Skip to content

Avoid duplicate preemptive Digest hashing#2276

Merged
hyperxpro merged 1 commit into
AsyncHttpClient:mainfrom
maygemdev:perf/preemptive-digest-ha1
Jul 23, 2026
Merged

Avoid duplicate preemptive Digest hashing#2276
hyperxpro merged 1 commit into
AsyncHttpClient:mainfrom
maygemdev:perf/preemptive-digest-ha1

Conversation

@pavel-ptashyts

Copy link
Copy Markdown
Contributor

Summary

  • pass the auth-int entity-body hash to the request-specific Realm.Builder
  • build the preemptive Digest realm once for origin and proxy authentication
  • remove the duplicate digest-response implementation that was recalculating HA1 and whose result was overwritten by the final build
  • verify the emitted origin and proxy responses against an independent MD5 calculation

This follows the entity-body-hash flow already used by the 401 and 407 interceptors. It does not modify Realm.java, so it remains compatible with #2269.

Verification

  • ./mvnw -pl client -Dtest=org.asynchttpclient.util.AuthenticatorUtilsTest,org.asynchttpclient.RealmTest,org.asynchttpclient.DigestAuthTest,org.asynchttpclient.DigestAuthRfc7616Test test (53 tests passed)
  • ./mvnw -B -ntp -pl client -DskipTests -Dmaven.javadoc.skip=true -Dgpg.skip=true verify (Revapi passed)

The full JDK 11 ./mvnw clean verify gate was not run because this environment provides JDK 21 only.

Codex on behalf of Pavel Ptashyts

Preemptive auth-int built temporary Realm objects and recalculated
HA1 before rebuilding the realm again. The final build also
overwrote the response that included the request body.

Pass the entity-body hash to the request-specific realm builder and
build it once for both origin and proxy authentication. Remove the
duplicate digest calculation path and verify the emitted response
independently.

Codex on behalf of Pavel Ptashyts

Co-Authored-By: Codex <codex@openai.com>
@hyperxpro
hyperxpro merged commit 9a8122d into AsyncHttpClient:main Jul 23, 2026
13 checks passed
@pavel-ptashyts
pavel-ptashyts deleted the perf/preemptive-digest-ha1 branch July 24, 2026 05:13
hyperxpro pushed a commit that referenced this pull request Jul 25, 2026
Realm.Builder.ha2 writes A2 into the recycled StringBuilder that
newResponse took from StringBuilderPool, but on the auth-int branch with
no precomputed entity-body hash it called StringUtils.toHexString, which
takes that same thread-local builder and resets it. The "POST:/secret:"
already written was discarded and A2 came out as the empty-body hash
twice, so the Digest response no longer bound the request method or the
target URI. Appending with appendBase16 keeps the hash in the buffer
already being built, which is what ha1 and newResponse already do for
HA1 and HA2. The two encoders emit identical lowercase, zero-padded hex,
so the digest is unchanged everywhere the branch was already correct.

Latent since #2148 replaced the EMPTY_ENTITY_MD5 constant with a
computed hash. The null-entityBodyHash branch is no longer reachable
from the request pipeline: #2276 wired setEntityBodyHash into
perRequestAuthorizationHeader and computeBodyHash never returns null, so
no wrong header reaches the wire today. It is still reached by the
nextnonce rotation in Interceptors and by Realms built through the
public API. The added RealmTest case checks the response against the
RFC 7616 A2 and fails on the current code.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants