[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Stale
- Tech stack
- java
- Domain
- api, authentication
Research direction
Start with hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/api/filter/AuthenticationFilter.java, especially the credential decoding and parsing at lines 192–195. Then find the auth API tests and check how they exercise Basic authentication. Done means regression coverage for non-ASCII and colon-containing passwords; a linked pull request (#3290) is already open, so coordinate before starting.
Written by the indexing model from the issue text.
Description
Bug Type (问题类型)
rest-api (结果不合预期)
Before submit
- I have confirmed and searched that there are no similar problems in the historical issue and documents
Environment (环境信息)
- Server Version: 1.7.0 (
hugegraph/server:latest, image0c58df2cae57;GET /versionsreports core 1.7.0). The code below is unchanged onmasteratd9abcd4 - Backend: RocksDB, 1 node,
usePD=false, authentication on (PASSWORDset) - OS: Docker on Linux
- Data Size: empty graph
Expected & Actual behavior (期望与实际表现)
Expected: any password the user API accepts can be used for HTTP Basic login.
Actual: the API accepts a non-ASCII password and a password containing :, but Basic login with either one fails. Measured 2026-10-07: set the admin password with PUT /graphspaces/DEFAULT/auth/users/-27:admin, then call GET /graphs with curl -u admin:<new password>.
| New admin password | PUT |
Basic login with the new password | Basic login with the old password |
|---|---|---|---|
newpass1234 (control) |
200 | 200 | 401 |
ädminpass1 |
200 | 401 Authentication failed |
401 |
new:pass1234 |
200 | 400 Invalid syntax for username and password |
not tried |
The non-ASCII row leaves the admin account with no working Basic login.
Cause, in AuthenticationFilter.java:192-195:
auth = new String(DatatypeConverter.parseBase64Binary(auth), Charsets.ASCII_CHARSET);
String[] values = auth.split(":");
if (values.length != 2) {
throw new BadRequestException("Invalid syntax for username and password");
- Decoding as US-ASCII turns every non-ASCII byte into U+FFFD, so the password checked is never the one that was stored.
split(":")cuts the password at every colon. RFC 7617 forbids a colon only in the user-id, so the credential should be split on the first colon.
Proposed fix: decode as UTF-8 (RFC 7617 section 2.1) and split at auth.indexOf(':'). A regression test in the auth API tests can cover both cases.
The Helm chart works around this by refusing such admin passwords in values.schema.json:824 and in its Server wrapper. The TODO at AuthenticationFilter.java:187 (from #3260) points here, and that guard can go once this is fixed.
Proposed for 1.8.0 (#3242): the fix is two lines, and today an admin password change through the API can lock the admin out of Basic login.
Reproduction
On a Server with authentication enabled and admin password adminpass123:
S=http://127.0.0.1:8080/graphspaces/DEFAULT/auth/users
curl -s -u admin:adminpass123 -X PUT -H 'Content-Type: application/json' \
--data-binary '{"user_password":"new:pass1234"}' "$S/-27:admin"
curl -s -u 'admin:new:pass1234' http://127.0.0.1:8080/graphs # 400
In the run above, the docker run entrypoint (HG_SERVER_BACKEND=rocksdb, HG_SERVER_USE_PD=false) kept waiting for a Store, so the Server was started inside the container with bin/init-store.sh and bin/start-hugegraph.sh.
Vertex/Edge example (问题点 / 边数据举例)
N/A
Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)
N/A
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 641
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 26
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/hugegraph
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
apache/hugegraph#3231 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug] Prometheus metrics format bugMay be free again @cui2022 claimed this 60 days ago, and no pull request is open. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
apache/hugegraph#3142 · 7 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 30/100
Maintainers usually reply within 1 day
All issues in apache/hugegraph
Similar issues
-
Fix Math.ceilDiv wrong result for exact positive divisionsPossibly taken @pamod-madubashana claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
scala-native/scala-native#5094 ·
Maintainers usually reply within 1 day
-
[Bug] AI unread message badge counts a batch of new bubbles as one messagePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
apache/rocketmq-dashboard#5784 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
PCL-Community/PCL-CE#3658 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
apache/skywalking#14127 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day