Audit.metadata causing null pointer exception on login

when setting

audit.metadata =CREATE;UPDATE;DELETE;READ

I’m getting this

core_1  | SEVERE: Servlet.service() for servlet [default] in context with path [] threw exception
core_1  | java.lang.NullPointerException
core_1  | 	at org.hisp.dhis.user.UserCredentials.hashCode(UserCredentials.java:508)
core_1  | 	at java.util.HashMap.hash(HashMap.java:340)
core_1  | 	at java.util.HashMap.readObject(HashMap.java:1419)
core_1  | 	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
core_1  | 	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
core_1  | 	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
core_1  | 	at java.lang.reflect.Method.invoke(Method.java:498)
core_1  | 	at java.io.ObjectStreamClass.invokeReadObject(ObjectStreamClass.java:1184)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2296)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.defaultReadFields(ObjectInputStream.java:2405)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2329)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.defaultReadFields(ObjectInputStream.java:2405)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2329)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.readObject(ObjectInputStream.java:503)
core_1  | 	at java.io.ObjectInputStream.readObject(ObjectInputStream.java:461)
core_1  | 	at java.util.HashMap.readObject(HashMap.java:1416)
core_1  | 	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
core_1  | 	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
core_1  | 	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
core_1  | 	at java.lang.reflect.Method.invoke(Method.java:498)
core_1  | 	at java.io.ObjectStreamClass.invokeReadObject(ObjectStreamClass.java:1184)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2296)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.defaultReadFields(ObjectInputStream.java:2405)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2329)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.defaultReadFields(ObjectInputStream.java:2405)
core_1  | 	at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:2329)
core_1  | 	at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:2187)
core_1  | 	at java.io.ObjectInputStream.readObject0(ObjectInputStream.java:1667)
core_1  | 	at java.io.ObjectInputStream.readObject(ObjectInputStream.java:503)
core_1  | 	at java.io.ObjectInputStream.readObject(ObjectInputStream.java:461)
core_1  | 	at org.apache.commons.lang3.SerializationUtils.clone(SerializationUtils.java:92)
core_1  | 	at org.hisp.dhis.security.spring2fa.TwoFactorAuthenticationProvider.authenticate(TwoFactorAuthenticationProvider.java:142)
core_1  | 	at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:182)
core_1  | 	at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:201)
core_1  | 	at org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter.attemptAuthentication(UsernamePasswordAuthenticationFilter.java:85)
core_1  | 	at org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter.doFilter(AbstractAuthenticationProcessingFilter.java:222)
core_1  | 	at org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter.doFilter(AbstractAuthenticationProcessingFilter.java:212)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.hisp.dhis.webapi.filter.CustomAuthenticationFilter.doFilter(CustomAuthenticationFilter.java:93)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.springframework.security.web.authentication.logout.LogoutFilter.doFilter(LogoutFilter.java:103)
core_1  | 	at org.springframework.security.web.authentication.logout.LogoutFilter.doFilter(LogoutFilter.java:89)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.springframework.security.web.header.HeaderWriterFilter.doHeadersAfter(HeaderWriterFilter.java:90)
core_1  | 	at org.springframework.security.web.header.HeaderWriterFilter.doFilterInternal(HeaderWriterFilter.java:75)
core_1  | 	at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:110)
core_1  | 	at org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:80)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter.doFilterInternal(WebAsyncManagerIntegrationFilter.java:55)
core_1  | 	at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
core_1  | 	at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:336)
core_1  | 	at org.springframework.security.web.FilterChainProxy.doFilterInternal(FilterChainProxy.java:211)
core_1  | 	at org.springframework.security.web.FilterChainProxy.doFilter(FilterChainProxy.java:183)
core_1  | 	at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:358)
core_1  | 	at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:271)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
core_1  | 	at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201)
core_1  | 	at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
core_1  | 	at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:358)
core_1  | 	at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:271)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
core_1  | 	at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201)
core_1  | 	at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
core_1  | 	at org.springframework.orm.hibernate5.support.OpenSessionInViewFilter.doFilterInternal(OpenSessionInViewFilter.java:156)
core_1  | 	at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
core_1  | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
core_1  | 	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:199)
core_1  | 	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)
core_1  | 	at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:543)
core_1  | 	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)
core_1  | 	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81)
core_1  | 	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)
core_1  | 	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)
core_1  | 	at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:609)
core_1  | 	at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)
core_1  | 	at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:818)
core_1  | 	at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1623)
core_1  | 	at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
core_1  | 	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
core_1  | 	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
core_1  | 	at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
core_1  | 	at java.lang.Thread.run(Thread.java:748)

and the dashboard doesn’t show up

removing the READ in the matrix seem to solve the issue

CREATE;UPDATE;DELETE
1 Like

Thanks for reporting this! What is the version of dhis2 instance that you are using?

What about audit.scope? What’s the setting when the audit.metadata is CREATE;UPDATE;DELETE;READ ?

The docs does give a warning:

But would you be able to share the full Catalina.out log (without the sensitive info) to make sure we’ve got enough info.

BTW, you could check out the API audits as well: Visualizations - DHIS2 Documentation