moresandeep commented on PR #1425:
URL: https://github.com/apache/knox/pull/1425#issuecomment-5814416491

   > `HadoopAuthPostFilter` never captures the caller JWT; this feature 
silently dead for topologies using the HadoopAuth filter.
   > 
   > ```
   > gateway-provider-security-hadoopauth/.../HadoopAuthPostFilter.java:91
   > ```
   > 
   > `doFilter()` still calls the public single-arg 
createSubjectFromToken(String), which resolves to `createSubjectFromToken(JWT, 
null)`. It was never updated to capture the caller's JWT as an 
`AuthTokenCredential` the way `JWTFederationFilter.doFilter()` now does.
   > 
   > **Impact**: On any topology using the `HadoopAuth` federation provider 
with `support.jwt=true`, no `AuthTokenCredential` is ever added to the Subject, 
so SubjectUtils.getAuthToken() returns null and the `X-Knox-Auth-Token` header 
is never emitted, even though the same caller gets it on a 
`JWTProvider`/`SSOCookieProvider` topology. The PR docs misattribute this to an 
inherent "innermost Subject.doAs wins" quirk, when it's actually a one-line 
oversight at this call site.
   > 
   > I approve this PR now and file a follow-up JIRA to fill this gap.
   
   You are right, I did not think about `HadoopAuth` path. My patch fixes it 
for SSO Cookie and JWT Provider. For future reference (to me) this is 
`HadoopAuth` where the gap is 
   ```
   <provider>
         <role>authentication</role>
         <name>HadoopAuth</name>
         <enabled>true</enabled>
         <param>
           <name>config.prefix</name>
           <value>hadoop.auth.config</value>
         </param>
         <param>
           <name>hadoop.auth.config.type</name>
           <value>simple</value>
         </param>
         <param>
           <name>hadoop.auth.config.simple.anonymous.allowed</name>
           <value>false</value>
         </param>
         <param>
           <name>hadoop.auth.config.signature.secret</name>
           <value>knox-signature-secret</value>
         </param>
         <!-- Routes Bearer JWTs to the inner JWTFederationFilter in both 
HadoopAuthFilter and HadoopAuthPostFilter -->
         <param>
           <name>support.jwt</name>
           <value>true</value>
         </param>
       </provider>
   ```
   Looks like you created a JIRA for this 
https://issues.apache.org/jira/browse/KNOX-3483 
   Thanks @smolnar82 !


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to