ppkarwasz opened a new issue, #4347:
URL: https://github.com/apache/logging-log4j2/issues/4347

   ## Description
   
   `BasicAuthorizationProvider` ignores `logging.auth.encoding` and does not 
fall back to UTF-8,
   contrary to its own comment ("If the user didn't specify a charset to use, 
we fallback to UTF-8").
   
   ```java
   Charset passwordCharset = props.getCharsetProperty(BASIC_AUTH_ENCODING);
   if (passwordCharset == null) {
       props.getCharsetProperty(SPRING_BASIC_AUTH_ENCODING, UTF_8);
   }
   ```
   
   - The one-argument `PropertiesUtil.getCharsetProperty(name)` falls back to 
`Charset.defaultCharset()`,
     so it never returns `null` and the branch is dead.
   - The branch also discards the value it computes.
   
   As a result, without `log4j2.configurationAuthorizationEncoding`, the 
credentials are encoded with the platform charset.
   This only makes a difference on JDKs before 18 with a non-UTF-8 default 
charset,
   where non-ASCII user names or passwords fail to authenticate.
   
   Expected behavior:
   
   ```java
   Charset passwordCharset = props.getCharsetProperty(BASIC_AUTH_ENCODING, 
null);
   if (passwordCharset == null) {
       passwordCharset = props.getCharsetProperty(SPRING_BASIC_AUTH_ENCODING, 
UTF_8);
   }
   ```
   
   ## Configuration
   
   **Version:** 2.26.1 (and `2.x` at `d631e82`)
   
   **Operating system:** any
   
   **JDK:** before 18, with a non-UTF-8 default charset
   
   ## Logs
   
   None.
   
   ## Reproduction
   
   Set `logging.auth.encoding=ISO-8859-1` (or nothing) and observe that the 
charset used is `Charset.defaultCharset()`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to