Jose Luis López created HADOOP-20003:
----------------------------------------
Summary: Clients shall read an HTTP refusal's reason from the
response body
Key: HADOOP-20003
URL: https://issues.apache.org/jira/browse/HADOOP-20003
Project: Hadoop Common
Issue Type: Sub-task
Components: common, hadoop-auth, hdfs-client, kms
Reporter: Jose Luis López
Several Hadoop clients take the reason a server refused a request from the HTTP
reason phrase ({{HttpURLConnection#getResponseMessage()}}). The same text is
also in the response body: {{sendError}} writes it into the error page's
MESSAGE row, which looks the same on Jetty 9.4 and on Jetty 12. Jetty 12 sends
no custom reason phrase (HADOOP-19972), so these clients would only see the
standard text, e.g. "Unauthorized" instead of "Authentication required".
h3. Changes
* New {{ResponseDetail}} in hadoop-auth ({{@InterfaceAudience.Private}}) reads
a capped amount of the error body. It returns the MESSAGE row of a Jetty error
page, or the text of any other page with the markup stripped. It falls back to
the phrase when there is no body. A JSON error envelope is left alone, and its
phrase is reported, because that envelope is sent with {{setStatus}}, not
{{sendError}}.
* {{AuthenticatedURL}} and {{HttpExceptionUtils#validateResponse}} use it to
report failures.
* {{WebHdfsFileSystem}} uses it for a 401 and the neighbouring error arms.
* {{KMSClientProvider}} uses it to decide whether to reset its token and
re-authenticate. That decision matches on "Invalid signature" and "Anonymous
requests are disallowed", which would never match the standard phrase.
h3. Compatibility
No change against Jetty 9.4 servers: the MESSAGE row holds exactly the text the
phrase carried.
h3. Tests
{{TestHttpExceptionUtils}} and {{TestAuthenticatedURL}} cover the body and
fallback cases. A new {{TestKMS}} case covers the re-authentication retry.
h3. Not in scope
{{NetworkTopologyServlet}} loses its reason on Jetty 9.4 too (a failed dump
answers 200). That needs its own JIRA.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]