zhang-arvin opened a new pull request, #7063:
URL: https://github.com/apache/shenyu/pull/7063

   Fixes #7058
   
   ## Problem
   
   The official `docker-compose.yaml` distributed a hardcoded, publicly-known
   `SHENYU_JWT_SECRETKEY=please-replace-with-your-own-secret-key`. Anyone who 
can
   read the repository (or any published copy of the compose file) knows this
   value and can forge admin JWTs, bypassing authentication. PR #6408 already
   introduced `shenyu.jwt.secretKey` with fail-fast validation for blank values
   and the `defaultSecretKey` sentinel, but the non-empty public value shipped 
in
   the compose file was not on the denylist.
   
   ## Changes
   
   - `shenyu-dist/.../docker-compose.yaml`: no longer ships a default key.
     `SHENYU_JWT_SECRETKEY=${SHENYU_JWT_SECRETKEY:?SHENYU_JWT_SECRETKEY must be 
set...}`
     forces docker compose to refuse to start until the user exports their own
     secret. Comment shows how to generate one (`openssl rand -base64 48`). The
     admin fail-fast validation on empty values acts as the second line of 
defense.
   - `shenyu-common/.../AdminConstants.java`: add `JWT_PUBLIC_SECRET_KEY` 
sentinel
     (`please-replace-with-your-own-secret-key`).
   - `shenyu-admin/.../JwtProperties.java`: reject the public key in the
     `@PostConstruct` validation, same treatment as `defaultSecretKey`, so 
existing
     deployments still using the shipped value fail fast instead of staying
     forgeable.
   - `JwtPropertiesTest.java`: unit test covering the new sentinel.
   
   ## Migration note
   
   If you are currently running the compose file as-is, admin will now fail to
   start until you set your own `SHENYU_JWT_SECRETKEY` (and if it was the old
   public value, it is now explicitly rejected). Generate one per the compose
   comment and all signed-in users will need to re-login.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to