You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@pulsar.apache.org by xy...@apache.org on 2022/08/05 18:53:05 UTC
[pulsar] 03/08: [improve][authentication] Improve get the basic authentication config (#16526)
This is an automated email from the ASF dual-hosted git repository.
xyz pushed a commit to branch branch-2.8
in repository https://gitbox.apache.org/repos/asf/pulsar.git
commit acb4eba0ec4077f017ad5b9fb26d64ac224438a6
Author: Zixuan Liu <no...@gmail.com>
AuthorDate: Wed Aug 3 20:31:11 2022 +0800
[improve][authentication] Improve get the basic authentication config (#16526)
Signed-off-by: Zixuan Liu <no...@gmail.com>
(cherry picked from commit d32e1df89c4a88fe3f3a26e3ed9563d8c2a2ae21)
---
conf/broker.conf | 7 ++
conf/proxy.conf | 7 ++
conf/standalone.conf | 6 ++
.../AuthenticationProviderBasic.java | 49 ++++++++----
.../AuthenticationProviderBasicTest.java | 91 ++++++++++++++++++++++
.../test/resources/authentication/basic/.htpasswd | 2 +
6 files changed, 147 insertions(+), 15 deletions(-)
diff --git a/conf/broker.conf b/conf/broker.conf
index ea27c8022b3..f485e854bc1 100644
--- a/conf/broker.conf
+++ b/conf/broker.conf
@@ -689,6 +689,13 @@ athenzDomainNames=
# When this parameter is not empty, unauthenticated users perform as anonymousUserRole
anonymousUserRole=
+## Configure the datasource of basic authenticate, supports the file and Base64 format.
+# file:
+# basicAuthConf=/path/my/.htpasswd
+# use Base64 to encode the contents of .htpasswd:
+# basicAuthConf=YOUR-BASE64-DATA
+basicAuthConf=
+
### --- Token Authentication Provider --- ###
## Symmetric key
diff --git a/conf/proxy.conf b/conf/proxy.conf
index 3336a6166a5..bc55d1b0327 100644
--- a/conf/proxy.conf
+++ b/conf/proxy.conf
@@ -238,6 +238,13 @@ httpRequestsLimitEnabled=false
httpRequestsMaxPerSecond=100.0
+## Configure the datasource of basic authenticate, supports the file and Base64 format.
+# file:
+# basicAuthConf=/path/my/.htpasswd
+# use Base64 to encode the contents of .htpasswd:
+# basicAuthConf=YOUR-BASE64-DATA
+basicAuthConf=
+
### --- Token Authentication Provider --- ###
## Symmetric key
diff --git a/conf/standalone.conf b/conf/standalone.conf
index 8562f1aa8e0..1abf5aa7de9 100644
--- a/conf/standalone.conf
+++ b/conf/standalone.conf
@@ -462,6 +462,12 @@ athenzDomainNames=
# When this parameter is not empty, unauthenticated users perform as anonymousUserRole
anonymousUserRole=
+## Configure the datasource of basic authenticate, supports the file and Base64 format.
+# file:
+# basicAuthConf=/path/my/.htpasswd
+# use Base64 to encode the contents of .htpasswd:
+# basicAuthConf=YOUR-BASE64-DATA
+basicAuthConf=
### --- Token Authentication Provider --- ###
diff --git a/pulsar-broker-common/src/main/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasic.java b/pulsar-broker-common/src/main/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasic.java
index b564f8a90f7..40ff8635e03 100644
--- a/pulsar-broker-common/src/main/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasic.java
+++ b/pulsar-broker-common/src/main/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasic.java
@@ -19,24 +19,29 @@
package org.apache.pulsar.broker.authentication;
+import java.io.BufferedReader;
+import java.io.File;
+import java.io.FileReader;
+import java.io.IOException;
+import java.io.StringReader;
+import java.nio.charset.StandardCharsets;
+import java.util.Arrays;
+import java.util.Base64;
+import java.util.HashMap;
+import java.util.List;
+import java.util.Map;
+import javax.naming.AuthenticationException;
+import lombok.Cleanup;
import org.apache.commons.codec.digest.Crypt;
import org.apache.commons.codec.digest.Md5Crypt;
import org.apache.commons.lang3.StringUtils;
import org.apache.pulsar.broker.ServiceConfiguration;
-
-import lombok.Cleanup;
import org.apache.pulsar.broker.authentication.metrics.AuthenticationMetrics;
-import javax.naming.AuthenticationException;
-import java.io.BufferedReader;
-import java.io.File;
-import java.io.FileReader;
-import java.io.IOException;
-import java.util.*;
-
public class AuthenticationProviderBasic implements AuthenticationProvider {
private static final String HTTP_HEADER_NAME = "Authorization";
private static final String CONF_SYSTEM_PROPERTY_KEY = "pulsar.auth.basic.conf";
+ private static final String CONF_PULSAR_PROPERTY_KEY = "basicAuthConf";
private Map<String, String> users;
@Override
@@ -46,14 +51,28 @@ public class AuthenticationProviderBasic implements AuthenticationProvider {
@Override
public void initialize(ServiceConfiguration config) throws IOException {
- File confFile = new File(System.getProperty(CONF_SYSTEM_PROPERTY_KEY));
- if (!confFile.exists()) {
- throw new IOException("The password auth conf file does not exist");
- } else if (!confFile.isFile()) {
- throw new IOException("The path is not a file");
