.Test;
+
+import static org.junit.Assert.assertTrue;
+import static org.junit.Assert.fail;
+
+public class OpenEJBHttpWsRegistryAuthTest {
+    private static final HttpListener NOOP_LISTENER = (request, response) -> {
+        // no-op
+    };
+
+    @Test
+    public void onlyBasicOrNoneAreAccepted() throws Exception {
+        for (final String authMethod : new String[]{"DIGEST", "CLIENT-CERT"}) {
+            try {
+                new OpenEJBHttpWsRegistry().addWsContainer(
+                        NOOP_LISTENER, 
Thread.currentThread().getContextClassLoader(),
+                        "ctx", "localhost", "/service", "realm", "NONE", 
authMethod, "moduleId");
+                fail("auth method " + authMethod + " must be rejected");
+            } catch (final IllegalArgumentException expected) {
+                assertTrue(expected.getMessage().contains(authMethod));
+            }
+        }
+    }
+}

Reply via email to