Sandor Molnar created KNOX-3502:
-----------------------------------
Summary: AliasService#isAlias should recognize both ${ALIAS= and
S{ALIAS= prefixes
Key: KNOX-3502
URL: https://issues.apache.org/jira/browse/KNOX-3502
Project: Apache Knox
Issue Type: Bug
Components: Server
Affects Versions: 3.0.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
{{AliasService#isAlias}} only treats a value as an alias reference when it
starts with the Shiro-specific {{S{ALIAS= }}prefix. That prefix exists only
because {{ShiroConfig}} rewrites the standard {{${ALIAS=...} }}form to
{{S\{ALIAS=...} }}to keep Shiro's own {{${...}}} interpolation from consuming
it. Everywhere else in Knox ({{{}KnoxCLI{}}}, {{{}HadoopAuthFilter{}}},
{{{}Pac4jDispatcherFilter{}}},{{{} Hashicorp Vault auth{}}}, topology params)
the canonical alias reference is {{{}${ALIAS=...}{}}}.
Consequently, non-Shiro consumers of {{isAlias}} (e.g.
{{KnoxLDAPServerManager}} backend password resolution) that receive the
standard {{${ALIAS=...}}} form get {{{}isAlias == false{}}}, so the alias is
never resolved and the literal string is used as the credential.
Update {{AliasService#isAlias}} to return true for both the {{S{ALIAS=}} and
{{$\{ALIAS=}} prefixes. {{extractAlias}} is unaffected, since both prefixes are
8 characters long.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)