[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 1/5
- Tiempo estimado
- Menos de una hora
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Estancado
- Stack tecnológico
- java
- Área
- api, authentication
Línea de trabajo
Start with hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/api/filter/AuthenticationFilter.java, especially the credential decoding and parsing at lines 192–195. Then find the auth API tests and check how they exercise Basic authentication. Done means regression coverage for non-ASCII and colon-containing passwords; a linked pull request (#3290) is already open, so coordinate before starting.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Bug Type (问题类型)
rest-api (结果不合预期)
Before submit
- I have confirmed and searched that there are no similar problems in the historical issue and documents
Environment (环境信息)
- Server Version: 1.7.0 (
hugegraph/server:latest, image0c58df2cae57;GET /versionsreports core 1.7.0). The code below is unchanged onmasteratd9abcd4 - Backend: RocksDB, 1 node,
usePD=false, authentication on (PASSWORDset) - OS: Docker on Linux
- Data Size: empty graph
Expected & Actual behavior (期望与实际表现)
Expected: any password the user API accepts can be used for HTTP Basic login.
Actual: the API accepts a non-ASCII password and a password containing :, but Basic login with either one fails. Measured 2026-10-07: set the admin password with PUT /graphspaces/DEFAULT/auth/users/-27:admin, then call GET /graphs with curl -u admin:<new password>.
| New admin password | PUT |
Basic login with the new password | Basic login with the old password |
|---|---|---|---|
newpass1234 (control) |
200 | 200 | 401 |
ädminpass1 |
200 | 401 Authentication failed |
401 |
new:pass1234 |
200 | 400 Invalid syntax for username and password |
not tried |
The non-ASCII row leaves the admin account with no working Basic login.
Cause, in AuthenticationFilter.java:192-195:
auth = new String(DatatypeConverter.parseBase64Binary(auth), Charsets.ASCII_CHARSET);
String[] values = auth.split(":");
if (values.length != 2) {
throw new BadRequestException("Invalid syntax for username and password");
- Decoding as US-ASCII turns every non-ASCII byte into U+FFFD, so the password checked is never the one that was stored.
split(":")cuts the password at every colon. RFC 7617 forbids a colon only in the user-id, so the credential should be split on the first colon.
Proposed fix: decode as UTF-8 (RFC 7617 section 2.1) and split at auth.indexOf(':'). A regression test in the auth API tests can cover both cases.
The Helm chart works around this by refusing such admin passwords in values.schema.json:824 and in its Server wrapper. The TODO at AuthenticationFilter.java:187 (from #3260) points here, and that guard can go once this is fixed.
Proposed for 1.8.0 (#3242): the fix is two lines, and today an admin password change through the API can lock the admin out of Basic login.
Reproduction
On a Server with authentication enabled and admin password adminpass123:
S=http://127.0.0.1:8080/graphspaces/DEFAULT/auth/users
curl -s -u admin:adminpass123 -X PUT -H 'Content-Type: application/json' \
--data-binary '{"user_password":"new:pass1234"}' "$S/-27:admin"
curl -s -u 'admin:new:pass1234' http://127.0.0.1:8080/graphs # 400
In the run above, the docker run entrypoint (HG_SERVER_BACKEND=rocksdb, HG_SERVER_USE_PD=false) kept waiting for a Store, so the Server was started inside the container with bin/init-store.sh and bin/start-hugegraph.sh.
Vertex/Edge example (问题点 / 边数据举例)
N/A
Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)
N/A
- Lenguaje dominante
- Java
- Estrellas
- 3.2k
- Forks
- 641
- Merge medio
- 2 d 9 h
- PR fusionados (30 d)
- 26
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de apache/hugegraph
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
apache/hugegraph#3231 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[Bug] Prometheus metrics format bugQuizá libre de nuevo @cui2022 la tomó hace 60 días y no hay ningún pull request abierto. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
apache/hugegraph#3142 · 7 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
Los mantenedores suelen responder en 1 día
-
[Feature] Let the Server take the initial admin password without a properties-file round tripAbierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
Los mantenedores suelen responder en 1 día
Todos los issues de apache/hugegraph
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Netcracker/qubership-integration-platform#1046 ·
Los mantenedores suelen responder en 2 días
-
`check_java_version()` fails when Java path contains spaces (Windows / Git Bash, `C:\Program Files`)Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
-
Fix Math.ceilDiv wrong result for exact positive divisionsPosiblemente ocupada @pamod-madubashana la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
scala-native/scala-native#5094 ·
Los mantenedores suelen responder en 1 día
-
NullPointerException in blocking command completion callback when the command succeeds (3.52.0)Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 2 días