zhang-arvin opened a new pull request, #7063:
URL: https://github.com/apache/shenyu/pull/7063
Fixes #7058
## Problem
The official `docker-compose.yaml` distributed a hardcoded, publicly-known
`SHENYU_JWT_SECRETKEY=please-replace-with-your-own-secret-key`. Anyone who
can
read the repository (or any published copy of the compose file) knows this
value and can forge admin JWTs, bypassing authentication. PR #6408 already
introduced `shenyu.jwt.secretKey` with fail-fast validation for blank values
and the `defaultSecretKey` sentinel, but the non-empty public value shipped
in
the compose file was not on the denylist.
## Changes
- `shenyu-dist/.../docker-compose.yaml`: no longer ships a default key.
`SHENYU_JWT_SECRETKEY=${SHENYU_JWT_SECRETKEY:?SHENYU_JWT_SECRETKEY must be
set...}`
forces docker compose to refuse to start until the user exports their own
secret. Comment shows how to generate one (`openssl rand -base64 48`). The
admin fail-fast validation on empty values acts as the second line of
defense.
- `shenyu-common/.../AdminConstants.java`: add `JWT_PUBLIC_SECRET_KEY`
sentinel
(`please-replace-with-your-own-secret-key`).
- `shenyu-admin/.../JwtProperties.java`: reject the public key in the
`@PostConstruct` validation, same treatment as `defaultSecretKey`, so
existing
deployments still using the shipped value fail fast instead of staying
forgeable.
- `JwtPropertiesTest.java`: unit test covering the new sentinel.
## Migration note
If you are currently running the compose file as-is, admin will now fail to
start until you set your own `SHENYU_JWT_SECRETKEY` (and if it was the old
public value, it is now explicitly rejected). Generate one per the compose
comment and all signed-in users will need to re-login.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]