[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 1/5
- Thời gian dự kiến
- Dưới một giờ
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- java
- Lĩnh vực
- api, authentication
Hướng nghiên cứu
Start with hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/api/filter/AuthenticationFilter.java, especially the credential decoding and parsing at lines 192–195. Then find the auth API tests and check how they exercise Basic authentication. Done means regression coverage for non-ASCII and colon-containing passwords; a linked pull request (#3290) is already open, so coordinate before starting.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Bug Type (问题类型)
rest-api (结果不合预期)
Before submit
- I have confirmed and searched that there are no similar problems in the historical issue and documents
Environment (环境信息)
- Server Version: 1.7.0 (
hugegraph/server:latest, image0c58df2cae57;GET /versionsreports core 1.7.0). The code below is unchanged onmasteratd9abcd4 - Backend: RocksDB, 1 node,
usePD=false, authentication on (PASSWORDset) - OS: Docker on Linux
- Data Size: empty graph
Expected & Actual behavior (期望与实际表现)
Expected: any password the user API accepts can be used for HTTP Basic login.
Actual: the API accepts a non-ASCII password and a password containing :, but Basic login with either one fails. Measured 2026-10-07: set the admin password with PUT /graphspaces/DEFAULT/auth/users/-27:admin, then call GET /graphs with curl -u admin:<new password>.
| New admin password | PUT |
Basic login with the new password | Basic login with the old password |
|---|---|---|---|
newpass1234 (control) |
200 | 200 | 401 |
ädminpass1 |
200 | 401 Authentication failed |
401 |
new:pass1234 |
200 | 400 Invalid syntax for username and password |
not tried |
The non-ASCII row leaves the admin account with no working Basic login.
Cause, in AuthenticationFilter.java:192-195:
auth = new String(DatatypeConverter.parseBase64Binary(auth), Charsets.ASCII_CHARSET);
String[] values = auth.split(":");
if (values.length != 2) {
throw new BadRequestException("Invalid syntax for username and password");
- Decoding as US-ASCII turns every non-ASCII byte into U+FFFD, so the password checked is never the one that was stored.
split(":")cuts the password at every colon. RFC 7617 forbids a colon only in the user-id, so the credential should be split on the first colon.
Proposed fix: decode as UTF-8 (RFC 7617 section 2.1) and split at auth.indexOf(':'). A regression test in the auth API tests can cover both cases.
The Helm chart works around this by refusing such admin passwords in values.schema.json:824 and in its Server wrapper. The TODO at AuthenticationFilter.java:187 (from #3260) points here, and that guard can go once this is fixed.
Proposed for 1.8.0 (#3242): the fix is two lines, and today an admin password change through the API can lock the admin out of Basic login.
Reproduction
On a Server with authentication enabled and admin password adminpass123:
S=http://127.0.0.1:8080/graphspaces/DEFAULT/auth/users
curl -s -u admin:adminpass123 -X PUT -H 'Content-Type: application/json' \
--data-binary '{"user_password":"new:pass1234"}' "$S/-27:admin"
curl -s -u 'admin:new:pass1234' http://127.0.0.1:8080/graphs # 400
In the run above, the docker run entrypoint (HG_SERVER_BACKEND=rocksdb, HG_SERVER_USE_PD=false) kept waiting for a Store, so the Server was started inside the container with bin/init-store.sh and bin/start-hugegraph.sh.
Vertex/Edge example (问题点 / 边数据举例)
N/A
Schema [VertexLabel, EdgeLabel, IndexLabel] (元数据结构)
N/A
- Ngôn ngữ chính
- Java
- Star
- 3.2k
- Fork
- 640
- Merge trung bình
- 2 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 26
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của apache/hugegraph
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
apache/hugegraph#3231 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Prometheus metrics format bugCó thể làm lại được @cui2022 đã nhận 59 ngày trước và không có pull request nào đang mở. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
apache/hugegraph#3142 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[Feature] Let the Server take the initial admin password without a properties-file round tripĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của apache/hugegraph
Issue tương tự
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
waiting-for-triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
spring-cloud/spring-cloud-openfeign#1443 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 84/100
ADORSYS-GIS/keycloak-oid4vp-plugin#221 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Upgrade to Spring Pulsar 2.0.8Đang mởstatus: team-only type: dependency-upgrade
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
spring-projects/spring-boot#52099 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 67/100
tchiotludo/akhq#3307 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày