Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature] Let the Server take the initial admin password without a properties-file round trip

Open
#3,285 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
java

Research direction

Start with ServerOptions.java:483 and HugeConfig.java:218 to trace how auth.admin_pa is defined and loaded; also read the referenced Docker entrypoint and Helm schema restrictions. Compare the proposed raw-password source with the compatibility option, then identify the tests covering configuration loading and initial admin setup. Done means the chosen behavior preserves the exact configured password and existing auth.admin_pa compatibility is addressed.

Written by the indexing model from the issue text.

Description

Feature Description (功能描述)

The initial admin password reaches the Server only through auth.admin_pa in rest-server.properties (ServerOptions.java:483). HugeConfig loads that file with Configurations.properties() (HugeConfig.java:218), so the value goes through the properties grammar. The password the Server stores can then differ from the one the operator set.

Measured 2026-10-07 with commons-configuration2 2.10.1 (the version in hugegraph-commons/pom.xml), reading a file through new Configurations().properties(file):

Written to the file Read back
padded padded (trimmed)
two\\back two\back (escape processed)
x\ty x, a tab, y
pässword (UTF-8 bytes) pässword (read as ISO-8859-1)

The Docker entrypoint writes PASSWORD into this file (docker-entrypoint.sh:184), so PASSWORD=pässword creates an admin whose password is pässword.

Proposal, either of:

  1. Read the initial admin password from a source that is not parsed as properties, for example an environment variable or a file path read as raw UTF-8 (auth.admin_pa_file), and keep auth.admin_pa for compatibility.
  2. Keep the file and document the contract: printable ASCII, no leading or trailing space, backslashes escaped.

The Helm chart refuses padded, backslash and non-ASCII admin passwords in values.schema.json:824 and its Server wrapper until this changes. The TODO at ServerOptions.java:483 (from #3260) points here.

Related: non-ASCII passwords also fail at Basic login, tracked separately in #3284. #3133 / #3192 cover the entrypoint's own escaping.

Not proposed for 1.8.0: the chart guard covers it, and option 1 adds a config surface.

Dominant language
Java
Stars
3.2k
Forks
640
Avg merge
2d 9h
Merged PRs (30d)
26

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/hugegraph

All issues in apache/hugegraph

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.