Skip to content

[#2818] - Skip simulateFailedLogin for AllowAllCredentialsMatcher - #2855

Closed
arimu1 wants to merge 1 commit into
apache:mainfrom
arimu1:fix-2818-allow-all-simulated-credentials
Closed

[#2818] - Skip simulateFailedLogin for AllowAllCredentialsMatcher#2855
arimu1 wants to merge 1 commit into
apache:mainfrom
arimu1:fix-2818-allow-all-simulated-credentials

Conversation

@arimu1

@arimu1 arimu1 commented Aug 13, 2026

Copy link
Copy Markdown

Summary

Fixes #2818.

AllowAllCredentialsMatcher always returns true from doCredentialsMatch, so it cannot provide decoy simulated credentials that fail matching. When a multi-realm setup asks such a realm about an unknown principal, simulateFailedLogin was treating the decoy as a misconfiguration and logging a false IncorrectCredentialsException error on every login.

This change:

  • Returns Optional.empty() from AllowAllCredentialsMatcher#createSimulatedCredentials()
  • Caches the opt-out in AuthenticatingRealm#ensureSimulatedAuthenticationInfo so empty simulated credentials are not re-requested on every lookup
  • Skips the misconfiguration warning for AllowAllCredentialsMatcher, since opting out is intentional

Test plan

  • mvn -pl core -am test -Dtest=AllowAllCredentialsMatcherTest,AuthenticatingRealmJavaTest -Dsurefire.failIfNoSpecifiedTests=false (JDK 21)
  • Added regression test for unknown principal + AllowAllCredentialsMatcher
  • Added test asserting createSimulatedCredentials() is empty

Made with LLM

Checklist

Following this checklist to help us incorporate your contribution quickly and easily:

  • Make sure there is a GitHub issue filed
    for the change (usually before you start working on it). Trivial changes like typos do not
    require a GitHub issue. Your pull request should address just this issue, without pulling in other changes.
  • Format the pull request title like [#XXX] - Fixes bug in SessionManager,
    where you replace #XXX with the appropriate GitHub issue. Best practice
    is to use the GitHub issue title in the pull request title and in the first line of the commit message.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • add fixes #XXX if merging the PR should close a related issue.
  • Run mvn verify to make sure basic checks pass. A more thorough check will be performed on your pull request automatically.
  • Committers: Make sure a milestone is set on the PR
  • Committers: Use "Squash and Merge" to combine all commits into one when merging a PR when appropriate.

Trivial changes like typos do not require a GitHub issue (javadoc, comments...).
In this case, just format the pull request title like [DOC] - Add javadoc in SessionManager.

If this is your first contribution, you have to read the Contribution Guidelines

If your pull request is about ~20 lines of code you don't need to sign an Individual Contributor License Agreement
if you are unsure please ask on the developers list.

To make clear that you license your contribution under the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.

AllowAllCredentialsMatcher always matches credentials, so it cannot supply
decoy simulated credentials. Return Optional.empty() and cache the opt-out in
AuthenticatingRealm to avoid false misconfiguration errors and repeated warnings
when a multi-realm setup asks a realm about an unknown principal.

Fixes apache#2818
@github-actions github-actions Bot added java Pull requests that update Java code tests labels Aug 13, 2026

@lprimak lprimak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you please restore the PR template. PRs cannot be accepted without it, and copyright / license attribution

@lprimak lprimak added CLA and removed pending-cla labels Aug 13, 2026
@lprimak lprimak added this to the 3.0.1 milestone Aug 14, 2026
@lprimak lprimak self-assigned this Aug 14, 2026
@lprimak

lprimak commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Please check the appropriate box in the description checklist to attribute license and copyright to Apache.

Thank you for your contribution.

@lprimak lprimak removed this from the 3.0.1 milestone Aug 14, 2026
@lprimak lprimak added pending-cla and removed CLA labels Aug 14, 2026
@lprimak

lprimak commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

I have reviewed your PR. I think it's way over-complicated. It inspired me to write much simpler PR.
Once again, thank you for your contribution as it inspired me. I will close this PR in favor of #2856

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

java Pull requests that update Java code pending-cla tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] AllowAllCredentialsMatcher logs a "matched the simulated credentials" error via simulateFailedLogin

2 participants