Jose Luis López created HADOOP-20004:
----------------------------------------

             Summary: Send a filter's refusal reason in the response body for 
every HTTP method
                 Key: HADOOP-20004
                 URL: https://issues.apache.org/jira/browse/HADOOP-20004
             Project: Hadoop Common
          Issue Type: Sub-task
          Components: common, hadoop-auth, kms, security
            Reporter: Jose Luis López


{{AuthenticationFilter}}, {{RestCsrfPreventionFilter}} and 
{{KMSAuthenticationFilter}} put their refusal message in the HTTP reason 
phrase. The CSRF and KMS filters do it by casting to 
{{org.eclipse.jetty.server.Response}} and calling {{setStatusWithReason}}. 
Jetty writes an error-page body only for GET, POST and HEAD, on 9.4 and on 12. 
So for a refused PUT or DELETE the phrase is the only place the message 
appears, and Jetty 12 does not send one.

h3. Changes
* New request attribute 
{{AuthenticationFilter.ERROR_MESSAGE_FOR_ANY_METHOD_ATTRIBUTE}} marks an error 
whose message the caller must be able to read.
* {{HttpServer2}} installs an error handler that writes the error page for a 
marked error whatever the method. It extends {{ErrorPageErrorHandler}}, so 
web.xml {{<error-page>}} mappings keep working. Unmarked errors are handled 
exactly as today.
* The three filters mark their refusals. In place of the Jetty cast they call 
the Servlet API's {{setStatus(int, String)}}, so Jetty 9.4 and any other 
container that sends a reason phrase still sends it. This also takes the Jetty 
dependency out of filters that downstream projects run in their own containers.

h3. Compatibility
The status code and the reason phrase are unchanged. A refused PUT or DELETE 
now also has an error-page body.

h3. Tests
{{TestRestCsrfPreventionFilter}} checks the phrase and the marker. 
{{TestHttpServer}} checks that a marked PUT error has a body and an unmarked 
one does not.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to