Skip to content

Commit baae601

Browse files
committed
Parameterize default credentials
1 parent f8a80c6 commit baae601

9 files changed

Lines changed: 51 additions & 24 deletions

File tree

‎core/persistence-jpa/src/test/java/org/apache/syncope/core/persistence/jpa/PersistenceTestContext.java‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,7 @@
1919
package org.apache.syncope.core.persistence.jpa;
2020

2121
import jakarta.persistence.EntityManagerFactory;
22+
import java.io.IOException;
2223
import javax.sql.DataSource;
2324
import org.apache.commons.lang3.StringUtils;
2425
import org.apache.syncope.common.keymaster.client.api.ConfParamOps;
@@ -116,7 +117,7 @@ public ConnectorManager connectorManager() {
116117
}
117118

118119
@Bean
119-
public EncryptorManager encryptorManager() {
120+
public EncryptorManager encryptorManager() throws IOException {
120121
SecurityProperties securityProperties = new SecurityProperties();
121122
securityProperties.setAesSecretKey(StringUtils.EMPTY);
122123
securityProperties.setProductionMode(false);

‎core/persistence-neo4j/src/test/java/org/apache/syncope/core/persistence/neo4j/PersistenceTestContext.java‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@
1818
*/
1919
package org.apache.syncope.core.persistence.neo4j;
2020

21+
import java.io.IOException;
2122
import javax.cache.CacheManager;
2223
import javax.cache.Caching;
2324
import org.apache.commons.lang3.StringUtils;
@@ -108,7 +109,7 @@ public ConnectorManager connectorManager() {
108109
}
109110

110111
@Bean
111-
public EncryptorManager encryptorManager() {
112+
public EncryptorManager encryptorManager() throws IOException {
112113
SecurityProperties securityProperties = new SecurityProperties();
113114
securityProperties.setAesSecretKey(StringUtils.EMPTY);
114115
securityProperties.setProductionMode(false);

‎core/spring/pom.xml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -151,14 +151,14 @@ under the License.
151151
<directory>src/main/resources</directory>
152152
<filtering>true</filtering>
153153
<includes>
154-
<include>**/security.properties</include>
154+
<include>**/default-credentials.properties</include>
155155
</includes>
156156
</resource>
157157
<resource>
158158
<directory>src/main/resources</directory>
159159
<filtering>false</filtering>
160160
<excludes>
161-
<exclude>**/security.properties</exclude>
161+
<exclude>**/default-credentials.properties</exclude>
162162
</excludes>
163163
</resource>
164164
</resources>

‎core/spring/src/main/java/org/apache/syncope/core/spring/security/DefaultCredentialChecker.java‎

Lines changed: 13 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,9 @@
1818
*/
1919
package org.apache.syncope.core.spring.security;
2020

21+
import java.io.IOException;
22+
import java.io.InputStream;
23+
import java.util.Properties;
2124
import org.slf4j.Logger;
2225
import org.slf4j.LoggerFactory;
2326

@@ -32,27 +35,18 @@ public class DefaultCredentialChecker {
3235
"The default AES key property is being used. "
3336
+ "This must be changed to avoid a security breach!";
3437

35-
private static final String DEFAULT_AES_KEY = "1abcdefghilmnopqrstuvz2!";
36-
3738
private static final String DEFAULT_JWS_KEY_ERROR_MESSAGE =
3839
"The default JWKS key property is being used. "
3940
+ "This must be changed to avoid a security breach!";
4041

41-
private static final String DEFAULT_JWS_KEY = "ZW7pRixehFuNUtnY5Se47IemgMryTzazPPJ9CGX5LTCmsOJpOgHAQEuPQeV9A28f";
42-
4342
private static final String DEFAULT_ADMIN_PASSWORD_ERROR_MESSAGE =
4443
"The default adminPassword property is being used. "
4544
+ "This must be changed to avoid a security breach!";
4645

47-
private static final String DEFAULT_ADMIN_PASSWORD =
48-
"DE088591C00CC98B36F5ADAAF7DA2B004CF7F2FE7BBB45B766B6409876E2F3DB13C7905C6AA59464";
49-
5046
private static final String DEFAULT_ANON_KEY_ERROR_MESSAGE =
5147
"The default anonymousKey property is being used. "
5248
+ "This must be changed to avoid a security breach!";
5349

54-
private static final String DEFAULT_ANON_KEY = "anonymousKey";
55-
5650
private final boolean defaultAesKeyInUse;
5751

5852
private final boolean defaultJwsKeyInUse;
@@ -68,12 +62,17 @@ public DefaultCredentialChecker(
6862
final String jwsKey,
6963
final String adminPassword,
7064
final String anonymousKey,
71-
final boolean productionMode) {
65+
final boolean productionMode) throws IOException {
66+
67+
try (InputStream in = getClass().getResourceAsStream("/META-INF/default-credentials.properties")) {
68+
Properties defaultCredentials = new Properties();
69+
defaultCredentials.load(in);
70+
defaultAesKeyInUse = defaultCredentials.getProperty("default.aesSecretKey").equals(aesKey);
71+
defaultJwsKeyInUse = defaultCredentials.getProperty("default.jwsKey").equals(jwsKey);
72+
defaultAdminPasswordInUse = defaultCredentials.getProperty("default.adminPassword").equals(adminPassword);
73+
defaultAnonymousKeyInUse = defaultCredentials.getProperty("default.anonymousKey").equals(anonymousKey);
74+
}
7275

73-
defaultAesKeyInUse = DEFAULT_AES_KEY.equals(aesKey);
74-
defaultJwsKeyInUse = DEFAULT_JWS_KEY.equals(jwsKey);
75-
defaultAdminPasswordInUse = DEFAULT_ADMIN_PASSWORD.equals(adminPassword);
76-
defaultAnonymousKeyInUse = DEFAULT_ANON_KEY.equals(anonymousKey);
7776
this.productionMode = productionMode;
7877
}
7978

‎core/spring/src/main/java/org/apache/syncope/core/spring/security/SecurityContext.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ public JWSAlgorithm jwsAlgorithm(final SecurityProperties props) {
113113
@Bean
114114
public DefaultCredentialChecker credentialChecker(
115115
final SecurityProperties props,
116-
final JWSAlgorithm jwsAlgorithm) {
116+
final JWSAlgorithm jwsAlgorithm) throws IOException {
117117

118118
return new DefaultCredentialChecker(
119119
props.getAesSecretKey(),
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# Licensed to the Apache Software Foundation (ASF) under one
2+
# or more contributor license agreements. See the NOTICE file
3+
# distributed with this work for additional information
4+
# regarding copyright ownership. The ASF licenses this file
5+
# to you under the Apache License, Version 2.0 (the
6+
# "License"); you may not use this file except in compliance
7+
# with the License. You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing,
12+
# software distributed under the License is distributed on an
13+
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14+
# KIND, either express or implied. See the License for the
15+
# specific language governing permissions and limitations
16+
# under the License.
17+
default.aesSecretKey=${secretKey}
18+
default.jwsKey=${jwsKey}
19+
default.adminPassword=${adminPassword}
20+
default.anonymousKey=${anonymousKey}

‎core/spring/src/test/java/org/apache/syncope/core/spring/SpringTestConfiguration.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ public ApplicationContextProvider applicationContextProvider() {
4747
}
4848

4949
@Bean
50-
public EncryptorManager encryptorManager() {
50+
public EncryptorManager encryptorManager() throws IOException {
5151
SecurityProperties securityProperties = new SecurityProperties();
5252
securityProperties.setAesSecretKey(AES_SECRET_KEY);
5353
return new DefaultEncryptorManager(new DefaultCredentialChecker("", "", "", "", false), securityProperties);

‎core/spring/src/test/java/org/apache/syncope/core/spring/security/DefaultEncryptorTest.java‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
import static org.junit.jupiter.api.Assertions.assertThrows;
2525
import static org.junit.jupiter.api.Assertions.assertTrue;
2626

27+
import java.io.IOException;
2728
import java.security.InvalidKeyException;
2829
import org.apache.syncope.common.lib.types.CipherAlgorithm;
2930
import org.apache.syncope.core.persistence.api.ApplicationContextProvider;
@@ -39,7 +40,7 @@ public class DefaultEncryptorTest {
3940
private static Encryptor ENCRYPTOR;
4041

4142
@BeforeAll
42-
public static void setUp() {
43+
public static void setUp() throws IOException {
4344
SecurityProperties props = new SecurityProperties();
4445
props.setAesSecretKey(SpringTestConfiguration.AES_SECRET_KEY);
4546
ApplicationContextProvider.getBeanFactory().registerSingleton("securityProperties", props);

‎fit/core-reference/src/test/java/org/apache/syncope/fit/AbstractITCase.java‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
import static org.awaitility.Awaitility.await;
2222
import static org.junit.jupiter.api.Assertions.assertEquals;
2323
import static org.junit.jupiter.api.Assertions.assertNotNull;
24+
import static org.junit.jupiter.api.Assertions.fail;
2425

2526
import com.fasterxml.jackson.databind.JsonNode;
2627
import com.fasterxml.jackson.databind.json.JsonMapper;
@@ -1163,13 +1164,17 @@ protected static void verifyMail(
11631164
@Autowired
11641165
protected DataSource testDataSource;
11651166

1166-
protected final EncryptorManager encryptorManager;
1167+
protected EncryptorManager encryptorManager;
11671168

11681169
protected AbstractITCase() {
11691170
SecurityProperties securityProperties = new SecurityProperties();
11701171
securityProperties.setAesSecretKey(StringUtils.EMPTY);
11711172
securityProperties.setProductionMode(false);
1172-
encryptorManager = new DefaultEncryptorManager(
1173-
new DefaultCredentialChecker("", "", "", "", false), securityProperties);
1173+
try {
1174+
encryptorManager = new DefaultEncryptorManager(
1175+
new DefaultCredentialChecker("", "", "", "", false), securityProperties);
1176+
} catch (IOException e) {
1177+
fail(e.getMessage(), e);
1178+
}
11741179
}
11751180
}

0 commit comments

Comments
 (0)