Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-15237

Distributed search with index sharding is not working with basic authentication plugin enabled

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Critical
    • Resolution: Unresolved
    • 7.7.3, 8.7, 8.8.1
    • None
    • Authentication

    Description

      Issue confirmed for 7.7.3, 8.7 and 8.8.1.

      Steps to reproduce are:
      1. Following the docs for setting up distributed search (https://solr.apache.org/guide/8_8/distributed-search-with-index-sharding.html).
      1.1 Stop both nodes after confirming that distributed search works without basic auth (last step).
      2. Enable basic authentication plugin for both nodes, example for node1 example/nodes/node1/security.json:

      "authentication":{ 
         "blockUnknown": true, 
         "class":"solr.BasicAuthPlugin",
         "credentials":{"solr":"IV0EHq1OnNrj6gvRCwvFwTrZ1+z1oBbnQdiVC3otuq0= Ndd7LKvVBAaZIF0QAVi1ekCfAJXr1GGfLtRUXhgrF8c="}, 
         "realm":"My Solr users", 
         "forwardCredentials": false 
      }}
      

      3. Configure shardsWhitelist in solr.xml for both nodes, example for node1 example/nodes/node1/solr.xml

      <shardHandlerFactory name="shardHandlerFactory"
          class="HttpShardHandlerFactory">
          <int name="socketTimeout">${socketTimeout:600000}</int>
          <int name="connTimeout">${connTimeout:60000}</int>
          <str name="shardsWhitelist">localhost:8984,localhost:8985</str>
        </shardHandlerFactory>
      

      4. Start both nodes.
      5. Confirm that searching on one node with basic auth works with curl --user solr:SolrRocks "http://localhost:8984/solr/core1/select?q=:&wt=xml&indent=true"
      6. Confirm that searching on both nodes does not work with curl --user solr:SolrRocks "http://localhost:8984/solr/core1/select?q=:&indent=true&shards=localhost:8985/solr/core1,localhost:8984/solr/core1&fl=id,name&wt=xml"

      Error:

      ❯ curl --user solr:SolrRocks "http://localhost:8984/solr/core1/select?q=*:*&indent=true&shards=localhost:8985/solr/core1,localhost:8984/solr/core1&fl=id,name&wt=xml"
      <?xml version="1.0" encoding="UTF-8"?>
      <response>
      
      <lst name="responseHeader">
        <int name="status">401</int>
        <int name="QTime">173</int>
        <lst name="params">
          <str name="q">*:*</str>
          <str name="shards">localhost:8985/solr/core1,localhost:8984/solr/core1</str>
          <str name="indent">true</str>
          <str name="fl">id,name</str>
          <str name="wt">xml</str>
        </lst>
      </lst>
      <lst name="error">
        <lst name="metadata">
          <str name="error-class">org.apache.solr.client.solrj.impl.BaseHttpSolrClient$RemoteSolrException</str>
          <str name="root-error-class">org.apache.solr.client.solrj.impl.BaseHttpSolrClient$RemoteSolrException</str>
        </lst>
        <str name="msg">Error from server at null: Expected mime type application/octet-stream but got text/html. &lt;html&gt;
      &lt;head&gt;
      &lt;meta http-equiv="Content-Type" content="text/html;charset=utf-8"/&gt;
      &lt;title&gt;Error 401 require authentication&lt;/title&gt;
      &lt;/head&gt;
      &lt;body&gt;&lt;h2&gt;HTTP ERROR 401 require authentication&lt;/h2&gt;
      &lt;table&gt;
      &lt;tr&gt;&lt;th&gt;URI:&lt;/th&gt;&lt;td&gt;/solr/core1/select&lt;/td&gt;&lt;/tr&gt;
      &lt;tr&gt;&lt;th&gt;STATUS:&lt;/th&gt;&lt;td&gt;401&lt;/td&gt;&lt;/tr&gt;
      &lt;tr&gt;&lt;th&gt;MESSAGE:&lt;/th&gt;&lt;td&gt;require authentication&lt;/td&gt;&lt;/tr&gt;
      &lt;tr&gt;&lt;th&gt;SERVLET:&lt;/th&gt;&lt;td&gt;default&lt;/td&gt;&lt;/tr&gt;
      &lt;/table&gt;
      
      &lt;/body&gt;
      &lt;/html&gt;
      </str>
        <int name="code">401</int>
      </lst>
      </response>
      

      See also SOLR-14569 that seems similar, but the patch provided does not help after I applied it to 8.8.1, therefore I think this is not the same issue.

      Adjust priority as necessary. For cases where basic auth is required this means we cannot use Solr as of now.

      Attachments

        Issue Links

          Activity

            People

              markrmiller Mark Robert Miller
              shuremov Samir Huremovic
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated: