Class Sha256AuthenticationProvider

java.lang.Object
org.apache.solr.security.Sha256AuthenticationProvider
All Implemented Interfaces:
org.apache.solr.common.SpecProvider, BasicAuthPlugin.AuthenticationProvider, ConfigEditablePlugin

public class Sha256AuthenticationProvider extends Object implements ConfigEditablePlugin, BasicAuthPlugin.AuthenticationProvider
  • Field Details

    • ALLOW_USER_AS_PASSWORD_PROP

      public static final String ALLOW_USER_AS_PASSWORD_PROP
      System property (or SOLR_SECURITY_AUTH_BASICAUTH_ALLOWUSERASPASSWORD environment variable) that, when explicitly set to true, disables the check that rejects a password equal to its username, both at login time and when creating or editing a user via the set-user command (UI, API or CLI). This is an escape hatch for users upgrading to 9.11.0 or 10.1.0 who still have Basic Auth users with weak passwords equal to the username; it lets them keep logging in (and managing those accounts) while they migrate to stronger passwords. Defaults to false.
      See Also:
  • Constructor Details

    • Sha256AuthenticationProvider

      public Sha256AuthenticationProvider()
  • Method Details