[Feature] Let the Server take the initial admin password without a properties-file round trip
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- java
- Domain
- authentication, backend
Research direction
Start with ServerOptions.java:483 and HugeConfig.java:218 to trace how auth.admin_pa is defined and loaded; also read the referenced Docker entrypoint and Helm schema restrictions. Compare the proposed raw-password source with the compatibility option, then identify the tests covering configuration loading and initial admin setup. Done means the chosen behavior preserves the exact configured password and existing auth.admin_pa compatibility is addressed.
Written by the indexing model from the issue text.
Description
Feature Description (功能描述)
The initial admin password reaches the Server only through auth.admin_pa in rest-server.properties (ServerOptions.java:483). HugeConfig loads that file with Configurations.properties() (HugeConfig.java:218), so the value goes through the properties grammar. The password the Server stores can then differ from the one the operator set.
Measured 2026-10-07 with commons-configuration2 2.10.1 (the version in hugegraph-commons/pom.xml), reading a file through new Configurations().properties(file):
| Written to the file | Read back |
|---|---|
padded |
padded (trimmed) |
two\\back |
two\back (escape processed) |
x\ty |
x, a tab, y |
pässword (UTF-8 bytes) |
pässword (read as ISO-8859-1) |
The Docker entrypoint writes PASSWORD into this file (docker-entrypoint.sh:184), so PASSWORD=pässword creates an admin whose password is pässword.
Proposal, either of:
- Read the initial admin password from a source that is not parsed as properties, for example an environment variable or a file path read as raw UTF-8 (
auth.admin_pa_file), and keepauth.admin_pafor compatibility. - Keep the file and document the contract: printable ASCII, no leading or trailing space, backslashes escaped.
The Helm chart refuses padded, backslash and non-ASCII admin passwords in values.schema.json:824 and its Server wrapper until this changes. The TODO at ServerOptions.java:483 (from #3260) points here.
Related: non-ASCII passwords also fail at Basic login, tracked separately in #3284. #3133 / #3192 cover the entrypoint's own escaping.
Not proposed for 1.8.0: the chart guard covers it, and option 1 adds a config surface.
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 640
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 26
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/hugegraph
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
apache/hugegraph#3231 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug] Prometheus metrics format bugMay be free again @cui2022 claimed this 59 days ago, and no pull request is open. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
apache/hugegraph#3142 · 7 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400Possibly taken @arshilkxwork claimed this 1 day ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 35/100
apache/hugegraph#3284 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 30/100
Maintainers usually reply within 1 day
All issues in apache/hugegraph
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
team:Lumberjack
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
OpenLiberty/open-liberty#35998 ·
Maintainers usually reply within 1 day
-
[BUG] SQS SendMessageBatch accepts more than 10 entries instead of TooManyEntriesInBatchRequestOpen
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
floci-io/floci#5319 · 1 comment ·
Maintainers usually reply within 1 day
-
Bug QWP
Difficulty 2/5 1-3 hours Newbie friendliness 79/100
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 64/100