[Feature] Let the Server take the initial admin password without a properties-file round trip
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- java
- Lĩnh vực
- authentication, backend
Hướng nghiên cứu
Start with ServerOptions.java:483 and HugeConfig.java:218 to trace how auth.admin_pa is defined and loaded; also read the referenced Docker entrypoint and Helm schema restrictions. Compare the proposed raw-password source with the compatibility option, then identify the tests covering configuration loading and initial admin setup. Done means the chosen behavior preserves the exact configured password and existing auth.admin_pa compatibility is addressed.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Feature Description (功能描述)
The initial admin password reaches the Server only through auth.admin_pa in rest-server.properties (ServerOptions.java:483). HugeConfig loads that file with Configurations.properties() (HugeConfig.java:218), so the value goes through the properties grammar. The password the Server stores can then differ from the one the operator set.
Measured 2026-10-07 with commons-configuration2 2.10.1 (the version in hugegraph-commons/pom.xml), reading a file through new Configurations().properties(file):
| Written to the file | Read back |
|---|---|
padded |
padded (trimmed) |
two\\back |
two\back (escape processed) |
x\ty |
x, a tab, y |
pässword (UTF-8 bytes) |
pässword (read as ISO-8859-1) |
The Docker entrypoint writes PASSWORD into this file (docker-entrypoint.sh:184), so PASSWORD=pässword creates an admin whose password is pässword.
Proposal, either of:
- Read the initial admin password from a source that is not parsed as properties, for example an environment variable or a file path read as raw UTF-8 (
auth.admin_pa_file), and keepauth.admin_pafor compatibility. - Keep the file and document the contract: printable ASCII, no leading or trailing space, backslashes escaped.
The Helm chart refuses padded, backslash and non-ASCII admin passwords in values.schema.json:824 and its Server wrapper until this changes. The TODO at ServerOptions.java:483 (from #3260) points here.
Related: non-ASCII passwords also fail at Basic login, tracked separately in #3284. #3133 / #3192 cover the entrypoint's own escaping.
Not proposed for 1.8.0: the chart guard covers it, and option 1 adds a config surface.
- Ngôn ngữ chính
- Java
- Star
- 3.2k
- Fork
- 640
- Merge trung bình
- 2 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 26
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của apache/hugegraph
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
apache/hugegraph#3231 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Prometheus metrics format bugCó thể làm lại được @cui2022 đã nhận 59 ngày trước và không có pull request nào đang mở. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
apache/hugegraph#3142 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400Có thể đã có người làm @arshilkxwork đã nhận hôm nay. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 35/100
apache/hugegraph#3284 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của apache/hugegraph
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
NationalSecurityAgency/ghidra#9748 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
spring-mcp-tools
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
explyt/spring-plugin#591 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
jenkinsci/build-monitor-plugin#1367 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
waiting-for-triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
spring-cloud/spring-cloud-openfeign#1443 ·
Maintainer thường phản hồi trong vòng 1 ngày