smolnar82 opened a new pull request, #1436: URL: https://github.com/apache/knox/pull/1436
[KNOX-3497](https://issues.apache.org/jira/browse/KNOX-3497) - Resolve credential-store aliases for LDAP Proxy Backend passwords ## What changes were proposed in this pull request? The Knox LDAP Proxy Backend read its bind/system/truststore passwords as literal strings from `gateway-site.xml`, so a `S{ALIAS=...}` credential-store reference was sent verbatim over the wire as the password instead of being resolved - unlike every other Knox password property (e.g. the proxy's own `gateway_ldap_bind_password`). This PR closes that gap: 1. `KnoxLDAPServerManager.createInterceptors()` now resolves credential-store alias references in the backend password properties (bindPassword, systemPassword, trustStorePassword) before the config map reaches the backend: 2. Literal values pass through unchanged for backward compatibility. 3. An unresolvable alias is left as-is and logged at ERROR, so the backend bind fails visibly rather than silently binding with a different credential. The fix lives in the server manager (which holds the AliasService and mutates the config map that flows to the backend), so the pluggable `LdapBackendFactory` / `LdapBackend` SPI is untouched. Docs updated in `knox-site/docs/service_ldap_server.md` with a new Credential store aliases for backend passwords subsection. ## How was this patch tested? - Unit - `KnoxLDAPServerManagerTest`: added cases for - `testLdapBackendPasswordAliasIsResolved`- `S{ALIAS=...}` → secret from the credential store, - `testLdapBackendLiteralPasswordIsUnchanged` - literal passthrough, - `testLdapBackendUnresolvablePasswordAliasIsLeftUnchanged` - alias left intact on failure. ## Integration Tests The default CI E2E env now supplies the demo backend's system password to the proxy via an alias, so `test_knox_ldap_proxy_search.py` exercises real alias resolution end-to-end: - build/gateway.sh seeds `gateway_ldap_demoldap_system_password` via `knoxcli.sh create-alias`. - build/gateway-site.xml sets: ``` <property> <name>gateway.ldap.interceptor.demoldap.systemPassword</name> <value>S{ALIAS=gateway_ldap_demoldap_system_password}</value> </property> ``` The proxy must resolve the alias to bind to the demo LDAP; a regression would send the literal `S{ALIAS=...}` string as the password and every proxied search would fail on a bind error - turning the whole suite red. Test results: ``` tests-1 | ------------------------------------ tests-1 | Your code has been rated at 10.00/10 tests-1 | tests-1 | Waiting for knox... tests-1 | ============================= test session starts ============================== tests-1 | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0 tests-1 | rootdir: /tests tests-1 | plugins: platformdirs-4.12.2 tests-1 | collected 124 items tests-1 | tests-1 | test_clientid_credentials.py ....... [ 5%] tests-1 | test_delegation.py ......... [ 12%] tests-1 | test_health.py ..... [ 16%] tests-1 | test_k8s_delegation.py ....... [ 22%] tests-1 | test_k8s_serviceaccount_validation.py ...... [ 27%] tests-1 | test_knox_admin_path_traversal.py ... [ 29%] tests-1 | test_knox_auth_service_and_ldap.py ... [ 32%] tests-1 | test_knox_configs.py . [ 33%] tests-1 | test_knox_ldap_cache.py ... [ 35%] tests-1 | test_knox_ldap_injection.py ....... [ 41%] tests-1 | test_knox_ldap_proxy_search.py ......... [ 48%] tests-1 | test_knoxauth_preauth_and_paths.py ...... [ 53%] tests-1 | test_knoxauth_token_forwarding.py ........... [ 62%] tests-1 | test_knoxidf.py ....... [ 67%] tests-1 | test_knoxsso_redirect.py . [ 68%] tests-1 | test_knoxtoken_jwt.py .................... [ 84%] tests-1 | test_remote_auth.py ... [ 87%] tests-1 | test_remoteauth_extauthz_additional_path.py .... [ 90%] tests-1 | test_token_exchange.py ............ [100%] tests-1 | tests-1 | =============================== warnings summary =============================== ... tests-1 | ----------------- generated xml file: /tests/test-results.xml ------------------ tests-1 | ====================== 124 passed, 116 warnings in 31.50s ====================== tests-1 exited with code 0 Aborting on container exit... Container compose-tests-1 Stopping Container compose-tests-1 Stopped Config w Enable Watch d Detach ``` ## UI changes N/A -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
