[
https://issues.apache.org/jira/browse/KNOX-2670?focusedWorklogId=654642&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-654642
]
ASF GitHub Bot logged work on KNOX-2670:
----------------------------------------
Author: ASF GitHub Bot
Created on: 23/Sep/21 17:47
Start Date: 23/Sep/21 17:47
Worklog Time Spent: 10m
Work Description: smolnar82 commented on pull request #501:
URL: https://github.com/apache/knox/pull/501#issuecomment-926025997
> LGTM. The patch looks good to me, but the inheritance hierarchy is a bit
difficult to follow.
It's not that complicated IMO.
<img width="839" alt="Screenshot 2021-09-23 at 19 46 31"
src="https://user-images.githubusercontent.com/34065904/134557895-24439797-f9a2-4e65-9482-e82d15daec22.png">
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
Issue Time Tracking
-------------------
Worklog Id: (was: 654642)
Remaining Estimate: 0h
Time Spent: 10m
> AliasBasedTokenStateService does not throw UnknownTokenException at
> revocation time
> -----------------------------------------------------------------------------------
>
> Key: KNOX-2670
> URL: https://issues.apache.org/jira/browse/KNOX-2670
> Project: Apache Knox
> Issue Type: Bug
> Affects Versions: 1.6.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
> *Steps to reproduce*
> # Configure Knox to use the AliasBasedTokenStateService implemntation
> # Generated token with 1 min lifespan on the token generation UI
> # Revoke the token on the token management page
> # Use knox token api to revoke again the already revoked token
> The result is:
> {noformat}
> { "revoked": "true" }{noformat}
>
> *Root cause analysis*
> {{AliasBasedTokenStateService.removeToken(String tokenId)}} claims it throws
> {{UnknownTokenException}} but this is not true since it's missing the
> {{validateToken(String)}} call. In fact, we would not even need that method:
> if we remove it then {{DefaultTokenStateService.removeToken(String)}} will be
> invoked that has the required check.
> The good news is that the token is not maintained in the memory or in the
> underlying keystore because
> {{AliasBasedTokenStateService.removeToken(Set<String> tokenIds)}} silently
> tries to remove the token from the keystore and from memory but those
> implementations are tolerant to invoke a delete with a non-existing alias.
> That means, the token was removed perfectly for the first time.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)