Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400

Open
#3,284 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

@arshilkxwork is already working on this.

Since Oct 7, 2026.

  • #3290 by @arshilkxwork — open

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
35/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
java

Research direction

Start with hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/api/filter/AuthenticationFilter.java, especially the credential decoding and parsing at lines 192–195. Then find the auth API tests and check how they exercise Basic authentication. Done means regression coverage for non-ASCII and colon-containing passwords; a linked pull request (#3290) is already open, so coordinate before starting.

Written by the indexing model from the issue text.

Description

Bug Type (问题类型)

rest-api (结果不合预期)

Before submit
  • I have confirmed and searched that there are no similar problems in the historical issue and documents
Environment (环境信息)
  • Server Version: 1.7.0 (hugegraph/server:latest, image 0c58df2cae57; GET /versions reports core 1.7.0). The code below is unchanged on master at d9abcd4
  • Backend: RocksDB, 1 node, usePD=false, authentication on (PASSWORD set)
  • OS: Docker on Linux
  • Data Size: empty graph
Expected & Actual behavior (期望与实际表现)

Expected: any password the user API accepts can be used for HTTP Basic login.

Actual: the API accepts a non-ASCII password and a password containing :, but Basic login with either one fails. Measured 2026-10-07: set the admin password with PUT /graphspaces/DEFAULT/auth/users/-27:admin, then call GET /graphs with curl -u admin:<new password>.

New admin password PUT Basic login with the new password Basic login with the old password
newpass1234 (control) 200 200 401
ädminpass1 200 401 Authentication failed 401
new:pass1234 200 400 Invalid syntax for username and password not tried

The non-ASCII row leaves the admin account with no working Basic login.

Cause, in AuthenticationFilter.java:192-195:

auth = new String(DatatypeConverter.parseBase64Binary(auth), Charsets.ASCII_CHARSET);
String[] values = auth.split(":");
if (values.length != 2) {
    throw new BadRequestException("Invalid syntax for username and password");
  1. Decoding as US-ASCII turns every non-ASCII byte into U+FFFD, so the password checked is never the one that was stored.
  2. split(":") cuts the password at every colon. RFC 7617 forbids a colon only in the user-id, so the credential should be split on the first colon.

Proposed fix: decode as UTF-8 (RFC 7617 section 2.1) and split at auth.indexOf(':'). A regression test in the auth API tests can cover both cases.

The Helm chart works around this by refusing such admin passwords in values.schema.json:824 and in its Server wrapper. The TODO at AuthenticationFilter.java:187 (from #3260) points here, and that guard can go once this is fixed.

Proposed for 1.8.0 (#3242): the fix is two lines, and today an admin password change through the API can lock the admin out of Basic login.

Reproduction

On a Server with authentication enabled and admin password adminpass123:

S=http://127.0.0.1:8080/graphspaces/DEFAULT/auth/users
curl -s -u admin:adminpass123 -X PUT -H 'Content-Type: application/json' \
  --data-binary '{"user_password":"new:pass1234"}' "$S/-27:admin"
curl -s -u 'admin:new:pass1234' http://127.0.0.1:8080/graphs   # 400

In the run above, the docker run entrypoint (HG_SERVER_BACKEND=rocksdb, HG_SERVER_USE_PD=false) kept waiting for a Store, so the Server was started inside the container with bin/init-store.sh and bin/start-hugegraph.sh.

Vertex/Edge example (问题点 / 边数据举例)

N/A

Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)

N/A

Dominant language
Java
Stars
3.2k
Forks
641
Avg merge
2d 9h
Merged PRs (30d)
26

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/hugegraph

All issues in apache/hugegraph

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.