smolnar82 opened a new pull request, #1436:
URL: https://github.com/apache/knox/pull/1436

   [KNOX-3497](https://issues.apache.org/jira/browse/KNOX-3497) - Resolve 
credential-store aliases for LDAP Proxy Backend passwords
   
   ## What changes were proposed in this pull request?
   
   The Knox LDAP Proxy Backend read its bind/system/truststore passwords as 
literal strings from `gateway-site.xml`, so a `S{ALIAS=...}` credential-store 
reference was sent verbatim over the wire as the password instead of being 
resolved - unlike every other Knox password property (e.g. the proxy's own 
`gateway_ldap_bind_password`).
   
   This PR closes that gap:
   
   1. `KnoxLDAPServerManager.createInterceptors()` now resolves 
credential-store alias references in the backend password properties 
(bindPassword, systemPassword, trustStorePassword) before the config map 
reaches the backend:
   2. Literal values pass through unchanged for backward compatibility.
   3. An unresolvable alias is left as-is and logged at ERROR, so the backend 
bind fails visibly rather than silently binding with a different credential.
   
   The fix lives in the server manager (which holds the AliasService and 
mutates the config map that flows to the backend), so the pluggable 
`LdapBackendFactory` / `LdapBackend` SPI is untouched.
   
   Docs updated in `knox-site/docs/service_ldap_server.md` with a new 
Credential store aliases for backend passwords subsection.
   
   ## How was this patch tested?
   
   - Unit - `KnoxLDAPServerManagerTest`: added cases for
     - `testLdapBackendPasswordAliasIsResolved`- `S{ALIAS=...}` → secret from 
the credential store,
     - `testLdapBackendLiteralPasswordIsUnchanged` - literal passthrough,
     - `testLdapBackendUnresolvablePasswordAliasIsLeftUnchanged` - alias left 
intact on failure.
   
   
   ## Integration Tests
   
   The default CI E2E env now supplies the demo backend's system password to 
the proxy via an alias, so `test_knox_ldap_proxy_search.py` exercises real 
alias resolution end-to-end:
   
   - build/gateway.sh seeds `gateway_ldap_demoldap_system_password` via 
`knoxcli.sh create-alias`.
   - build/gateway-site.xml sets:
   ```
   <property>
       <name>gateway.ldap.interceptor.demoldap.systemPassword</name>
       <value>S{ALIAS=gateway_ldap_demoldap_system_password}</value>
   </property>
   ```
   The proxy must resolve the alias to bind to the demo LDAP; a regression 
would send the literal `S{ALIAS=...}` string as the password and every proxied 
search would fail on a bind error - turning the whole suite red.
   
   Test results:
   ```
   tests-1  | ------------------------------------
   tests-1  | Your code has been rated at 10.00/10
   tests-1  | 
   tests-1  | Waiting for knox...
   tests-1  | ============================= test session starts 
==============================
   tests-1  | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0
   tests-1  | rootdir: /tests
   tests-1  | plugins: platformdirs-4.12.2
   tests-1  | collected 124 items
   tests-1  | 
   tests-1  | test_clientid_credentials.py .......                              
       [  5%]
   tests-1  | test_delegation.py .........                                      
       [ 12%]
   tests-1  | test_health.py .....                                              
       [ 16%]
   tests-1  | test_k8s_delegation.py .......                                    
       [ 22%]
   tests-1  | test_k8s_serviceaccount_validation.py ......                      
       [ 27%]
   tests-1  | test_knox_admin_path_traversal.py ...                             
       [ 29%]
   tests-1  | test_knox_auth_service_and_ldap.py ...                            
       [ 32%]
   tests-1  | test_knox_configs.py .                                            
       [ 33%]
   tests-1  | test_knox_ldap_cache.py ...                                       
       [ 35%]
   tests-1  | test_knox_ldap_injection.py .......                               
       [ 41%]
   tests-1  | test_knox_ldap_proxy_search.py .........                          
       [ 48%]
   tests-1  | test_knoxauth_preauth_and_paths.py ......                         
       [ 53%]
   tests-1  | test_knoxauth_token_forwarding.py ...........                     
       [ 62%]
   tests-1  | test_knoxidf.py .......                                           
       [ 67%]
   tests-1  | test_knoxsso_redirect.py .                                        
       [ 68%]
   tests-1  | test_knoxtoken_jwt.py ....................                        
       [ 84%]
   tests-1  | test_remote_auth.py ...                                           
       [ 87%]
   tests-1  | test_remoteauth_extauthz_additional_path.py ....                  
       [ 90%]
   tests-1  | test_token_exchange.py ............                               
       [100%]
   tests-1  | 
   tests-1  | =============================== warnings summary 
===============================
   ...
   tests-1  | ----------------- generated xml file: /tests/test-results.xml 
------------------
   tests-1  | ====================== 124 passed, 116 warnings in 31.50s 
======================
   tests-1 exited with code 0
   Aborting on container exit...
   Container compose-tests-1 Stopping 
   Container compose-tests-1 Stopped Config   w Enable Watch   d Detach
   ```
   
   ## UI changes
   
   N/A


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to