This is an automated email from the ASF dual-hosted git repository.
rzo1 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git
The following commit(s) were added to refs/heads/main by this push:
new fa933a7e63 reject null passwords in SQLLoginModule (#3059)
fa933a7e63 is described below
commit fa933a7e63c9da10880a1f90a65c78bacb609f28
Author: Richard Zowalla <[email protected]>
AuthorDate: Wed Oct 7 17:34:18 2026 +0200
reject null passwords in SQLLoginModule (#3059)
A NULL stored password combined with no provided password must not
authenticate.
---
.../openejb/core/security/jaas/SQLLoginModule.java | 7 +++---
.../openejb/core/security/SQLLoginModuleTest.java | 26 ++++++++++++++++++++++
2 files changed, 29 insertions(+), 4 deletions(-)
diff --git
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
index 42878455e8..aeaa1091b1 100644
---
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
+++
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
@@ -349,15 +349,14 @@ public class SQLLoginModule implements LoginModule {
* This method checks if the provided password is correct. The original
* password may have been digested.
*
+ * A missing stored password (NULL column) or a missing provided password
+ * always fails: absence of a credential must never authenticate.
+ *
* @param real Original password in digested form if applicable
* @param provided User provided password in clear text
* @return true If the password is correct
*/
private boolean checkPassword(final String real, final String provided) {
- if (real == null && provided == null) {
- return true;
- }
-
if (real == null || provided == null) {
return false;
}
diff --git
a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
index 07764082c8..26031e135d 100644
---
a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
+++
b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
@@ -33,6 +33,7 @@ import java.sql.Connection;
import java.sql.Driver;
import java.sql.PreparedStatement;
import java.sql.SQLException;
+import java.sql.Types;
import java.util.Properties;
import static org.junit.Assert.assertEquals;
@@ -70,6 +71,10 @@ public class SQLLoginModuleTest {
st.setString(1, "daniel");
st.setString(2, "password");
st.execute();
+ // account without a stored password
+ st.setString(1, "nopassword");
+ st.setNull(2, Types.VARCHAR);
+ st.execute();
st.close();
// Add roles (groups)
@@ -138,4 +143,25 @@ public class SQLLoginModuleTest {
context.login();
}
+ @Test(expected = FailedLoginException.class)
+ public void testNullStoredAndNullProvidedPasswordLogin() throws
LoginException {
+ final LoginContext context = new LoginContext("SQLLogin",
+ new UsernamePasswordCallbackHandler("nopassword", null));
+ context.login();
+ }
+
+ @Test(expected = FailedLoginException.class)
+ public void testNullStoredPasswordLogin() throws LoginException {
+ final LoginContext context = new LoginContext("SQLLogin",
+ new UsernamePasswordCallbackHandler("nopassword", "anything"));
+ context.login();
+ }
+
+ @Test(expected = FailedLoginException.class)
+ public void testNullProvidedPasswordLogin() throws LoginException {
+ final LoginContext context = new LoginContext("SQLLogin",
+ new UsernamePasswordCallbackHandler("jonathan", null));
+ context.login();
+ }
+
}