This is an automated email from the ASF dual-hosted git repository.

rzo1 pushed a commit to branch tomee-10.x
in repository https://gitbox.apache.org/repos/asf/tomee.git

commit e1643366248927ea38b546649f786650c31a1327
Author: Markus Jung <[email protected]>
AuthorDate: Fri Aug 21 21:00:47 2026 +0200

    unified failure handling
    
    (cherry picked from commit 5e422da7b6c50b718c2f2952236ac4f4ff26449e)
---
 .../openejb/core/security/jaas/PropertiesLoginModule.java    | 11 ++++++-----
 .../apache/openejb/core/security/jaas/SQLLoginModule.java    | 12 +++++++++---
 2 files changed, 15 insertions(+), 8 deletions(-)

diff --git 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/PropertiesLoginModule.java
 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/PropertiesLoginModule.java
index ce6e1aec27..c2291d7b23 100644
--- 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/PropertiesLoginModule.java
+++ 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/PropertiesLoginModule.java
@@ -32,6 +32,8 @@ import javax.security.auth.login.LoginException;
 import javax.security.auth.spi.LoginModule;
 import java.io.IOException;
 import java.net.URL;
+import java.nio.charset.StandardCharsets;
+import java.security.MessageDigest;
 import java.util.Enumeration;
 import java.util.LinkedHashSet;
 import java.util.Map;
@@ -112,11 +114,10 @@ public class PropertiesLoginModule implements LoginModule 
{
 
         final String password = users.getProperty(user);
 
-        if (password == null) {
-            throw new FailedLoginException("User does not exist");
-        }
-        if (!password.equals(new String(tmpPassword))) {
-            throw new FailedLoginException("Password does not match");
+        if (password == null || !MessageDigest.isEqual(
+                password.getBytes(StandardCharsets.UTF_8),
+                new String(tmpPassword).getBytes(StandardCharsets.UTF_8))) {
+            throw new FailedLoginException("Username or password does not 
match");
         }
 
         users.clear();
diff --git 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
index 4734090dc4..42878455e8 100644
--- 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
+++ 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
@@ -37,6 +37,7 @@ import javax.security.auth.login.LoginException;
 import javax.security.auth.spi.LoginModule;
 import javax.sql.DataSource;
 import java.io.IOException;
+import java.nio.charset.StandardCharsets;
 import java.security.MessageDigest;
 import java.security.NoSuchAlgorithmException;
 import java.security.Principal;
@@ -48,6 +49,7 @@ import java.sql.ResultSet;
 import java.sql.SQLException;
 import java.util.EnumMap;
 import java.util.HashSet;
+import java.util.Locale;
 import java.util.Map;
 import java.util.Properties;
 import java.util.Set;
@@ -363,7 +365,8 @@ public class SQLLoginModule implements LoginModule {
         // Both are non-null
         if (Strings.checkNullBlankString(digest)) {
             // No digest algorithm is used
-            return real.equals(provided);
+            return MessageDigest.isEqual(
+                real.getBytes(StandardCharsets.UTF_8), 
provided.getBytes(StandardCharsets.UTF_8));
         }
 
         try {
@@ -372,9 +375,12 @@ public class SQLLoginModule implements LoginModule {
             final byte[] data = md.digest(provided.getBytes());
 
             if (encoding == null || "hex".equalsIgnoreCase(encoding)) {
-                return real.equalsIgnoreCase(HexConverter.bytesToHex(data));
+                // lower-case both sides to keep the hex comparison 
case-insensitive
+                return MessageDigest.isEqual(
+                    
real.toLowerCase(Locale.ENGLISH).getBytes(StandardCharsets.UTF_8),
+                    
HexConverter.bytesToHex(data).toLowerCase(Locale.ENGLISH).getBytes(StandardCharsets.UTF_8));
             } else if ("base64".equalsIgnoreCase(encoding)) {
-                return real.equals(new String(Base64.encodeBase64(data)));
+                return 
MessageDigest.isEqual(real.getBytes(StandardCharsets.UTF_8), 
Base64.encodeBase64(data));
             }
         } catch (final NoSuchAlgorithmException e) {
             // Should not occur.  Availability of algorithm has been checked 
at initialization

Reply via email to