smolnar82 opened a new pull request, #1439:
URL: https://github.com/apache/knox/pull/1439

   [KNOX-3502](https://issues.apache.org/jira/browse/KNOX-3502) - 
AliasService.isAlias recognizes the canonical ${ALIAS=} prefix
   
   ## What changes were proposed in this pull request?
   
   `AliasService#isAlias` only treated a value as an alias reference when it 
started with the Shiro-specific `S{ALIAS=` prefix. That prefix exists solely 
because `ShiroConfig` rewrites the standard `${ALIAS=...}` form to 
`S{ALIAS=...}` to keep Shiro's own `${...}` interpolation from consuming it. 
Everywhere else in Knox (`KnoxCLI`, `HadoopAuthFilter`, 
`Pac4jDispatcherFilter`, Hashicorp Vault auth, topology params) the canonical 
alias reference is `${ALIAS=...}`.
   
   As a result, non-Shiro consumers of `isAlias` — notably 
`KnoxLDAPServerManager` backend password resolution (LDAP proxy) — that 
received the standard `${ALIAS=...}` form got `isAlias == false`, so the alias 
was never resolved and the literal string was used as the credential (bind 
failure).
   
   - `AliasService#isAlias` now returns `true` for both `S{ALIAS=` and 
`${ALIAS=`; added a `STANDARD_ALIAS_PREFIX` constant alongside the existing 
`ALIAS_PREFIX`. `extractAlias` is unchanged, since both prefixes are 8 
characters long.
   - Fixed the misleading `${ALIAS=}` example in `KnoxLDAPServerManager`'s 
javadoc.
   
   ## How was this patch tested?
   
   - New `AliasServiceTest` covering both prefixes for 
`isAlias`/`extractAlias`, plus literal/empty rejection (5 tests).
   - Confirmed existing consumers still pass: `KnoxLdapContextFactoryTest` (6) 
and `KnoxLDAPServerManagerTest` (29).
   
   ## Integration Tests
   
   Updated the existing LDAP proxy suite to exercise the canonical form 
end-to-end:
   - `.github/workflows/build/gateway-site.xml` — demo backend `systemPassword` 
now uses `${ALIAS=gateway_ldap_demoldap_system_password}`.
   - `.github/workflows/tests/test_knox_ldap_proxy_search.py` — docstring 
updated; the suite already asserts the backend bind succeeds (a resolution 
regression would use the literal alias string and fail every search), so it 
covers this change.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to