[infinispan-issues] [JBoss JIRA] (ISPN-10722) Mgmt console: home page load fails in case secured cache container

Will Burns (Jira) issues at jboss.org
Mon Oct 28 13:43:00 EDT 2019


    [ https://issues.jboss.org/browse/ISPN-10722?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13805138#comment-13805138 ] 

Will Burns commented on ISPN-10722:
-----------------------------------

Still get errors like:

{quote}
13:42:02,045 ERROR [org.jboss.as.controller.management-operation] (External Management Request Threads -- 2) WFLYCTL0013: Operation ("read-attribute") failed - address: ([
    ("subsystem" => "datagrid-infinispan"),
    ("cache-container" => "clustered")
]): org.infinispan.commons.CacheException: Could not execute cluster wide cache stats operation
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.AbstractClusterStats.fetchClusterWideStatsIfNeeded(AbstractClusterStats.java:117)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.AbstractClusterStats.getStat(AbstractClusterStats.java:207)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.AbstractClusterStats.getStatAsLong(AbstractClusterStats.java:198)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.ClusterContainerStatsImpl.getMemoryAvailable(ClusterContainerStatsImpl.java:81)
	at org.infinispan.extension:ispn-9.4 at 9.4.16-SNAPSHOT//org.jboss.as.clustering.infinispan.subsystem.CacheContainerMetricsHandler.executeRuntimeStep(CacheContainerMetricsHandler.java:309)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AbstractRuntimeOnlyHandler$1.execute(AbstractRuntimeOnlyHandler.java:59)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AbstractOperationContext.executeStep(AbstractOperationContext.java:999)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AbstractOperationContext.processStages(AbstractOperationContext.java:743)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AbstractOperationContext.executeOperation(AbstractOperationContext.java:467)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.OperationContextImpl.executeOperation(OperationContextImpl.java:1411)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.ModelControllerImpl.internalExecute(ModelControllerImpl.java:423)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.ModelControllerImpl.lambda$execute$1(ModelControllerImpl.java:243)
	at org.wildfly.security.elytron-private at 1.6.0.Final//org.wildfly.security.auth.server.SecurityIdentity.runAs(SecurityIdentity.java:265)
	at org.wildfly.security.elytron-private at 1.6.0.Final//org.wildfly.security.auth.server.SecurityIdentity.runAs(SecurityIdentity.java:231)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.ModelControllerImpl.execute(ModelControllerImpl.java:243)
	at org.jboss.as.domain-http-interface at 6.0.2.Final//org.jboss.as.domain.http.server.DomainApiHandler.handleRequest(DomainApiHandler.java:212)
	at io.undertow.core at 2.0.13.Final//io.undertow.server.handlers.encoding.EncodingHandler.handleRequest(EncodingHandler.java:72)
	at org.jboss.as.domain-http-interface at 6.0.2.Final//org.jboss.as.domain.http.server.DomainApiCheckHandler.handleRequest(DomainApiCheckHandler.java:93)
	at org.jboss.as.domain-http-interface at 6.0.2.Final//org.jboss.as.domain.http.server.security.ElytronIdentityHandler.lambda$handleRequest$0(ElytronIdentityHandler.java:62)
	at org.wildfly.security.elytron-private at 1.6.0.Final//org.wildfly.security.auth.server.SecurityIdentity.runAs(SecurityIdentity.java:289)
	at org.wildfly.security.elytron-private at 1.6.0.Final//org.wildfly.security.auth.server.SecurityIdentity.runAs(SecurityIdentity.java:246)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AccessAuditContext.doAs(AccessAuditContext.java:254)
	at org.jboss.as.controller at 6.0.2.Final//org.jboss.as.controller.AccessAuditContext.doAs(AccessAuditContext.java:225)
	at org.jboss.as.domain-http-interface at 6.0.2.Final//org.jboss.as.domain.http.server.security.ElytronIdentityHandler.handleRequest(ElytronIdentityHandler.java:61)
	at io.undertow.core at 2.0.13.Final//io.undertow.server.handlers.BlockingHandler.handleRequest(BlockingHandler.java:56)
	at io.undertow.core at 2.0.13.Final//io.undertow.server.Connectors.executeRootHandler(Connectors.java:360)
	at io.undertow.core at 2.0.13.Final//io.undertow.server.HttpServerExchange$1.run(HttpServerExchange.java:830)
	at org.jboss.threads at 2.3.2.Final//org.jboss.threads.ContextClassLoaderSavingRunnable.run(ContextClassLoaderSavingRunnable.java:35)
	at org.jboss.threads at 2.3.2.Final//org.jboss.threads.EnhancedQueueExecutor.safeRun(EnhancedQueueExecutor.java:1985)
	at org.jboss.threads at 2.3.2.Final//org.jboss.threads.EnhancedQueueExecutor$ThreadBody.doRunTask(EnhancedQueueExecutor.java:1487)
	at org.jboss.threads at 2.3.2.Final//org.jboss.threads.EnhancedQueueExecutor$ThreadBody.run(EnhancedQueueExecutor.java:1349)
	at java.base/java.lang.Thread.run(Thread.java:834)
	at org.jboss.threads at 2.3.2.Final//org.jboss.threads.JBossThread.run(JBossThread.java:485)
Caused by: java.lang.SecurityException: ISPN000287: Unauthorized access: subject 'null' lacks 'ADMIN' permission
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.security.impl.AuthorizationHelper.checkPermission(AuthorizationHelper.java:87)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.security.impl.AuthorizationHelper.checkPermission(AuthorizationHelper.java:57)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.manager.DefaultCacheManager.getCacheManagerConfiguration(DefaultCacheManager.java:841)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.manager.DefaultCacheManager.executor(DefaultCacheManager.java:1085)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.ClusterContainerStatsImpl.getClusterStatMaps(ClusterContainerStatsImpl.java:62)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.ClusterContainerStatsImpl.updateStats(ClusterContainerStatsImpl.java:55)
	at org.infinispan.core:ispn-9.4 at 9.4.16-SNAPSHOT//org.infinispan.stats.impl.AbstractClusterStats.fetchClusterWideStatsIfNeeded(AbstractClusterStats.java:114)

