smolnar82 opened a new pull request, #1439: URL: https://github.com/apache/knox/pull/1439
[KNOX-3502](https://issues.apache.org/jira/browse/KNOX-3502) - AliasService.isAlias recognizes the canonical ${ALIAS=} prefix ## What changes were proposed in this pull request? `AliasService#isAlias` only treated a value as an alias reference when it started with the Shiro-specific `S{ALIAS=` prefix. That prefix exists solely because `ShiroConfig` rewrites the standard `${ALIAS=...}` form to `S{ALIAS=...}` to keep Shiro's own `${...}` interpolation from consuming it. Everywhere else in Knox (`KnoxCLI`, `HadoopAuthFilter`, `Pac4jDispatcherFilter`, Hashicorp Vault auth, topology params) the canonical alias reference is `${ALIAS=...}`. As a result, non-Shiro consumers of `isAlias` — notably `KnoxLDAPServerManager` backend password resolution (LDAP proxy) — that received the standard `${ALIAS=...}` form got `isAlias == false`, so the alias was never resolved and the literal string was used as the credential (bind failure). - `AliasService#isAlias` now returns `true` for both `S{ALIAS=` and `${ALIAS=`; added a `STANDARD_ALIAS_PREFIX` constant alongside the existing `ALIAS_PREFIX`. `extractAlias` is unchanged, since both prefixes are 8 characters long. - Fixed the misleading `${ALIAS=}` example in `KnoxLDAPServerManager`'s javadoc. ## How was this patch tested? - New `AliasServiceTest` covering both prefixes for `isAlias`/`extractAlias`, plus literal/empty rejection (5 tests). - Confirmed existing consumers still pass: `KnoxLdapContextFactoryTest` (6) and `KnoxLDAPServerManagerTest` (29). ## Integration Tests Updated the existing LDAP proxy suite to exercise the canonical form end-to-end: - `.github/workflows/build/gateway-site.xml` — demo backend `systemPassword` now uses `${ALIAS=gateway_ldap_demoldap_system_password}`. - `.github/workflows/tests/test_knox_ldap_proxy_search.py` — docstring updated; the suite already asserts the backend bind succeeds (a resolution regression would use the literal alias string and fail every search), so it covers this change. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
