moresandeep commented on PR #1425:
URL: https://github.com/apache/knox/pull/1425#issuecomment-5814416491
> `HadoopAuthPostFilter` never captures the caller JWT; this feature
silently dead for topologies using the HadoopAuth filter.
>
> ```
> gateway-provider-security-hadoopauth/.../HadoopAuthPostFilter.java:91
> ```
>
> `doFilter()` still calls the public single-arg
createSubjectFromToken(String), which resolves to `createSubjectFromToken(JWT,
null)`. It was never updated to capture the caller's JWT as an
`AuthTokenCredential` the way `JWTFederationFilter.doFilter()` now does.
>
> **Impact**: On any topology using the `HadoopAuth` federation provider
with `support.jwt=true`, no `AuthTokenCredential` is ever added to the Subject,
so SubjectUtils.getAuthToken() returns null and the `X-Knox-Auth-Token` header
is never emitted, even though the same caller gets it on a
`JWTProvider`/`SSOCookieProvider` topology. The PR docs misattribute this to an
inherent "innermost Subject.doAs wins" quirk, when it's actually a one-line
oversight at this call site.
>
> I approve this PR now and file a follow-up JIRA to fill this gap.
You are right, I did not think about `HadoopAuth` path. My patch fixes it
for SSO Cookie and JWT Provider. For future reference (to me) this is
`HadoopAuth` where the gap is
```
<provider>
<role>authentication</role>
<name>HadoopAuth</name>
<enabled>true</enabled>
<param>
<name>config.prefix</name>
<value>hadoop.auth.config</value>
</param>
<param>
<name>hadoop.auth.config.type</name>
<value>simple</value>
</param>
<param>
<name>hadoop.auth.config.simple.anonymous.allowed</name>
<value>false</value>
</param>
<param>
<name>hadoop.auth.config.signature.secret</name>
<value>knox-signature-secret</value>
</param>
<!-- Routes Bearer JWTs to the inner JWTFederationFilter in both
HadoopAuthFilter and HadoopAuthPostFilter -->
<param>
<name>support.jwt</name>
<value>true</value>
</param>
</provider>
```
Looks like you created a JIRA for this
https://issues.apache.org/jira/browse/KNOX-3483
Thanks @smolnar82 !
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]