This is an automated email from the ASF dual-hosted git repository.

dsmiley pushed a commit to branch branch_9x
in repository https://gitbox.apache.org/repos/asf/solr.git

commit 90aac33c33cddc71e34bfbeded6f1070be87fc12
Author: Jan Høydahl <[email protected]>
AuthorDate: Wed Aug 5 11:43:13 2026 +0200

    PKIAuthenticationPlugin: handle non-base64 SolrAuthV2 signature (#4553)
    
    (cherry picked from commit d9e1468dda4d00f20e211e51a69c095bc3be5457)
---
 .../unreleased/PR#4553-pki-v2-header-base64-fix.yml    |  7 +++++++
 .../apache/solr/security/PKIAuthenticationPlugin.java  |  8 +++++++-
 .../solr/security/TestPKIAuthenticationPlugin.java     | 18 ++++++++++++++++++
 3 files changed, 32 insertions(+), 1 deletion(-)

diff --git a/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml 
b/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml
new file mode 100644
index 00000000000..9e503d01e70
--- /dev/null
+++ b/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml
@@ -0,0 +1,7 @@
+title: PKIAuthenticationPlugin now rejects a SolrAuthV2 header with a 
malformed signature using a 401 response, instead of returning a 500
+type: fixed
+authors:
+  - name: Jan Høydahl
+links:
+  - name: PR#4553
+    url: https://github.com/apache/solr/pull/4553
diff --git 
a/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java 
b/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java
index ce1c09a8742..c41b00ec66d 100644
--- a/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java
+++ b/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java
@@ -266,7 +266,13 @@ public class PKIAuthenticationPlugin extends 
AuthenticationPlugin
     int sigStart = header.lastIndexOf(' ');
 
     String data = header.substring(0, sigStart);
-    byte[] sig = Base64.getDecoder().decode(header.substring(sigStart + 1));
+    byte[] sig;
+    try {
+      sig = Base64.getDecoder().decode(header.substring(sigStart + 1));
+    } catch (IllegalArgumentException e) {
+      log.warn("Could not parse signature in SolrAuthV2 header as base64");
+      return null;
+    }
     PKIHeaderData rv = validateSignature(data, sig, key, false);
     if (rv == null) {
       log.warn("Failed to verify signature, trying after refreshing the key ");
diff --git 
a/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java 
b/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java
index 5c2cdd39c92..0f5a3f501e9 100644
--- 
a/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java
+++ 
b/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java
@@ -36,6 +36,7 @@ import javax.servlet.http.HttpServletResponse;
 import org.apache.http.Header;
 import org.apache.http.HttpHeaders;
 import org.apache.http.auth.BasicUserPrincipal;
+import org.apache.http.message.BasicHeader;
 import org.apache.http.message.BasicHttpRequest;
 import org.apache.solr.SolrTestCaseJ4;
 import org.apache.solr.common.params.ModifiableSolrParams;
@@ -204,6 +205,23 @@ public class TestPKIAuthenticationPlugin extends 
SolrTestCaseJ4 {
         "Should not have proceeded after authentication failure", 
wrappedRequestByFilter.get());
   }
 
+  @Test
+  public void testMalformedV2HeaderSignatureRejected() throws Exception {
+    headerKey = PKIAuthenticationPlugin.HEADER_V2;
+    header.set(new BasicHeader(headerKey, nodeName + " someuser 1234567890 
not_base64!!!"));
+
+    HttpServletResponse response = mock(HttpServletResponse.class);
+    assertFalse(
+        "Should have rejected request with a non-base64 signature",
+        mock.authenticate(mockReq, response, filterChain));
+
+    verify(response).setHeader(HttpHeaders.WWW_AUTHENTICATE, 
PKIAuthenticationPlugin.HEADER_V2);
+    verify(response).sendError(ArgumentMatchers.eq(401), anyString());
+
+    assertNull(
+        "Should not have proceeded after authentication failure", 
wrappedRequestByFilter.get());
+  }
+
   public void testParseCipher() {
     for (String validUser : new String[] {"user1", "$", "some user", "some 
123"}) {
       for (long validTimestamp :

Reply via email to