]
Stefan Guilhen resolved SECURITY-993.
-------------------------------------
Resolution: Done
PR has been merged upstream
SimpleRole.hashCode NPE when a principal has the roles set to null
------------------------------------------------------------------
Key: SECURITY-993
URL:
https://issues.jboss.org/browse/SECURITY-993
Project: PicketBox
Issue Type: Bug
Components: Identity
Affects Versions: PicketBox_5_1_0.Final
Environment: Wild Fly Swarm 2018.2.0
Reporter: Sergey Beryozkin
Assignee: Ilia Vassilev
Priority: Minor
Fix For: PicketBox_5_1_1.Beta1
If a principal is created with the roles set to null then NPE is reported back to the
user during the authentication process:
{noformat}
java.lang.RuntimeException: java.lang.NullPointerException
at
org.wildfly.extension.undertow.security.JAASIdentityManagerImpl.verifyCredential(JAASIdentityManagerImpl.java:140)
at
org.wildfly.extension.undertow.security.JAASIdentityManagerImpl.verify(JAASIdentityManagerImpl.java:94)
at
io.undertow.security.impl.BasicAuthenticationMechanism.authenticate(BasicAuthenticationMechanism.java:167)
at
io.undertow.security.impl.SecurityContextImpl$AuthAttempter.transition(SecurityContextImpl.java:245)
....
Caused by: java.lang.NullPointerException
at org.jboss.security.identity.plugins.SimpleRole.hashCode(SimpleRole.java:106)
{noformat}