Skip to content

BREAKING CHANGE: do not allow simple requests for login#4823

Merged
achmelo merged 20 commits into
v3.x.xfrom
reboot/login-csrf
Jul 24, 2026
Merged

BREAKING CHANGE: do not allow simple requests for login#4823
achmelo merged 20 commits into
v3.x.xfrom
reboot/login-csrf

Conversation

@achmelo

@achmelo achmelo commented Jul 17, 2026

Copy link
Copy Markdown
Member

Description

Require content-type=application/json for login request. Respond with 415 in case of other content types.

Linked to # (issue)
Part of the # (epic)

Type of change

  • fix: Bug fix (non-breaking change which fixes an issue)
  • feat: New feature (non-breaking change which adds functionality)
  • docs: Change in a documentation
  • refactor: Refactor the code
  • chore: Chore, repository cleanup, updates the dependencies.
  • BREAKING CHANGE or !: Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • My code follows the style guidelines of this project
  • PR title conforms to commit message guideline ## Commit Message Structure Guideline
  • I have commented my code, particularly in hard-to-understand areas. In JS I did provide JSDoc
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • The java tests in the area I was working on leverage @nested annotations
  • Any dependent changes have been merged and published in downstream modules

For more details about how should the code look like read the Contributing guideline

achmelo added 3 commits July 16, 2026 11:17
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
@github-actions github-actions Bot added the Sensitive Sensitive change that requires peer review label Jul 17, 2026
@pablocarle

Copy link
Copy Markdown
Contributor

This may qualify as a breaking change as well. I remember having to do some custom logic in the login controller to keep the behaviour the same as before.

achmelo and others added 4 commits July 17, 2026 11:23
…_ATTR. Using defaultIfEmpty (rather than switchIfEmpty) guarantees the chain is filtered exactly once. chain.filter(...) returns Mono<Void>, which completes without emitting a value, so a switchIfEmpty placed after it would always fire its fallback and invoke the downstream chain (and the controller) a second time.

Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
achmelo added 3 commits July 20, 2026 15:54
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
achmelo and others added 2 commits July 22, 2026 14:35
Signed-off-by: ac892247 <a.chmelo@gmail.com>
@achmelo achmelo changed the title fix: do not allow simple requests for login BREAKING CHANGE: do not allow simple requests for login Jul 23, 2026
achmelo and others added 2 commits July 23, 2026 09:36
Comment thread apiml/src/main/java/org/zowe/apiml/filter/ContentTypeFilter.java Outdated
Comment thread apiml/src/main/java/org/zowe/apiml/filter/CachedBodyFilter.java
achmelo and others added 5 commits July 23, 2026 15:31
Co-authored-by: Andrea Tabone <39694626+taban03@users.noreply.github.com>
Signed-off-by: achmelo <37397715+achmelo@users.noreply.github.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
# Conflicts:
#	apiml/src/main/java/org/zowe/apiml/WebSecurityConfig.java
Signed-off-by: ac892247 <a.chmelo@gmail.com>
Signed-off-by: ac892247 <a.chmelo@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

@achmelo
achmelo merged commit 207350f into v3.x.x Jul 24, 2026
48 checks passed
@achmelo
achmelo deleted the reboot/login-csrf branch July 24, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Sensitive Sensitive change that requires peer review size/XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants