[
https://issues.apache.org/jira/browse/PROTON-1486?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16091444#comment-16091444
]
ASF subversion and git services commented on PROTON-1486:
---------------------------------------------------------
Commit 6789e558d92ed341d1655f59a8a4daddbf68dfb1 in qpid-proton-j's branch
refs/heads/master from [~k-wall]
[ https://git-wip-us.apache.org/repos/asf?p=qpid-proton-j.git;h=6789e55 ]
PROTON-1486: Expose SaslOutcome additional-data to users of the API
Based on original work by rgodfrey <[email protected]>
> Proton(-J) provides no mechanism to get or set the additional-data field on
> sasl-outcome
> ----------------------------------------------------------------------------------------
>
> Key: PROTON-1486
> URL: https://issues.apache.org/jira/browse/PROTON-1486
> Project: Qpid Proton
> Issue Type: Bug
> Components: proton-j
> Reporter: Rob Godfrey
> Assignee: Keith Wall
> Attachments: PROTON_1486.patch
>
>
> The Proton Engine API provides no mechanism for getting or setting the
> additional-data field on sasl-outcome.
> Some SASL mechanisms (e.g. SCRAM-SHA-\*) send additional data along with the
> outcome (in the case of SCRAM-SHA-\* the additional data is a proof that the
> server is also aware of the credentials and is not simply just accepting any
> credential data as part of some sort of attack).
> One approach for the API would be to expose the additional-data field using
> the send/recv/pending methods used for exchanging the challenge/response in
> the earlier phases of the sasl exchange.
--
This message was sent by Atlassian JIRA
(v6.4.14#64029)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]