Jose Luis López created HADOOP-20004:
----------------------------------------
Summary: Send a filter's refusal reason in the response body for
every HTTP method
Key: HADOOP-20004
URL: https://issues.apache.org/jira/browse/HADOOP-20004
Project: Hadoop Common
Issue Type: Sub-task
Components: common, hadoop-auth, kms, security
Reporter: Jose Luis López
{{AuthenticationFilter}}, {{RestCsrfPreventionFilter}} and
{{KMSAuthenticationFilter}} put their refusal message in the HTTP reason
phrase. The CSRF and KMS filters do it by casting to
{{org.eclipse.jetty.server.Response}} and calling {{setStatusWithReason}}.
Jetty writes an error-page body only for GET, POST and HEAD, on 9.4 and on 12.
So for a refused PUT or DELETE the phrase is the only place the message
appears, and Jetty 12 does not send one.
h3. Changes
* New request attribute
{{AuthenticationFilter.ERROR_MESSAGE_FOR_ANY_METHOD_ATTRIBUTE}} marks an error
whose message the caller must be able to read.
* {{HttpServer2}} installs an error handler that writes the error page for a
marked error whatever the method. It extends {{ErrorPageErrorHandler}}, so
web.xml {{<error-page>}} mappings keep working. Unmarked errors are handled
exactly as today.
* The three filters mark their refusals. In place of the Jetty cast they call
the Servlet API's {{setStatus(int, String)}}, so Jetty 9.4 and any other
container that sends a reason phrase still sends it. This also takes the Jetty
dependency out of filters that downstream projects run in their own containers.
h3. Compatibility
The status code and the reason phrase are unchanged. A refused PUT or DELETE
now also has an error-page body.
h3. Tests
{{TestRestCsrfPreventionFilter}} checks the phrase and the marker.
{{TestHttpServer}} checks that a marked PUT error has a body and an unmarked
one does not.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]