Skip to content

Prevent impersonation of anonymous for resource domain requests#26360

Closed
somiljain2006 wants to merge 4 commits intojenkinsci:masterfrom
somiljain2006:Anonymous-impersonation-bug
Closed

Prevent impersonation of anonymous for resource domain requests#26360
somiljain2006 wants to merge 4 commits intojenkinsci:masterfrom
somiljain2006:Anonymous-impersonation-bug

Conversation

@somiljain2006
Copy link
Contributor

@somiljain2006 somiljain2006 commented Feb 24, 2026

Anonymous resource domain requests should not attempt user impersonation. Some SecurityRealm implementations cannot resolve a user named "anonymous", which previously caused UsernameNotFoundException and broke public artifact downloads.

Fixes #16639

Testing done

Added a regression test verifying that anonymous resource-domain downloads do not attempt user impersonation and succeed without triggering UsernameNotFoundException

Screenshots (UI changes only)

N/A

Before

After

Proposed changelog entries

Fixed failures when downloading resources anonymously with external security realms.

Proposed changelog category

/label bug

Proposed upgrade guidelines

N/A

Submitter checklist

  • The issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples). Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • UI changes do not introduce regressions when enforcing the current default rules of Content Security Policy Plugin. In particular, new or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

@mention

Before the changes are marked as ready-for-merge:

Maintainer checklist

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, be a Bug or Improvement, and either the issue or pull request must be labeled as lts-candidate to be considered.

@comment-ops-bot
Copy link

I wasn't able to add the following labels: Bug

Check that the label exists and is spelt right then try again.

@comment-ops-bot comment-ops-bot bot added the bug For changelog: Minor bug. Will be listed after features label Feb 24, 2026
@daniel-beck
Copy link
Member

Some SecurityRealm implementations cannot resolve a user named "anonymous"

Please provide evidence for this claim.

@daniel-beck
Copy link
Member

daniel-beck commented Feb 24, 2026

Please note the pinned issue titled "MUST READ: Instructions for newcomer contributors" in this repository. With one merged pull request so far, you are entitled to have 2 open PRs. As you currently have seven open, I'm closing this one. You're welcome to resubmit this PR once you're below your limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug For changelog: Minor bug. Will be listed after features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[JENKINS-75201] Failure to impersonate anonymous in ResourceDomainRootAction

2 participants