Zoltan Chovan has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24829 )

Change subject: [tests] Add proxy user integration coverage
......................................................................


Patch Set 1:

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24829/1/src/kudu/integration-tests/security-itest.cc
File src/kudu/integration-tests/security-itest.cc:

http://gerrit.cloudera.org:8080/#/c/24829/1/src/kudu/integration-tests/security-itest.cc@398
PS1, Line 398: ASSERT_FALSE(s.ok());
I think this assertion is a bit weak. Any sort of problem would pass here, not 
just auth rejection. Using ASSERT_TRUE(s.IsNotAuthorized()) << s.ToString(); 
would match the convention established by previous tests.

Also maybe using an effective user that is in --user_acl but not in 
--proxy_user_acl, would give a clearer view of the rejection's context. Since 
"proxy-denied" is in neither, the error could come from during negotiation (the 
proxy authoriser) or during operation, so the ValidateProxyUser is not the only 
gate that is being tested.



--
To view, visit http://gerrit.cloudera.org:8080/24829
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ibe7178c9d659a9a0018f39c0d29258f5dc602a82
Gerrit-Change-Number: 24829
Gerrit-PatchSet: 1
Gerrit-Owner: mintao <[email protected]>
Gerrit-Reviewer: Alexey Serbin <[email protected]>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Reviewer: Zoltan Chovan <[email protected]>
Gerrit-Comment-Date: Wed, 16 Sep 2026 11:40:37 +0000
Gerrit-HasComments: Yes

Reply via email to