This is an automated email from the ASF dual-hosted git repository.

rzo1 pushed a commit to branch tomee-10.x
in repository https://gitbox.apache.org/repos/asf/tomee.git

commit a32a7a3a6f38ba36b2249a4de2c46dd936752ebb
Author: Richard Zowalla <[email protected]>
AuthorDate: Wed Oct 7 17:34:18 2026 +0200

    reject null passwords in SQLLoginModule (#3059)
    
    A NULL stored password combined with no provided password must not
    authenticate.
    
    (cherry picked from commit fa933a7e63c9da10880a1f90a65c78bacb609f28)
---
 .../openejb/core/security/jaas/SQLLoginModule.java |  7 +++---
 .../openejb/core/security/SQLLoginModuleTest.java  | 26 ++++++++++++++++++++++
 2 files changed, 29 insertions(+), 4 deletions(-)

diff --git 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
index 42878455e8..aeaa1091b1 100644
--- 
a/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
+++ 
b/container/openejb-core/src/main/java/org/apache/openejb/core/security/jaas/SQLLoginModule.java
@@ -349,15 +349,14 @@ public class SQLLoginModule implements LoginModule {
      * This method checks if the provided password is correct. The original
      * password may have been digested.
      *
+     * A missing stored password (NULL column) or a missing provided password
+     * always fails: absence of a credential must never authenticate.
+     *
      * @param real     Original password in digested form if applicable
      * @param provided User provided password in clear text
      * @return true If the password is correct
      */
     private boolean checkPassword(final String real, final String provided) {
-        if (real == null && provided == null) {
-            return true;
-        }
-
         if (real == null || provided == null) {
             return false;
         }
diff --git 
a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
 
b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
index 07764082c8..26031e135d 100644
--- 
a/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
+++ 
b/container/openejb-core/src/test/java/org/apache/openejb/core/security/SQLLoginModuleTest.java
@@ -33,6 +33,7 @@ import java.sql.Connection;
 import java.sql.Driver;
 import java.sql.PreparedStatement;
 import java.sql.SQLException;
+import java.sql.Types;
 import java.util.Properties;
 
 import static org.junit.Assert.assertEquals;
@@ -70,6 +71,10 @@ public class SQLLoginModuleTest {
         st.setString(1, "daniel");
         st.setString(2, "password");
         st.execute();
+        // account without a stored password
+        st.setString(1, "nopassword");
+        st.setNull(2, Types.VARCHAR);
+        st.execute();
         st.close();
 
         // Add roles (groups)
@@ -138,4 +143,25 @@ public class SQLLoginModuleTest {
         context.login();
     }
 
+    @Test(expected = FailedLoginException.class)
+    public void testNullStoredAndNullProvidedPasswordLogin() throws 
LoginException {
+        final LoginContext context = new LoginContext("SQLLogin",
+            new UsernamePasswordCallbackHandler("nopassword", null));
+        context.login();
+    }
+
+    @Test(expected = FailedLoginException.class)
+    public void testNullStoredPasswordLogin() throws LoginException {
+        final LoginContext context = new LoginContext("SQLLogin",
+            new UsernamePasswordCallbackHandler("nopassword", "anything"));
+        context.login();
+    }
+
+    @Test(expected = FailedLoginException.class)
+    public void testNullProvidedPasswordLogin() throws LoginException {
+        final LoginContext context = new LoginContext("SQLLogin",
+            new UsernamePasswordCallbackHandler("jonathan", null));
+        context.login();
+    }
+
 }

Reply via email to