This is an automated email from the ASF dual-hosted git repository. rzo1 pushed a commit to branch tomee-10.x in repository https://gitbox.apache.org/repos/asf/tomee.git
commit a32a7a3a6f38ba36b2249a4de2c46dd936752ebb Author: Richard Zowalla <[email protected]> AuthorDate: Wed Oct 7 17:34:18 2026 +0200 reject null passwords in SQLLoginModule (#3059) A NULL stored password combined with no provided password must not authenticate. (cherry picked from commit fa933a7e63c9da10880a1f90a65c78bacb609f28) --- .../openejb/core/security/jaas/SQLLoginModule.java | 7 +++--- .../openejb/core/security/SQLLoginModuleTest.java | 26 ++++++++++++++++++++++ 2 files changed, 29 insertions(+), 4 deletions(-) diff --git a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java index 42878455e8..aeaa1091b1 100644 --- a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java +++ b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java @@ -349,15 +349,14 @@ public class SQLLoginModule implements LoginModule { * This method checks if the provided password is correct. The original * password may have been digested. * + * A missing stored password (NULL column) or a missing provided password + * always fails: absence of a credential must never authenticate. + * * @param real Original password in digested form if applicable * @param provided User provided password in clear text * @return true If the password is correct */ private boolean checkPassword(final String real, final String provided) { - if (real == null && provided == null) { - return true; - } - if (real == null || provided == null) { return false; } diff --git a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java index 07764082c8..26031e135d 100644 --- a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java +++ b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java @@ -33,6 +33,7 @@ import java.sql.Connection; import java.sql.Driver; import java.sql.PreparedStatement; import java.sql.SQLException; +import java.sql.Types; import java.util.Properties; import static org.junit.Assert.assertEquals; @@ -70,6 +71,10 @@ public class SQLLoginModuleTest { st.setString(1, "daniel"); st.setString(2, "password"); st.execute(); + // account without a stored password + st.setString(1, "nopassword"); + st.setNull(2, Types.VARCHAR); + st.execute(); st.close(); // Add roles (groups) @@ -138,4 +143,25 @@ public class SQLLoginModuleTest { context.login(); } + @Test(expected = FailedLoginException.class) + public void testNullStoredAndNullProvidedPasswordLogin() throws LoginException { + final LoginContext context = new LoginContext("SQLLogin", + new UsernamePasswordCallbackHandler("nopassword", null)); + context.login(); + } + + @Test(expected = FailedLoginException.class) + public void testNullStoredPasswordLogin() throws LoginException { + final LoginContext context = new LoginContext("SQLLogin", + new UsernamePasswordCallbackHandler("nopassword", "anything")); + context.login(); + } + + @Test(expected = FailedLoginException.class) + public void testNullProvidedPasswordLogin() throws LoginException { + final LoginContext context = new LoginContext("SQLLogin", + new UsernamePasswordCallbackHandler("jonathan", null)); + context.login(); + } + }
