Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400

Abierto
#3,284 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@arshilkxwork ya está trabajando en esto.

Desde el 7/10/2026.

  • #3290 de @arshilkxwork — abierto

Evaluación

Dificultad
1/5
Tiempo estimado
Menos de una hora
Aptitud para principiantes
35/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Estancado
Stack tecnológico
java

Línea de trabajo

Start with hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/api/filter/AuthenticationFilter.java, especially the credential decoding and parsing at lines 192–195. Then find the auth API tests and check how they exercise Basic authentication. Done means regression coverage for non-ASCII and colon-containing passwords; a linked pull request (#3290) is already open, so coordinate before starting.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Bug Type (问题类型)

rest-api (结果不合预期)

Before submit
  • I have confirmed and searched that there are no similar problems in the historical issue and documents
Environment (环境信息)
  • Server Version: 1.7.0 (hugegraph/server:latest, image 0c58df2cae57; GET /versions reports core 1.7.0). The code below is unchanged on master at d9abcd4
  • Backend: RocksDB, 1 node, usePD=false, authentication on (PASSWORD set)
  • OS: Docker on Linux
  • Data Size: empty graph
Expected & Actual behavior (期望与实际表现)

Expected: any password the user API accepts can be used for HTTP Basic login.

Actual: the API accepts a non-ASCII password and a password containing :, but Basic login with either one fails. Measured 2026-10-07: set the admin password with PUT /graphspaces/DEFAULT/auth/users/-27:admin, then call GET /graphs with curl -u admin:<new password>.

New admin password PUT Basic login with the new password Basic login with the old password
newpass1234 (control) 200 200 401
ädminpass1 200 401 Authentication failed 401
new:pass1234 200 400 Invalid syntax for username and password not tried

The non-ASCII row leaves the admin account with no working Basic login.

Cause, in AuthenticationFilter.java:192-195:

auth = new String(DatatypeConverter.parseBase64Binary(auth), Charsets.ASCII_CHARSET);
String[] values = auth.split(":");
if (values.length != 2) {
    throw new BadRequestException("Invalid syntax for username and password");
  1. Decoding as US-ASCII turns every non-ASCII byte into U+FFFD, so the password checked is never the one that was stored.
  2. split(":") cuts the password at every colon. RFC 7617 forbids a colon only in the user-id, so the credential should be split on the first colon.

Proposed fix: decode as UTF-8 (RFC 7617 section 2.1) and split at auth.indexOf(':'). A regression test in the auth API tests can cover both cases.

The Helm chart works around this by refusing such admin passwords in values.schema.json:824 and in its Server wrapper. The TODO at AuthenticationFilter.java:187 (from #3260) points here, and that guard can go once this is fixed.

Proposed for 1.8.0 (#3242): the fix is two lines, and today an admin password change through the API can lock the admin out of Basic login.

Reproduction

On a Server with authentication enabled and admin password adminpass123:

S=http://127.0.0.1:8080/graphspaces/DEFAULT/auth/users
curl -s -u admin:adminpass123 -X PUT -H 'Content-Type: application/json' \
  --data-binary '{"user_password":"new:pass1234"}' "$S/-27:admin"
curl -s -u 'admin:new:pass1234' http://127.0.0.1:8080/graphs   # 400

In the run above, the docker run entrypoint (HG_SERVER_BACKEND=rocksdb, HG_SERVER_USE_PD=false) kept waiting for a Store, so the Server was started inside the container with bin/init-store.sh and bin/start-hugegraph.sh.

Vertex/Edge example (问题点 / 边数据举例)

N/A

Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)

N/A

Lenguaje dominante
Java
Estrellas
3.2k
Forks
641
Merge medio
2 d 9 h
PR fusionados (30 d)
26

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/hugegraph

Todos los issues de apache/hugegraph

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.