rzo1 opened a new pull request, #3074: URL: https://github.com/apache/tomee/pull/3074
TomEEDefaultIdentityStore compared the stored tomcat-users.xml password with plain equals, so digested passwords never matched their cleartext while the digest itself authenticated. It now verifies through the CredentialHandler of the UserDatabaseRealm bound to the same resource, falls back to a constant-time plaintext comparison with a warning if no such realm exists, and returns INVALID_RESULT for a wrong password. Adds unit tests and a new arquillian-tomee-security-tests module covering digested, plaintext and realm-less setups. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
