Yida Wu has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24929 )

Change subject: IMPALA-15412: Fix Formatting of error_description in 
WWW-Authenticate Header
......................................................................


Patch Set 3: Code-Review+1

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24929/3/be/src/util/oauth-servers-manager.cc
File be/src/util/oauth-servers-manager.cc:

http://gerrit.cloudera.org:8080/#/c/24929/3/be/src/util/oauth-servers-manager.cc@39
PS3, Line 39: error_message
Maybe out of scope for this PR, but do we worry about the error_message 
exposing some info in this header, like the raw claim values? For example in 
https://gerrit.cloudera.org/#/c/24472/10/be/src/util/jwt-util.cc L109:
 "return Status(TErrorCode::JWT_VERIFY_FAILED, Substitute("Claim '$0' value 
'$1' is not allowed", claim_name, claim_value.serialize()));".
And we are not sure if future would be other error message from down there, I 
am thinking would it be safer to log the details in server side instead and 
return the error code or something static in the header?



--
To view, visit http://gerrit.cloudera.org:8080/24929
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ifbb593c82afca89394560d21c5ad9a5c49ad2a53
Gerrit-Change-Number: 24929
Gerrit-PatchSet: 3
Gerrit-Owner: Jason Fehr <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Joe McDonnell <[email protected]>
Gerrit-Reviewer: Michael Smith <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Wed, 30 Sep 2026 03:37:26 +0000
Gerrit-HasComments: Yes

Reply via email to