Yida Wu has posted comments on this change. ( http://gerrit.cloudera.org:8080/24929 )
Change subject: IMPALA-15412: Fix Formatting of error_description in WWW-Authenticate Header ...................................................................... Patch Set 3: Code-Review+1 (1 comment) http://gerrit.cloudera.org:8080/#/c/24929/3/be/src/util/oauth-servers-manager.cc File be/src/util/oauth-servers-manager.cc: http://gerrit.cloudera.org:8080/#/c/24929/3/be/src/util/oauth-servers-manager.cc@39 PS3, Line 39: error_message Maybe out of scope for this PR, but do we worry about the error_message exposing some info in this header, like the raw claim values? For example in https://gerrit.cloudera.org/#/c/24472/10/be/src/util/jwt-util.cc L109: "return Status(TErrorCode::JWT_VERIFY_FAILED, Substitute("Claim '$0' value '$1' is not allowed", claim_name, claim_value.serialize()));". And we are not sure if future would be other error message from down there, I am thinking would it be safer to log the details in server side instead and return the error code or something static in the header? -- To view, visit http://gerrit.cloudera.org:8080/24929 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: Ifbb593c82afca89394560d21c5ad9a5c49ad2a53 Gerrit-Change-Number: 24929 Gerrit-PatchSet: 3 Gerrit-Owner: Jason Fehr <[email protected]> Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Reviewer: Joe McDonnell <[email protected]> Gerrit-Reviewer: Michael Smith <[email protected]> Gerrit-Reviewer: Yida Wu <[email protected]> Gerrit-Comment-Date: Wed, 30 Sep 2026 03:37:26 +0000 Gerrit-HasComments: Yes
