Repository: hadoop
Updated Branches:
  refs/heads/branch-2.8 ab57c869e -> c7b79e8d9


HADOOP-13580. If user is unauthorized, log "unauthorized" instead of "Invalid 
signed text:". Contributed by Wei-Chiu Chuang.

(cherry picked from commit f6f3a447bf3b2900a2e9a0615ad9877f9310e062)
(cherry picked from commit 031d5f6c5bf7ab74d9c12fbefdb1c12c58024f03)


Project: http://git-wip-us.apache.org/repos/asf/hadoop/repo
Commit: http://git-wip-us.apache.org/repos/asf/hadoop/commit/c7b79e8d
Tree: http://git-wip-us.apache.org/repos/asf/hadoop/tree/c7b79e8d
Diff: http://git-wip-us.apache.org/repos/asf/hadoop/diff/c7b79e8d

Branch: refs/heads/branch-2.8
Commit: c7b79e8d91cc07012ec4029135a4bc2033e173d8
Parents: ab57c86
Author: Wei-Chiu Chuang <weic...@apache.org>
Authored: Fri Sep 16 14:53:09 2016 -0700
Committer: Wei-Chiu Chuang <weic...@apache.org>
Committed: Fri Sep 16 14:56:55 2016 -0700

----------------------------------------------------------------------
 .../security/authentication/server/AuthenticationFilter.java      | 3 +++
 1 file changed, 3 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/hadoop/blob/c7b79e8d/hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/server/AuthenticationFilter.java
----------------------------------------------------------------------
diff --git 
a/hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/server/AuthenticationFilter.java
 
b/hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/server/AuthenticationFilter.java
index 0a9b8b5..5262fdc 100644
--- 
a/hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/server/AuthenticationFilter.java
+++ 
b/hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/server/AuthenticationFilter.java
@@ -438,6 +438,9 @@ public class AuthenticationFilter implements Filter {
       for (Cookie cookie : cookies) {
         if (cookie.getName().equals(AuthenticatedURL.AUTH_COOKIE)) {
           tokenStr = cookie.getValue();
+          if (tokenStr.isEmpty()) {
+            throw new AuthenticationException("Unauthorized access");
+          }
           try {
             tokenStr = signer.verifyAndExtract(tokenStr);
           } catch (SignerException ex) {


---------------------------------------------------------------------
To unsubscribe, e-mail: common-commits-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-commits-h...@hadoop.apache.org

Reply via email to