Anubhav Jindal has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24448 )

Change subject: IMPALA-14799: Add oauth_servers support and tests
......................................................................


Patch Set 19:

(1 comment)

Done

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc
File be/src/util/webserver.cc:

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc@777
PS18, Line 777:         if (use_jwt_) {
              :           if (OAuthTokenAuth(bearer_token, request_info, 
&response_headers)) {
              :             total_jwt_token_auth_success_->Increment(1);
              :             authenticated = true;
              :             check_csrf_protection = false;
              :             // TODO: cookies are not added, but are not needed 
right now
              :           }
              :         }
              :         if (!authenticated && use_oauth_) {
              :           if (OAuthTokenAuth(bearer_token, request_info, 
&response_headers)) {
              :             total_oauth_token_auth_success_->Increment(1);
              :             authenticated = true;
              :             check_csrf_protection = false;
              :             // TODO: cookies are not added, but are not needed 
right now
              :           }
              :         }
              :         if (!authenticated) {
              :           if (use_jwt_) {
              :             LOG(INFO) << "Invalid JWT token provided";
              :             total_jwt_token_auth_failure_->Increment(1);
              :           }
              :           if (use_oauth_) {
              :             LOG(INFO) << "Invalid OAuth token provided";
              :             total_oauth_token_auth_failure_->Increment(1);
              :           }
              :         }
> Since OAuthTokenAuth() now verifies the token against the unified OAuthServ
Good question. In the current flow, if both are enabled we intentionally treat 
them as compatibility modes and apply precedence in the caller: JWT path is 
attempted first, then OAuth as fallback if JWT path does not authenticate. So 
the counters/logs reflect the path semantics in this block (JWT-first then 
OAuth fallback), not the exact internal OAuthServersManager config identity. 
Returning exact server/config provenance would require extending the auth API 
and is out of scope for this change.



--
To view, visit http://gerrit.cloudera.org:8080/24448
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ib29ff36600406ba59c10f29d79cc632020f4a3f7
Gerrit-Change-Number: 24448
Gerrit-PatchSet: 19
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Mon, 24 Aug 2026 07:38:27 +0000
Gerrit-HasComments: Yes

Reply via email to