Yida Wu has posted comments on this change. ( http://gerrit.cloudera.org:8080/24448 )
Change subject: IMPALA-14799: Add oauth_servers support and tests ...................................................................... Patch Set 19: (1 comment) http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc File be/src/util/webserver.cc: http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc@777 PS18, Line 777: if (use_jwt_) { : if (OAuthTokenAuth(bearer_token, request_info, &response_headers)) { : total_jwt_token_auth_success_->Increment(1); : authenticated = true; : check_csrf_protection = false; : // TODO: cookies are not added, but are not needed right now : } : } : if (!authenticated && use_oauth_) { : if (OAuthTokenAuth(bearer_token, request_info, &response_headers)) { : total_oauth_token_auth_success_->Increment(1); : authenticated = true; : check_csrf_protection = false; : // TODO: cookies are not added, but are not needed right now : } : } : if (!authenticated) { : if (use_jwt_) { : LOG(INFO) << "Invalid JWT token provided"; : total_jwt_token_auth_failure_->Increment(1); : } : if (use_oauth_) { : LOG(INFO) << "Invalid OAuth token provided"; : total_oauth_token_auth_failure_->Increment(1); : } : } > Good point. Your understanding is correct that, with unified OAuthServersMa I don't think we need to keep this two block structure just to preserve the order the metric counters. Consider what happens on a failing token when both flags are set, the use_jwt_ block runs OAuthTokenAuth(). It fails, authenticated stays false, so we fall into the use_oauth_ block and call OAuthTokenAuth() again on the exact same token. Since the function doesn't know which mode is calling it, it just fails the same check a second time. And not only this, I think it may also push a second WWW-Authenticate header onto the response, so the client receives a duplicate header on every failed request when both flags are enabled. -- To view, visit http://gerrit.cloudera.org:8080/24448 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: Ib29ff36600406ba59c10f29d79cc632020f4a3f7 Gerrit-Change-Number: 24448 Gerrit-PatchSet: 19 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Reviewer: Yida Wu <[email protected]> Gerrit-Comment-Date: Tue, 25 Aug 2026 06:21:29 +0000 Gerrit-HasComments: Yes
