You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@knox.apache.org by "Philip Zampino (Jira)" <ji...@apache.org> on 2019/11/15 16:14:00 UTC

[jira] [Created] (KNOX-2127) ZooKeeperAliasService mishandles mixed-case alias keys properly

Philip Zampino created KNOX-2127:
------------------------------------

             Summary: ZooKeeperAliasService mishandles mixed-case alias keys properly
                 Key: KNOX-2127
                 URL: https://issues.apache.org/jira/browse/KNOX-2127
             Project: Apache Knox
          Issue Type: Bug
          Components: Server
    Affects Versions: 1.3.0
            Reporter: Philip Zampino
            Assignee: Philip Zampino
             Fix For: 1.4.0


The ZooKeeperAliasService mishandles mixed-case alias keys. Due to JDK-4891485, the getPasswordFromAliasForCluster(String, String, boolean) implementation assumes the alias key should be lower-cased. However, it enforces no such requirement when an alias is added. Hence, it's possible to add a mixed-case alias key, but impossible to retrieve the value thereof.

If this lower-case requirement is necessary, then the implementation must enforce it consistently. The add methods must also lower-case the alias keys.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)