ppkarwasz opened a new issue, #4347:
URL: https://github.com/apache/logging-log4j2/issues/4347
## Description
`BasicAuthorizationProvider` ignores `logging.auth.encoding` and does not
fall back to UTF-8,
contrary to its own comment ("If the user didn't specify a charset to use,
we fallback to UTF-8").
```java
Charset passwordCharset = props.getCharsetProperty(BASIC_AUTH_ENCODING);
if (passwordCharset == null) {
props.getCharsetProperty(SPRING_BASIC_AUTH_ENCODING, UTF_8);
}
```
- The one-argument `PropertiesUtil.getCharsetProperty(name)` falls back to
`Charset.defaultCharset()`,
so it never returns `null` and the branch is dead.
- The branch also discards the value it computes.
As a result, without `log4j2.configurationAuthorizationEncoding`, the
credentials are encoded with the platform charset.
This only makes a difference on JDKs before 18 with a non-UTF-8 default
charset,
where non-ASCII user names or passwords fail to authenticate.
Expected behavior:
```java
Charset passwordCharset = props.getCharsetProperty(BASIC_AUTH_ENCODING,
null);
if (passwordCharset == null) {
passwordCharset = props.getCharsetProperty(SPRING_BASIC_AUTH_ENCODING,
UTF_8);
}
```
## Configuration
**Version:** 2.26.1 (and `2.x` at `d631e82`)
**Operating system:** any
**JDK:** before 18, with a non-UTF-8 default charset
## Logs
None.
## Reproduction
Set `logging.auth.encoding=ISO-8859-1` (or nothing) and observe that the
charset used is `Charset.defaultCharset()`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]