Jose Luis López created HADOOP-20003:
----------------------------------------

             Summary: Clients shall read an HTTP refusal's reason from the 
response body
                 Key: HADOOP-20003
                 URL: https://issues.apache.org/jira/browse/HADOOP-20003
             Project: Hadoop Common
          Issue Type: Sub-task
          Components: common, hadoop-auth, hdfs-client, kms
            Reporter: Jose Luis López


Several Hadoop clients take the reason a server refused a request from the HTTP 
reason phrase ({{HttpURLConnection#getResponseMessage()}}). The same text is 
also in the response body: {{sendError}} writes it into the error page's 
MESSAGE row, which looks the same on Jetty 9.4 and on Jetty 12. Jetty 12 sends 
no custom reason phrase (HADOOP-19972), so these clients would only see the 
standard text, e.g. "Unauthorized" instead of "Authentication required".

h3. Changes
* New {{ResponseDetail}} in hadoop-auth ({{@InterfaceAudience.Private}}) reads 
a capped amount of the error body. It returns the MESSAGE row of a Jetty error 
page, or the text of any other page with the markup stripped. It falls back to 
the phrase when there is no body. A JSON error envelope is left alone, and its 
phrase is reported, because that envelope is sent with {{setStatus}}, not 
{{sendError}}.
* {{AuthenticatedURL}} and {{HttpExceptionUtils#validateResponse}} use it to 
report failures.
* {{WebHdfsFileSystem}} uses it for a 401 and the neighbouring error arms.
* {{KMSClientProvider}} uses it to decide whether to reset its token and 
re-authenticate. That decision matches on "Invalid signature" and "Anonymous 
requests are disallowed", which would never match the standard phrase.

h3. Compatibility
No change against Jetty 9.4 servers: the MESSAGE row holds exactly the text the 
phrase carried.

h3. Tests
{{TestHttpExceptionUtils}} and {{TestAuthenticatedURL}} cover the body and 
fallback cases. A new {{TestKMS}} case covers the re-authentication retry.

h3. Not in scope
{{NetworkTopologyServlet}} loses its reason on Jetty 9.4 too (a failed dump 
answers 200). That needs its own JIRA.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to