Tamás Hanicz created KNOX-3500:
----------------------------------
Summary: knoxcli creates a throwaway embedded H2 database, locking
it to the wrong credentials
Key: KNOX-3500
URL: https://issues.apache.org/jira/browse/KNOX-3500
Project: Apache Knox
Issue Type: Bug
Components: KnoxCLI
Affects Versions: 3.0.0
Reporter: Tamás Hanicz
Assignee: Tamás Hanicz
CLIGatewayServices.init() initializes TOKEN_STATE_SERVICE on every knoxcli
invocation. With gateway.service.tokenstate.impl=JDBCTokenStateService and an
external DB configured, the external DB connect fails and
TokenStateServiceFactory falls back to H2DBTokenStateService. That fallback
creates data/security/h2db/knoxdb.mv.db with user knox / password = master
secret.
Once the operator then sets gateway_database_user / gateway_database_password,
that leftover H2 file can no longer be opened (H2 validates credentials at
open, 28000). Any later fallback therefore fails too and silently degrades to
the in-memory DefaultTokenStateService. Same path for the three KnoxIDF Jdbc*
services.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)