This is an automated email from the ASF dual-hosted git repository. dsmiley pushed a commit to branch branch_9x in repository https://gitbox.apache.org/repos/asf/solr.git
commit 90aac33c33cddc71e34bfbeded6f1070be87fc12 Author: Jan Høydahl <[email protected]> AuthorDate: Wed Aug 5 11:43:13 2026 +0200 PKIAuthenticationPlugin: handle non-base64 SolrAuthV2 signature (#4553) (cherry picked from commit d9e1468dda4d00f20e211e51a69c095bc3be5457) --- .../unreleased/PR#4553-pki-v2-header-base64-fix.yml | 7 +++++++ .../apache/solr/security/PKIAuthenticationPlugin.java | 8 +++++++- .../solr/security/TestPKIAuthenticationPlugin.java | 18 ++++++++++++++++++ 3 files changed, 32 insertions(+), 1 deletion(-) diff --git a/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml b/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml new file mode 100644 index 00000000000..9e503d01e70 --- /dev/null +++ b/changelog/unreleased/PR#4553-pki-v2-header-base64-fix.yml @@ -0,0 +1,7 @@ +title: PKIAuthenticationPlugin now rejects a SolrAuthV2 header with a malformed signature using a 401 response, instead of returning a 500 +type: fixed +authors: + - name: Jan Høydahl +links: + - name: PR#4553 + url: https://github.com/apache/solr/pull/4553 diff --git a/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java b/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java index ce1c09a8742..c41b00ec66d 100644 --- a/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java +++ b/solr/core/src/java/org/apache/solr/security/PKIAuthenticationPlugin.java @@ -266,7 +266,13 @@ public class PKIAuthenticationPlugin extends AuthenticationPlugin int sigStart = header.lastIndexOf(' '); String data = header.substring(0, sigStart); - byte[] sig = Base64.getDecoder().decode(header.substring(sigStart + 1)); + byte[] sig; + try { + sig = Base64.getDecoder().decode(header.substring(sigStart + 1)); + } catch (IllegalArgumentException e) { + log.warn("Could not parse signature in SolrAuthV2 header as base64"); + return null; + } PKIHeaderData rv = validateSignature(data, sig, key, false); if (rv == null) { log.warn("Failed to verify signature, trying after refreshing the key "); diff --git a/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java b/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java index 5c2cdd39c92..0f5a3f501e9 100644 --- a/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java +++ b/solr/core/src/test/org/apache/solr/security/TestPKIAuthenticationPlugin.java @@ -36,6 +36,7 @@ import javax.servlet.http.HttpServletResponse; import org.apache.http.Header; import org.apache.http.HttpHeaders; import org.apache.http.auth.BasicUserPrincipal; +import org.apache.http.message.BasicHeader; import org.apache.http.message.BasicHttpRequest; import org.apache.solr.SolrTestCaseJ4; import org.apache.solr.common.params.ModifiableSolrParams; @@ -204,6 +205,23 @@ public class TestPKIAuthenticationPlugin extends SolrTestCaseJ4 { "Should not have proceeded after authentication failure", wrappedRequestByFilter.get()); } + @Test + public void testMalformedV2HeaderSignatureRejected() throws Exception { + headerKey = PKIAuthenticationPlugin.HEADER_V2; + header.set(new BasicHeader(headerKey, nodeName + " someuser 1234567890 not_base64!!!")); + + HttpServletResponse response = mock(HttpServletResponse.class); + assertFalse( + "Should have rejected request with a non-base64 signature", + mock.authenticate(mockReq, response, filterChain)); + + verify(response).setHeader(HttpHeaders.WWW_AUTHENTICATE, PKIAuthenticationPlugin.HEADER_V2); + verify(response).sendError(ArgumentMatchers.eq(401), anyString()); + + assertNull( + "Should not have proceeded after authentication failure", wrappedRequestByFilter.get()); + } + public void testParseCipher() { for (String validUser : new String[] {"user1", "$", "some user", "some 123"}) { for (long validTimestamp :
