Package org.apache.solr.security
Class Sha256AuthenticationProvider
java.lang.Object
org.apache.solr.security.Sha256AuthenticationProvider
- All Implemented Interfaces:
org.apache.solr.common.SpecProvider,BasicAuthPlugin.AuthenticationProvider,ConfigEditablePlugin
public class Sha256AuthenticationProvider
extends Object
implements ConfigEditablePlugin, BasicAuthPlugin.AuthenticationProvider
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringSystem property (orSOLR_SECURITY_AUTH_BASICAUTH_ALLOWUSERASPASSWORDenvironment variable) that, when explicitly set totrue, disables the check that rejects a password equal to its username, both at login time and when creating or editing a user via theset-usercommand (UI, API or CLI). -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanauthenticate(String username, String password) Operate the commands on the latest conf and return a new conf object If there are errors in the commands , throw a SolrException.static Stringorg.apache.solr.common.util.ValidatingJsonMapgetSpec()voidstatic String
-
Field Details
-
ALLOW_USER_AS_PASSWORD_PROP
System property (orSOLR_SECURITY_AUTH_BASICAUTH_ALLOWUSERASPASSWORDenvironment variable) that, when explicitly set totrue, disables the check that rejects a password equal to its username, both at login time and when creating or editing a user via theset-usercommand (UI, API or CLI). This is an escape hatch for users upgrading to 9.11.0 or 10.1.0 who still have Basic Auth users with weak passwords equal to the username; it lets them keep logging in (and managing those accounts) while they migrate to stronger passwords. Defaults tofalse.- See Also:
-
-
Constructor Details
-
Sha256AuthenticationProvider
public Sha256AuthenticationProvider()
-
-
Method Details
-
getSaltedHashedValue
-
init
- Specified by:
initin interfaceBasicAuthPlugin.AuthenticationProvider
-
authenticate
- Specified by:
authenticatein interfaceBasicAuthPlugin.AuthenticationProvider
-
getPromptHeaders
- Specified by:
getPromptHeadersin interfaceBasicAuthPlugin.AuthenticationProvider
-
sha256
-
edit
public Map<String,Object> edit(Map<String, Object> latestConf, List<org.apache.solr.common.util.CommandOperation> commands) Description copied from interface:ConfigEditablePluginOperate the commands on the latest conf and return a new conf object If there are errors in the commands , throw a SolrException. return a null if no changes are to be made as a result of this edit. It is the responsibility of the implementation to ensure that the returned config is valid . The framework does no validation of the data- Specified by:
editin interfaceConfigEditablePlugin
-
getSpec
public org.apache.solr.common.util.ValidatingJsonMap getSpec()- Specified by:
getSpecin interfaceorg.apache.solr.common.SpecProvider
-