[ 
https://issues.apache.org/jira/browse/TOMEE-4648?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Markus Jung updated TOMEE-4648:
-------------------------------
    Description: 
When a custom {{HttpAuthenticationMechanism}} decorates or wraps the built-in 
BASIC mechanism, TomEE answers 401 even when the caller sends valid 
credentials. This shows up in the decorated variant and in the custom-handler 
variant ({{AppCustomAuthenticationMechanismHandler2IT}}). A plain BASIC test 
also fails the same {{testAuthenticated}} check, so the problem is not limited 
to the wrapped case.

Both OpenID Connect default modules fail token validation against the bundled 
OpenID provider. The TCK ships two default OpenID setups ({{OpenId2DefaultIT}}, 
{{OpenId3DefaultIT}}), and TomEE rejects the token in each.

Root cause has not been narrowed further than "TomEE own code" per the prior 
triage; the failures sit in the BASIC mechanism's credential check path and the 
OpenID token validation path, not in TCK test setup.

h2. Steps to reproduce / TCK reference
Run the Jakarta Security 4.0 TCK reactor against TomEE Plus (Java 21) through 
the {{security}} runner in {{runner-standalone}}. The following tests fail and 
are excluded in {{runner-standalone/exclusions/security.txt}} in the 
apache/tomee-tck harness repo:
* {{AppCustomAuthenticationMechanismHandler2IT}} (3 failing methods)
* {{AppMemBasicDecorateIT#testAuthenticated}}
* {{AppMemBasicIT#testAuthenticated}}
* {{OpenId2DefaultIT}}
* {{OpenId3DefaultIT}}

Remove the matching lines from {{security.txt}} once fixed, then re-run the 
{{security}} runner to confirm all five test classes pass.

  was:
h2. Description
When a custom {{HttpAuthenticationMechanism}} decorates or wraps the built-in 
BASIC mechanism, TomEE answers 401 even when the caller sends valid 
credentials. This shows up in the decorated variant and in the custom-handler 
variant ({{AppCustomAuthenticationMechanismHandler2IT}}). A plain BASIC test 
also fails the same {{testAuthenticated}} check, so the problem is not limited 
to the wrapped case.

Both OpenID Connect default modules fail token validation against the bundled 
OpenID provider. The TCK ships two default OpenID setups ({{OpenId2DefaultIT}}, 
{{OpenId3DefaultIT}}), and TomEE rejects the token in each.

Root cause has not been narrowed further than "TomEE own code" per the prior 
triage; the failures sit in the BASIC mechanism's credential check path and the 
OpenID token validation path, not in TCK test setup.

h2. Steps to reproduce / TCK reference
Run the Jakarta Security 4.0 TCK reactor against TomEE Plus (Java 21) through 
the {{security}} runner in {{runner-standalone}}. The following tests fail and 
are excluded in {{runner-standalone/exclusions/security.txt}} in the 
apache/tomee-tck harness repo:
* {{AppCustomAuthenticationMechanismHandler2IT}} (3 failing methods)
* {{AppMemBasicDecorateIT#testAuthenticated}}
* {{AppMemBasicIT#testAuthenticated}}
* {{OpenId2DefaultIT}}
* {{OpenId3DefaultIT}}

Remove the matching lines from {{security.txt}} once fixed, then re-run the 
{{security}} runner to confirm all five test classes pass.


> Jakarta Security: BASIC decorated/handler2 rejects valid credentials; OpenID 
> fails token check
> ----------------------------------------------------------------------------------------------
>
>                 Key: TOMEE-4648
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4648
>             Project: TomEE
>          Issue Type: Bug
>            Reporter: Markus Jung
>            Priority: Major
>
> When a custom {{HttpAuthenticationMechanism}} decorates or wraps the built-in 
> BASIC mechanism, TomEE answers 401 even when the caller sends valid 
> credentials. This shows up in the decorated variant and in the custom-handler 
> variant ({{AppCustomAuthenticationMechanismHandler2IT}}). A plain BASIC test 
> also fails the same {{testAuthenticated}} check, so the problem is not 
> limited to the wrapped case.
> Both OpenID Connect default modules fail token validation against the bundled 
> OpenID provider. The TCK ships two default OpenID setups 
> ({{OpenId2DefaultIT}}, {{OpenId3DefaultIT}}), and TomEE rejects the token in 
> each.
> Root cause has not been narrowed further than "TomEE own code" per the prior 
> triage; the failures sit in the BASIC mechanism's credential check path and 
> the OpenID token validation path, not in TCK test setup.
> h2. Steps to reproduce / TCK reference
> Run the Jakarta Security 4.0 TCK reactor against TomEE Plus (Java 21) through 
> the {{security}} runner in {{runner-standalone}}. The following tests fail 
> and are excluded in {{runner-standalone/exclusions/security.txt}} in the 
> apache/tomee-tck harness repo:
> * {{AppCustomAuthenticationMechanismHandler2IT}} (3 failing methods)
> * {{AppMemBasicDecorateIT#testAuthenticated}}
> * {{AppMemBasicIT#testAuthenticated}}
> * {{OpenId2DefaultIT}}
> * {{OpenId3DefaultIT}}
> Remove the matching lines from {{security.txt}} once fixed, then re-run the 
> {{security}} runner to confirm all five test classes pass.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to