Skip to content

[fix][broker] Apply the role logging anonymizer to topic authorization denial logs - #26642

Merged
lhotari merged 2 commits into
apache:masterfrom
KannarFr:fix/anonymize-denial-log-roles
Sep 19, 2026
Merged

lhotari merged 2 commits into
apache:masterfrom
KannarFr:fix/anonymize-denial-log-roles

Conversation

@KannarFr

Copy link
Copy Markdown
Contributor

Motivation

PIP-402 added authenticationRoleLoggingAnonymizer so operators can keep roles out of broker logs.
The warning ServerCnx.isTopicOperationAllowed logs when a topic operation is not allowed still
printed authRole and originalPrincipal as is.

DefaultAuthenticationRoleLoggingAnonymizer.anonymize(null) also failed with the SHA256 and MD5
anonymizers, while originalPrincipal is null for every client that does not connect through a proxy.

Modifications

  • Pass authRole and originalPrincipal through the anonymizer in the topic authorization denial log.
  • Return null from DefaultAuthenticationRoleLoggingAnonymizer.anonymize for a null role.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • Added DefaultAuthenticationRoleLoggingAnonymizerTest, covering a null role for every anonymizer
    type and the anonymized value of a role.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

🤖 Generated with Claude Code

KannarFr and others added 2 commits September 18, 2026 11:38
…n denial logs

The warning logged when a topic operation is not allowed printed authRole and
originalPrincipal without going through authenticationRoleLoggingAnonymizer,
unlike the other role logs in ServerCnx.

DefaultAuthenticationRoleLoggingAnonymizer.anonymize now accepts a null role.
originalPrincipal is null for clients that do not connect through a proxy, and
the SHA256 and MD5 anonymizers failed on it.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@lhotari
lhotari merged commit 03174f6 into apache:master Sep 19, 2026
43 checks passed
@lhotari lhotari added this to the 5.0.0 milestone Sep 23, 2026
lhotari pushed a commit that referenced this pull request Sep 23, 2026
…n denial logs (#26642)

Apply the configured role logging anonymizer consistently to topic authorization denial logs.

(cherry picked from commit 03174f6)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants