[ 
https://issues.apache.org/jira/browse/KNOX-3478?focusedWorklogId=1043727&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1043727
 ]

ASF GitHub Bot logged work on KNOX-3478:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 24/Sep/26 12:48
            Start Date: 24/Sep/26 12:48
    Worklog Time Spent: 10m 
      Work Description: moresandeep commented on PR #1425:
URL: https://github.com/apache/knox/pull/1425#issuecomment-5814416491

   > `HadoopAuthPostFilter` never captures the caller JWT; this feature 
silently dead for topologies using the HadoopAuth filter.
   > 
   > ```
   > gateway-provider-security-hadoopauth/.../HadoopAuthPostFilter.java:91
   > ```
   > 
   > `doFilter()` still calls the public single-arg 
createSubjectFromToken(String), which resolves to `createSubjectFromToken(JWT, 
null)`. It was never updated to capture the caller's JWT as an 
`AuthTokenCredential` the way `JWTFederationFilter.doFilter()` now does.
   > 
   > **Impact**: On any topology using the `HadoopAuth` federation provider 
with `support.jwt=true`, no `AuthTokenCredential` is ever added to the Subject, 
so SubjectUtils.getAuthToken() returns null and the `X-Knox-Auth-Token` header 
is never emitted, even though the same caller gets it on a 
`JWTProvider`/`SSOCookieProvider` topology. The PR docs misattribute this to an 
inherent "innermost Subject.doAs wins" quirk, when it's actually a one-line 
oversight at this call site.
   > 
   > I approve this PR now and file a follow-up JIRA to fill this gap.
   
   You are right, I did not think about `HadoopAuth` path. My patch fixes it 
for SSO Cookie and JWT Provider. For future reference (to me) this is 
`HadoopAuth` where the gap is 
   ```
   <provider>
         <role>authentication</role>
         <name>HadoopAuth</name>
         <enabled>true</enabled>
         <param>
           <name>config.prefix</name>
           <value>hadoop.auth.config</value>
         </param>
         <param>
           <name>hadoop.auth.config.type</name>
           <value>simple</value>
         </param>
         <param>
           <name>hadoop.auth.config.simple.anonymous.allowed</name>
           <value>false</value>
         </param>
         <param>
           <name>hadoop.auth.config.signature.secret</name>
           <value>knox-signature-secret</value>
         </param>
         <!

Issue Time Tracking
-------------------

    Worklog Id:     (was: 1043727)
    Time Spent: 40m  (was: 0.5h)

> Extend auth service API to pass JWT token as header downstream
> --------------------------------------------------------------
>
>                 Key: KNOX-3478
>                 URL: https://issues.apache.org/jira/browse/KNOX-3478
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>            Reporter: Sandeep More
>            Assignee: Sandeep More
>            Priority: Major
>          Time Spent: 40m
>  Remaining Estimate: 0h
>
> There could be cases where we might need to pass user authenticated tokens to 
> be passed down to the downstream applications along side `
> preauth.auth.header.actor.id.name` and 
> `preauth.auth.header.actor.groups.prefix`



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to