This is an automated email from the ASF dual-hosted git repository. dsmiley pushed a commit to branch branch_10x in repository https://gitbox.apache.org/repos/asf/solr.git
commit 72921ecf447accdb312b8269ea3693cb32cb9de7 Author: heitzjm <[email protected]> AuthorDate: Thu Aug 6 21:24:10 2026 +0200 SOLR-18270 CertAuthPlugin : update the lookup attribute (without parametrization) (#4474) Co-authored-by: Eric Pugh <[email protected]> (cherry picked from commit 647de260b06f2903de833587af4389603e4bf42e) --- .../unreleased/SOLR-18270-easy-fix-without-parametrization.yml | 8 ++++++++ solr/core/src/java/org/apache/solr/security/CertAuthPlugin.java | 6 +++++- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/changelog/unreleased/SOLR-18270-easy-fix-without-parametrization.yml b/changelog/unreleased/SOLR-18270-easy-fix-without-parametrization.yml new file mode 100644 index 00000000000..6dd0337fb27 --- /dev/null +++ b/changelog/unreleased/SOLR-18270-easy-fix-without-parametrization.yml @@ -0,0 +1,8 @@ +title: CertAuthPlugin now uses correct Jetty attribute for certificate lookup for SSL authentication +type: fixed +authors: + - name: Jean-Marie HEITZ + nick: heitzjm +links: + - name: SOLR-18270 + url: https://issues.apache.org/jira/browse/SOLR-18270 diff --git a/solr/core/src/java/org/apache/solr/security/CertAuthPlugin.java b/solr/core/src/java/org/apache/solr/security/CertAuthPlugin.java index 091191fd409..84f4a5289b5 100644 --- a/solr/core/src/java/org/apache/solr/security/CertAuthPlugin.java +++ b/solr/core/src/java/org/apache/solr/security/CertAuthPlugin.java @@ -39,6 +39,9 @@ public class CertAuthPlugin extends AuthenticationPlugin { private static final String PARAM_CLASS = "class"; private static final String PARAM_PARAMS = "params"; + private static final String JAKARTA_REQUEST_ATTRIBUTE_NAME = + "jakarta.servlet.request.X509Certificate"; + private static final CertPrincipalResolver DEFAULT_PRINCIPAL_RESOLVER = certificate -> certificate.getSubjectX500Principal(); protected final CoreContainer coreContainer; @@ -102,7 +105,8 @@ public class CertAuthPlugin extends AuthenticationPlugin { HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws Exception { X509Certificate[] certs = - (X509Certificate[]) request.getAttribute("javax.servlet.request.X509Certificate"); + (X509Certificate[]) request.getAttribute(JAKARTA_REQUEST_ATTRIBUTE_NAME); + if (certs == null || certs.length == 0) { return sendError(response, "require certificate"); }
