[JBoss JIRA] (ELY-613) Some nested classes should be considered to be static nested in Elytron
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-613?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse updated ELY-613:
---------------------------------
Fix Version/s: 1.1.0.Beta32
(was: 1.1.0.Beta31)
> Some nested classes should be considered to be static nested in Elytron
> -----------------------------------------------------------------------
>
> Key: ELY-613
> URL: https://issues.jboss.org/browse/ELY-613
> Project: WildFly Elytron
> Issue Type: Bug
> Affects Versions: 1.1.0.Beta7
> Reporter: Ondrej Lukas
> Assignee: Darran Lofthouse
> Labels: static_analysis
> Fix For: 1.1.0.Beta32
>
>
> There are some inner classes in Elytron which should be considered to be static nested to avoid dependency on their outer class. Following nested classes should be considered:
> * LoadedIdentity and Identity from org.wildfly.security.auth.realm.FileSystemSecurityRealm
> * DecoderState from org.wildfly.security.asn1.DERDecoder
> * AccountEntry from org.wildfly.security.auth.realm.LegacyPropertiesSecurityRealm
> * JaasAuthorizationIdentity and DefaultCallbackHandler from org.wildfly.security.auth.realm.JaasSecurityRealm
> * LoadKey from org.wildfly.security.keystore.AtomicLoadKeyStore
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 1 month
[JBoss JIRA] (ELY-873) AuthenticationClient testing without jboss-modules
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-873?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse updated ELY-873:
---------------------------------
Fix Version/s: 1.1.0.Beta32
(was: 1.1.0.Beta31)
> AuthenticationClient testing without jboss-modules
> --------------------------------------------------
>
> Key: ELY-873
> URL: https://issues.jboss.org/browse/ELY-873
> Project: WildFly Elytron
> Issue Type: Enhancement
> Components: Authentication Client, Testsuite
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Fix For: 1.1.0.Beta32
>
>
> Keeping AuthenticationClient usable without a dependency on JBoss Modules is the kind of thing that will be easy to break.
> We should probably have a matrix of tests verifying AuthenticationClient anyway, we should then repeat the tests without JBoss Modules on the ClassPath.
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 1 month
[JBoss JIRA] (ELY-810) Unify CredentialStore around CredentialSource style storage capability
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-810?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse updated ELY-810:
---------------------------------
Fix Version/s: 1.1.0.Beta32
(was: 1.1.0.Beta31)
> Unify CredentialStore around CredentialSource style storage capability
> ----------------------------------------------------------------------
>
> Key: ELY-810
> URL: https://issues.jboss.org/browse/ELY-810
> Project: WildFly Elytron
> Issue Type: Task
> Components: Credential Store
> Reporter: David Lloyd
> Assignee: David Lloyd
> Fix For: 1.1.0.Beta32
>
>
> The following needs to be done:
> * Move the PB masked password format to a proper password type
> * Introduce protection parameters for credential stores and entries
> * Drop the admin_key concept in favor of credential store protection parameters
> * Introduce a proper vault-compatible credential store
> * Introduce a mechanism to pull protection parameters for stores from the client configuration
> * Use a credential store which can store (nearly) any credential type
> * Update XML accordingly
> * Remove dangerous command execution patterns from credential store, make them safe and make them CredentialSources instead
> * Clean up exception hierarchy of credential stores
> * Introduce simple map-backed credential store
> Additionally, the above implies:
> * Introduce AlgorithmParameterSpi for password parameter types
> * Introduce hashing ability for parameters
> * Add missing parameter types for PBE
> * Introduce serialization trickery to support picketbox class names for vault files
> * Atomic file output stream
> * Update tests as needed
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 1 month
[JBoss JIRA] (ELY-773) Where AuthenticationConfiguration has calls to PasswordFactory.getInstance(alg) pass in Supplier<Provider[]>
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-773?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse updated ELY-773:
---------------------------------
Fix Version/s: 1.1.0.Beta32
(was: 1.1.0.Beta31)
> Where AuthenticationConfiguration has calls to PasswordFactory.getInstance(alg) pass in Supplier<Provider[]>
> ------------------------------------------------------------------------------------------------------------
>
> Key: ELY-773
> URL: https://issues.jboss.org/browse/ELY-773
> Project: WildFly Elytron
> Issue Type: Task
> Components: Authentication Client
> Reporter: Darran Lofthouse
> Assignee: David Lloyd
> Priority: Critical
> Fix For: 1.1.0.Beta32
>
>
> This may be obsoleted by ongoing work but just wanted an issue to track where AuthenticationConfiguration and related classes currently uses PaswordFactory.getInstance without passing in a Supplier for Provider[].
> * SetCredentialsConfiguration
> * SetKeyStoreCredentialAuthenticationConfiguration
> * ElytronAuthenticator
> * ElytronXmlParser.
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 1 month