[
https://issues.apache.org/jira/browse/KNOX-3478?focusedWorklogId=1043727&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1043727
]
ASF GitHub Bot logged work on KNOX-3478:
----------------------------------------
Author: ASF GitHub Bot
Created on: 24/Sep/26 12:48
Start Date: 24/Sep/26 12:48
Worklog Time Spent: 10m
Work Description: moresandeep commented on PR #1425:
URL: https://github.com/apache/knox/pull/1425#issuecomment-5814416491
> `HadoopAuthPostFilter` never captures the caller JWT; this feature
silently dead for topologies using the HadoopAuth filter.
>
> ```
> gateway-provider-security-hadoopauth/.../HadoopAuthPostFilter.java:91
> ```
>
> `doFilter()` still calls the public single-arg
createSubjectFromToken(String), which resolves to `createSubjectFromToken(JWT,
null)`. It was never updated to capture the caller's JWT as an
`AuthTokenCredential` the way `JWTFederationFilter.doFilter()` now does.
>
> **Impact**: On any topology using the `HadoopAuth` federation provider
with `support.jwt=true`, no `AuthTokenCredential` is ever added to the Subject,
so SubjectUtils.getAuthToken() returns null and the `X-Knox-Auth-Token` header
is never emitted, even though the same caller gets it on a
`JWTProvider`/`SSOCookieProvider` topology. The PR docs misattribute this to an
inherent "innermost Subject.doAs wins" quirk, when it's actually a one-line
oversight at this call site.
>
> I approve this PR now and file a follow-up JIRA to fill this gap.
You are right, I did not think about `HadoopAuth` path. My patch fixes it
for SSO Cookie and JWT Provider. For future reference (to me) this is
`HadoopAuth` where the gap is
```
<provider>
<role>authentication</role>
<name>HadoopAuth</name>
<enabled>true</enabled>
<param>
<name>config.prefix</name>
<value>hadoop.auth.config</value>
</param>
<param>
<name>hadoop.auth.config.type</name>
<value>simple</value>
</param>
<param>
<name>hadoop.auth.config.simple.anonymous.allowed</name>
<value>false</value>
</param>
<param>
<name>hadoop.auth.config.signature.secret</name>
<value>knox-signature-secret</value>
</param>
<!
Issue Time Tracking
-------------------
Worklog Id: (was: 1043727)
Time Spent: 40m (was: 0.5h)
> Extend auth service API to pass JWT token as header downstream
> --------------------------------------------------------------
>
> Key: KNOX-3478
> URL: https://issues.apache.org/jira/browse/KNOX-3478
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Reporter: Sandeep More
> Assignee: Sandeep More
> Priority: Major
> Time Spent: 40m
> Remaining Estimate: 0h
>
> There could be cases where we might need to pass user authenticated tokens to
> be passed down to the downstream applications along side `
> preauth.auth.header.actor.id.name` and
> `preauth.auth.header.actor.groups.prefix`
--
This message was sent by Atlassian Jira
(v8.20.10#820010)