[ https://issues.apache.org/jira/browse/DRILL-8155?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17527577#comment-17527577 ]
ASF GitHub Bot commented on DRILL-8155: --------------------------------------- vvysotskyi commented on code in PR #2516: URL: https://github.com/apache/drill/pull/2516#discussion_r857767899 ########## contrib/storage-jdbc/src/main/java/org/apache/drill/exec/store/jdbc/JdbcConventionFactory.java: ########## @@ -0,0 +1,35 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.apache.drill.exec.store.jdbc; + +import org.apache.calcite.sql.SqlDialect; + +import java.util.Map; +import java.util.concurrent.ConcurrentHashMap; + +public class JdbcConventionFactory { + + private final Map<SqlDialect, DrillJdbcConvention> CACHE = new ConcurrentHashMap<>(); Review Comment: Yes, it would be also nice to have an expiry time on it > Introduce new plugin authentication modes > ----------------------------------------- > > Key: DRILL-8155 > URL: https://issues.apache.org/jira/browse/DRILL-8155 > Project: Apache Drill > Issue Type: Improvement > Components: Security > Affects Versions: 1.20.0 > Reporter: Charles Givre > Assignee: Charles Givre > Priority: Major > Fix For: Future > > > At present, Drill storage plugins can use a shared set of credentials to > access storage on behalf of Drill users or, in a subset of cases belonging to > the broader Hadoop family, they can impersonate the Drill user when > drill.exec.impersonation.enabled = true. An important but missing auth mode > is [what is termed "user translation" in > Trino|[https://docs.starburst.io/latest/security/impersonation.html].] Under > user translation, the active Drill user is translated to a user known to the > external storage by means of a translation table that associates Drill users > with their credentials for the external storage. No support for user > impersonation in the external storage is required in this mode. This ticket > proposes that we add establish a design pattern that adds support for this > auth mode to Drill storage plugins. > Another present day limitation is that impersonation, for the plugins that > support it, is toggled by a global switch. We propose here that the auth > mode chosen for a plugin should be independent of the auth modes chosen for > other plugins, by a move of this option into their respective storage configs. > Finally, while a standardised means of choosing an authentication mode is > desired, note that not every storage plugin needs to, or can, support every > mode. -- This message was sent by Atlassian Jira (v8.20.7#820007)