+ String data = config.getProperties().getProperty(CONF_PULSAR_PROPERTY_KEY);
+ if (StringUtils.isEmpty(data)) {
+ data = System.getProperty(CONF_SYSTEM_PROPERTY_KEY);
+ }
+ if (StringUtils.isEmpty(data)) {
+ throw new IOException("No basic authentication config provided");
+ }
+
+ @Cleanup BufferedReader reader = null;
+ if (org.apache.commons.codec.binary.Base64.isBase64(data)) {
+ reader = new BufferedReader(new StringReader(new String(Base64.getDecoder().decode(data),
+ StandardCharsets.UTF_8)));
+ } else {
+ File confFile = new File(data);
+ if (!confFile.exists()) {
+ throw new IOException("The password auth conf file does not exist");
+ } else if (!confFile.isFile()) {
+ throw new IOException("The path is not a file");
+ }
+ reader = new BufferedReader(new FileReader(confFile));
}
- @Cleanup BufferedReader reader = new BufferedReader(new FileReader(confFile));
users = new HashMap<>();
for (String line : reader.lines().toArray(s -> new String[s])) {
List<String> splitLine = Arrays.asList(line.split(":"));
diff --git a/pulsar-broker-common/src/test/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasicTest.java b/pulsar-broker-common/src/test/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasicTest.java
new file mode 100644
index 00000000000..812e99a0abf
--- /dev/null
+++ b/pulsar-broker-common/src/test/java/org/apache/pulsar/broker/authentication/AuthenticationProviderBasicTest.java
@@ -0,0 +1,91 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements. See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership. The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.pulsar.broker.authentication;
+
+import com.google.common.io.Resources;
+import java.io.IOException;
+import java.nio.charset.StandardCharsets;
+import java.nio.file.FileSystems;
+import java.nio.file.Files;
+import java.util.Base64;
+import java.util.Properties;
+import lombok.Cleanup;
+import org.apache.pulsar.broker.ServiceConfiguration;
+import org.apache.pulsar.common.api.AuthData;
+import org.testng.annotations.Test;
+
+import javax.naming.AuthenticationException;
+
+public class AuthenticationProviderBasicTest {
+ private final String basicAuthConf = Resources.getResource("authentication/basic/.htpasswd").getPath();
+ private final String basicAuthConfBase64 = Base64.getEncoder().encodeToString(Files.readAllBytes(
+ FileSystems.getDefault().getPath(basicAuthConf)));
+
+ public AuthenticationProviderBasicTest() throws IOException {
+ }
+
+ private void testAuthenticate(AuthenticationProviderBasic provider) throws AuthenticationException {
+ AuthData authData = AuthData.of("superUser2:superpassword".getBytes(StandardCharsets.UTF_8));
+ provider.newAuthState(authData, null, null);
+ }
+
+ @Test
+ public void testLoadFileFromPulsarProperties() throws Exception {
+ @Cleanup
+ AuthenticationProviderBasic provider = new AuthenticationProviderBasic();
+ ServiceConfiguration serviceConfiguration = new ServiceConfiguration();
+ Properties properties = new Properties();
+ properties.setProperty("basicAuthConf", basicAuthConf);
+ serviceConfiguration.setProperties(properties);
+ provider.initialize(serviceConfiguration);
+ testAuthenticate(provider);
+ }
+
+ @Test
+ public void testLoadBase64FromPulsarProperties() throws Exception {
+ @Cleanup
+ AuthenticationProviderBasic provider = new AuthenticationProviderBasic();
+ ServiceConfiguration serviceConfiguration = new ServiceConfiguration();
+ Properties properties = new Properties();
+ properties.setProperty("basicAuthConf", basicAuthConfBase64);
+ serviceConfiguration.setProperties(properties);
+ provider.initialize(serviceConfiguration);
+ testAuthenticate(provider);
+ }
+
+ @Test
+ public void testLoadFileFromSystemProperties() throws Exception {
+ @Cleanup
+ AuthenticationProviderBasic provider = new AuthenticationProviderBasic();
+ ServiceConfiguration serviceConfiguration = new ServiceConfiguration();
+ System.setProperty("pulsar.auth.basic.conf", basicAuthConf);
+ provider.initialize(serviceConfiguration);
+ testAuthenticate(provider);
+ }
+
+ @Test
+ public void testLoadBase64FromSystemProperties() throws Exception {
+ @Cleanup
+ AuthenticationProviderBasic provider = new AuthenticationProviderBasic();
+ ServiceConfiguration serviceConfiguration = new ServiceConfiguration();
+ System.setProperty("pulsar.auth.basic.conf", basicAuthConfBase64);
+ provider.initialize(serviceConfiguration);
+ testAuthenticate(provider);
+ }
+}
diff --git a/pulsar-broker-common/src/test/resources/authentication/basic/.htpasswd b/pulsar-broker-common/src/test/resources/authentication/basic/.htpasswd
new file mode 100644
index 00000000000..b1a099a5f0e
--- /dev/null
+++ b/pulsar-broker-common/src/test/resources/authentication/basic/.htpasswd
@@ -0,0 +1,2 @@
+superUser:mQQQIsyvvKRtU
+superUser2:$apr1$foobarmq$kuSZlLgOITksCkRgl57ie/