Hi all, While reviewing #5119 <https://github.com/apache/polaris/pull/5119>, I found the authentication flow a little confusing:
- InternalIdentityProvider and OidcPolarisCredentialAugmentor both attach a PolarisCredential to the identity, for their respective authentication paths. - AuthenticatingAugmentor then consumes that credential to produce a PolarisPrincipal. Logically, the first two are source-specific preparation steps, followed by a shared authentication step. But the OIDC preparation and shared authentication steps both implement SecurityIdentityAugmentor. Their dependency is hidden in priorities and the credential passed through SecurityIdentity, rather than expressed as a direct call. Could we turn OidcPolarisCredentialAugmentor into a regular CDI component and have AuthenticatingAugmentor call it explicitly first, then call authenticator.authenticate(identity)? Internal authentication would skip that mapping because its credential is already present. Do downstream extensions rely on running between these two augmentors? Otherwise, would this make the flow clearer? To be clear, this is not a blocker for PR 5119. Yufei