{quote}

> Mgmt console: home page load fails in case secured cache container
> ------------------------------------------------------------------
>
>                 Key: ISPN-10722
>                 URL: https://issues.jboss.org/browse/ISPN-10722
>             Project: Infinispan
>          Issue Type: Bug
>          Components: Console, JMX, reporting and management
>    Affects Versions: 9.4.16.Final, 10.0.0.CR2
>            Reporter: Dan Berindei
>            Assignee: Will Burns
>            Priority: Major
>             Fix For: 10.0.0.Final, 9.4.17.Final
>
>
> The following exception appears in server logs and hanging screen is visible in browser when mgmt console home page is accessed, in case when the server is started with secured cache-container.
> {noformat}
> 12:53:09,199 ERROR [org.jboss.as.controller.management-operation] (External Management Request Threads -- 2) WFLYCTL0013: Operation ("read-attribute") failed - address: ([
>     ("subsystem" => "datagrid-infinispan"),
>     ("cache-container" => "local")
> ]): java.lang.SecurityException: ISPN000287: Unauthorized access: subject 'null' lacks 'ADMIN' permission
> 	at org.infinispan.core:ispn-9.4 at 9.4.16.Final//org.infinispan.security.impl.AuthorizationHelper.checkPermission(AuthorizationHelper.java:87)
> 	at org.infinispan.core:ispn-9.4 at 9.4.16.Final//org.infinispan.security.impl.AuthorizationHelper.checkPermission(AuthorizationHelper.java:57)
> 	at org.infinispan.core:ispn-9.4 at 9.4.16.Final//org.infinispan.manager.DefaultCacheManager.getDefaultCacheConfiguration(DefaultCacheManager.java:847)
> 	at org.infinispan.core:ispn-9.4 at 9.4.16.Final//org.infinispan.xsite.GlobalXSiteAdminOperations.collectXSiteAdminOperation(GlobalXSiteAdminOperations.java:135)
> 	at org.infinispan.core:ispn-9.4 at 9.4.16.Final//org.infinispan.xsite.GlobalXSiteAdminOperations.globalStatus(GlobalXSiteAdminOperations.java:86)
> 	at org.infinispan.extension:ispn-9.4 at 9.4.16.Final//org.jboss.as.clustering.infinispan.subsystem.CacheContainerMetricsHandler.filterSitesByStatus(CacheContainerMetricsHandler.java:342)
> 	at org.infinispan.extension:ispn-9.4 at 9.4.16.Final//org.jboss.as.clustering.infinispan.subsystem.CacheContainerMetricsHandler.executeRuntimeStep(CacheContainerMetricsHandler.java:296)
> {noformat}



--
This message was sent by Atlassian Jira
(v7.13.8#713008)


More information about the infinispan-issues mailing list