Feature Description (功能描述)
The initial admin password reaches the Server only through auth.admin_pa in rest-server.properties (ServerOptions.java:483). HugeConfig loads that file with Configurations.properties() (HugeConfig.java:218), so the value goes through the properties grammar. The password the Server stores can then differ from the one the operator set.
Measured 2026-10-07 with commons-configuration2 2.10.1 (the version in hugegraph-commons/pom.xml), reading a file through new Configurations().properties(file):
| Written to the file |
Read back |
padded |
padded (trimmed) |
two\\back |
two\back (escape processed) |
x\ty |
x, a tab, y |
pässword (UTF-8 bytes) |
pässword (read as ISO-8859-1) |
The Docker entrypoint writes PASSWORD into this file (docker-entrypoint.sh:184), so PASSWORD=pässword creates an admin whose password is pässword.
Proposal, either of:
- Read the initial admin password from a source that is not parsed as properties, for example an environment variable or a file path read as raw UTF-8 (
auth.admin_pa_file), and keep auth.admin_pa for compatibility.
- Keep the file and document the contract: printable ASCII, no leading or trailing space, backslashes escaped.
The Helm chart refuses padded, backslash and non-ASCII admin passwords in values.schema.json:824 and its Server wrapper until this changes. The TODO at ServerOptions.java:483 (from #3260) points here.
Related: non-ASCII passwords also fail at Basic login, tracked separately in #3284. #3133 / #3192 cover the entrypoint's own escaping.
Not proposed for 1.8.0: the chart guard covers it, and option 1 adds a config surface.
Feature Description (功能描述)
The initial admin password reaches the Server only through
auth.admin_painrest-server.properties(ServerOptions.java:483).HugeConfigloads that file withConfigurations.properties()(HugeConfig.java:218), so the value goes through the properties grammar. The password the Server stores can then differ from the one the operator set.Measured 2026-10-07 with commons-configuration2 2.10.1 (the version in
hugegraph-commons/pom.xml), reading a file throughnew Configurations().properties(file):paddedpadded(trimmed)two\\backtwo\back(escape processed)x\tyx, a tab,ypässword(UTF-8 bytes)pässword(read as ISO-8859-1)The Docker entrypoint writes
PASSWORDinto this file (docker-entrypoint.sh:184), soPASSWORD=pässwordcreates an admin whose password ispässword.Proposal, either of:
auth.admin_pa_file), and keepauth.admin_pafor compatibility.The Helm chart refuses padded, backslash and non-ASCII admin passwords in
values.schema.json:824and its Server wrapper until this changes. The TODO atServerOptions.java:483(from #3260) points here.Related: non-ASCII passwords also fail at Basic login, tracked separately in #3284. #3133 / #3192 cover the entrypoint's own escaping.
Not proposed for 1.8.0: the chart guard covers it, and option 1 adds a config surface.