Prevent impersonation of anonymous for resource domain requests#26360
Closed
somiljain2006 wants to merge 4 commits intojenkinsci:masterfrom
Closed
Prevent impersonation of anonymous for resource domain requests#26360somiljain2006 wants to merge 4 commits intojenkinsci:masterfrom
somiljain2006 wants to merge 4 commits intojenkinsci:masterfrom
Conversation
|
I wasn't able to add the following labels: Bug Check that the label exists and is spelt right then try again. |
Member
Please provide evidence for this claim. |
Member
|
Please note the pinned issue titled "MUST READ: Instructions for newcomer contributors" in this repository. With one merged pull request so far, you are entitled to have 2 open PRs. As you currently have seven open, I'm closing this one. You're welcome to resubmit this PR once you're below your limit. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Anonymous resource domain requests should not attempt user impersonation. Some SecurityRealm implementations cannot resolve a user named "anonymous", which previously caused UsernameNotFoundException and broke public artifact downloads.
Fixes #16639
Testing done
Added a regression test verifying that anonymous resource-domain downloads do not attempt user impersonation and succeed without triggering UsernameNotFoundException
Screenshots (UI changes only)
N/A
Before
After
Proposed changelog entries
Fixed failures when downloading resources anonymously with external security realms.
Proposed changelog category
/label bug
Proposed upgrade guidelines
N/A
Submitter checklist
@Restrictedor have@since TODOJavadocs, as appropriate.@Deprecated(since = "TODO")or@Deprecated(forRemoval = true, since = "TODO"), if applicable.evalto ease future introduction of Content Security Policy (CSP) directives (see documentation).Desired reviewers
@mention
Before the changes are marked as
ready-for-merge:Maintainer checklist
upgrade-guide-neededlabel is set and there is a Proposed upgrade guidelines section in the pull request title (see example).lts-candidateto be considered.