rzo1 opened a new pull request, #3074:
URL: https://github.com/apache/tomee/pull/3074

   TomEEDefaultIdentityStore compared the stored tomcat-users.xml password with 
plain equals, so digested passwords never matched their cleartext while the 
digest itself authenticated. It now verifies through the CredentialHandler of 
the UserDatabaseRealm bound to the same resource, falls back to a constant-time 
plaintext comparison with a warning if no such realm exists, and returns 
INVALID_RESULT for a wrong password. Adds unit tests and a new 
arquillian-tomee-security-tests module covering digested, plaintext and 
realm-less setups.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to