Hi all,

While reviewing #5119 <https://github.com/apache/polaris/pull/5119>, I
found the authentication flow a little confusing:

   -

   InternalIdentityProvider and OidcPolarisCredentialAugmentor both attach
   a PolarisCredential to the identity, for their respective authentication
   paths.
   -

   AuthenticatingAugmentor then consumes that credential to produce a
   PolarisPrincipal.

Logically, the first two are source-specific preparation steps, followed by
a shared authentication step. But the OIDC preparation and shared
authentication steps both implement SecurityIdentityAugmentor. Their
dependency is hidden in priorities and the credential passed through
SecurityIdentity, rather than expressed as a direct call.

Could we turn OidcPolarisCredentialAugmentor into a regular CDI component
and have AuthenticatingAugmentor call it explicitly first, then call
authenticator.authenticate(identity)? Internal authentication would skip
that mapping because its credential is already present.

Do downstream extensions rely on running between these two augmentors?
Otherwise,
would this make the flow clearer?

To be clear, this is not a blocker for PR 5119.
Yufei

Reply via email to