Skip to content

Remove inert mutual auth request and javadoc-only import - #7281

Merged
dagnir merged 1 commit into
feature/master/netty-kerberos-proxy-authfrom
dongie/netty-kerberos-cleanup
Aug 14, 2026
Merged

Remove inert mutual auth request and javadoc-only import#7281
dagnir merged 1 commit into
feature/master/netty-kerberos-proxy-authfrom
dongie/netty-kerberos-cleanup

Conversation

@dagnir

@dagnir dagnir commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

requestMutualAuth(true) asked for mutual authentication that was never established: the proxy's response token is never consumed, so there is nothing to verify it against. Preemptive single-leg Negotiate cannot verify it either, so the call is dropped rather than wired up.

The com.sun.security.auth.module.Krb5LoginModule import existed only to satisfy a javadoc {@link}. Referring to the class by name in {@code} instead keeps the documentation while dropping a compile-time reference to a JDK-implementation-specific class.

Motivation and Context

Modifications

Testing

Screenshots (if appropriate)

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

Checklist

  • I have read the CONTRIBUTING document
  • Local run of mvn install succeeds
  • My code follows the code style of this project
  • My change requires a change to the Javadoc documentation
  • I have updated the Javadoc documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have added a changelog entry. Adding a new entry must be accomplished by running the scripts/new-change script and following the instructions. Commit the new file created by the script in .changes/next-release with your changes.
  • My change is to implement 1.11 parity feature and I have updated LaunchChangelog

License

  • I confirm that this pull request can be released under the Apache 2 license

requestMutualAuth(true) asked for mutual authentication that was never
established: the proxy's response token is never consumed, so there is
nothing to verify it against. Preemptive single-leg Negotiate cannot
verify it either, so the call is dropped rather than wired up.

The com.sun.security.auth.module.Krb5LoginModule import existed only to
satisfy a javadoc {@link}. Referring to the class by name in {@code}
instead keeps the documentation while dropping a compile-time reference
to a JDK-implementation-specific class.
@dagnir
dagnir requested a review from a team as a code owner August 14, 2026 21:58
@dagnir
dagnir requested a review from Fred1155 August 14, 2026 21:59
@dagnir
dagnir merged commit bdf60d5 into feature/master/netty-kerberos-proxy-auth Aug 14, 2026
4 checks passed
@github-actions

Copy link
Copy Markdown

This pull request has been closed and the conversation has been locked. Comments on closed PRs are hard for our team to see. If you need more assistance, please open a new issue that references this one.

@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Aug 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants