Tamás Hanicz created KNOX-3500:
----------------------------------

             Summary: knoxcli creates a throwaway embedded H2 database, locking 
it to the wrong credentials
                 Key: KNOX-3500
                 URL: https://issues.apache.org/jira/browse/KNOX-3500
             Project: Apache Knox
          Issue Type: Bug
          Components: KnoxCLI
    Affects Versions: 3.0.0
            Reporter: Tamás Hanicz
            Assignee: Tamás Hanicz


CLIGatewayServices.init() initializes TOKEN_STATE_SERVICE on every knoxcli 
invocation. With gateway.service.tokenstate.impl=JDBCTokenStateService and an 
external DB configured, the external DB connect fails  and 
TokenStateServiceFactory falls back to H2DBTokenStateService. That fallback 
creates data/security/h2db/knoxdb.mv.db with user knox / password = master 
secret.

Once the operator then sets gateway_database_user / gateway_database_password, 
that leftover H2 file can no longer be opened (H2 validates credentials at 
open, 28000). Any later fallback therefore fails too and silently degrades to 
the in-memory DefaultTokenStateService. Same path for the three KnoxIDF Jdbc* 
services.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to