This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch 10.1.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/10.1.x by this push:
     new 79b18a1100 Follow-up to 87ed9d47
79b18a1100 is described below

commit 79b18a1100dd93b4739d89e6dec2b019b7efb7da
Author: Mark Thomas <[email protected]>
AuthorDate: Wed Sep 30 12:36:15 2026 +0100

    Follow-up to 87ed9d47
    
    - always set the callback result
---
 .../org/apache/catalina/authenticator/jaspic/CallbackHandlerImpl.java | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git 
a/java/org/apache/catalina/authenticator/jaspic/CallbackHandlerImpl.java 
b/java/org/apache/catalina/authenticator/jaspic/CallbackHandlerImpl.java
index c28886eee5..3216b556f6 100644
--- a/java/org/apache/catalina/authenticator/jaspic/CallbackHandlerImpl.java
+++ b/java/org/apache/catalina/authenticator/jaspic/CallbackHandlerImpl.java
@@ -84,6 +84,7 @@ public class CallbackHandlerImpl implements CallbackHandler, 
Contained {
                     GroupPrincipalCallback gpc = (GroupPrincipalCallback) 
callback;
                     groups = gpc.getGroups();
                 } else if (callback instanceof PasswordValidationCallback) {
+                    PasswordValidationCallback pvc = 
(PasswordValidationCallback) callback;
                     if (container == null) {
                         
log.warn(sm.getString("callbackHandlerImpl.containerMissing", 
callback.getClass().getName()));
                         passwordValidationFailed = true;
@@ -92,15 +93,14 @@ public class CallbackHandlerImpl implements 
CallbackHandler, Contained {
                                 container.getName()));
                         passwordValidationFailed = true;
                     } else {
-                        PasswordValidationCallback pvc = 
(PasswordValidationCallback) callback;
                         principal =
                                 
container.getRealm().authenticate(pvc.getUsername(), 
String.valueOf(pvc.getPassword()));
-                        pvc.setResult(principal != null);
                         if (principal == null) {
                             passwordValidationFailed = true;
                         }
                         subject = pvc.getSubject();
                     }
+                    pvc.setResult(!passwordValidationFailed);
                 } else {
                     
log.error(sm.getString("callbackHandlerImpl.jaspicCallbackMissing", 
callback.getClass().getName()));
                 }


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to