Anubhav Jindal has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24448 )

Change subject: IMPALA-14799: Add oauth_servers support and tests
......................................................................


Patch Set 20:

(1 comment)

Done

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc
File be/src/util/webserver.cc:

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc@777
PS18, Line 777:         const bool token_authenticated =
              :             OAuthTokenAuth(bearer_token, request_info, 
&response_headers);
              :         if (token_authenticated) {
              :           authenticated = true;
              :           check_csrf_protection = false;
              :           // Preserve existing JWT-first compatibility 
semantics when both modes
              :           // are enabled while avoiding duplicate token 
verification calls.
              :           if (use_jwt_) {
              :             total_jwt_token_auth_success_->Increment(1);
              :           } else if (use_oauth_) {
              :             total_oauth_token_auth_success_->Increment(1);
              :           }
              :           // TODO: cookies are not added, but are not needed 
right now
              :         } else if (use_jwt_) {
              :           LOG(INFO) << "Invalid JWT token provided";
              :           total_jwt_token_auth_failure_->Increment(1);
              :         } else if (use_oauth_) {
              :           LOG(INFO) << "Invalid OAuth token provided";
              :           total_oauth_token_auth_failure_->Increment(1);
              :         }
              :       }
              :     }
              :   }
              : 
              :   if (!authenticated && auth_mode_ == AuthMode::NONE) {
              :     // Wi
> I don't think we need to keep this two block structure just to preserve the
you’re absolutely right. In the both-enabled path we could end up calling 
OAuthTokenAuth() twice for the same bearer token, which is redundant and could 
duplicate the failure header. I updated the flow to call it once per request 
and then apply metrics/logging based on the compatibility-mode semantics



--
To view, visit http://gerrit.cloudera.org:8080/24448
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ib29ff36600406ba59c10f29d79cc632020f4a3f7
Gerrit-Change-Number: 24448
Gerrit-PatchSet: 20
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Tue, 25 Aug 2026 06:52:28 +0000
Gerrit-HasComments: Yes

Reply via email to