From e0cafa69af184abbd9cc965fc4333ebd1c6d91bb Mon Sep 17 00:00:00 2001 From: Guus der Kinderen Date: Wed, 9 Sep 2026 12:04:18 +0200 Subject: [PATCH 1/3] fixes #246: Require custom REST API authentication filters to be annotated as such Previously, `plugin.restapi.customAuthFilter` accepted any class name that resolved via `Class.forName`, with no check that the class is intended for authentication. This made it deceptively easy to misconfigure the plugin: a class that happened to resolve but was never meant to authenticate anything would silently replace the plugin's own authentication check. This risks leaving the REST API's endpoints reachable without valid credentials. Because this is a persisted configuration change rather than a code change, the misconfiguration would also survive a restart and go undetected by anything that doesn't specifically look for it. This commit adds additional checks to guard against such misconfiguration. Notably, a custom authentication filter now needs to be annotated using `@Priority(Priorities.AUTHENTICATION)`. This annotation was chosen deliberately over alternatives that would require new types or dependencies: it's already part of the JAX-RS API this plugin depends on, so the check works identically across Openfire versions, without requiring a new interface, a new library, or a version bump. Also corrects `AuthFilter` annotation from `@Priority(Priorities.AUTHORIZATION)` to `@Priority(Priorities.AUTHENTICATION)`, matching what it actually does and what custom replacements are now required to declare. Added documentation for the custom authentication filter mechanism in readme.md. --- changelog.html | 1 + readme.md | 28 +++ .../openfire/plugin/rest/AuthFilter.java | 2 +- .../plugin/rest/RESTServicePlugin.java | 12 +- .../plugin/rest/service/JerseyWrapper.java | 96 ++++++-- .../rest/service/JerseyWrapperTest.java | 230 ++++++++++++++++++ src/web/rest-api.jsp | 2 +- 7 files changed, 349 insertions(+), 22 deletions(-) create mode 100644 src/test/java/org/jivesoftware/openfire/plugin/rest/service/JerseyWrapperTest.java diff --git a/changelog.html b/changelog.html index 09b741d68..2a15c8a70 100644 --- a/changelog.html +++ b/changelog.html @@ -47,6 +47,7 @@

1.12.1 (to be determined)