Zoltan Chovan has posted comments on this change. ( http://gerrit.cloudera.org:8080/24829 )
Change subject: [tests] Add proxy user integration coverage ...................................................................... Patch Set 1: (1 comment) http://gerrit.cloudera.org:8080/#/c/24829/1/src/kudu/integration-tests/security-itest.cc File src/kudu/integration-tests/security-itest.cc: http://gerrit.cloudera.org:8080/#/c/24829/1/src/kudu/integration-tests/security-itest.cc@398 PS1, Line 398: ASSERT_FALSE(s.ok()); I think this assertion is a bit weak. Any sort of problem would pass here, not just auth rejection. Using ASSERT_TRUE(s.IsNotAuthorized()) << s.ToString(); would match the convention established by previous tests. Also maybe using an effective user that is in --user_acl but not in --proxy_user_acl, would give a clearer view of the rejection's context. Since "proxy-denied" is in neither, the error could come from during negotiation (the proxy authoriser) or during operation, so the ValidateProxyUser is not the only gate that is being tested. -- To view, visit http://gerrit.cloudera.org:8080/24829 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: kudu Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: Ibe7178c9d659a9a0018f39c0d29258f5dc602a82 Gerrit-Change-Number: 24829 Gerrit-PatchSet: 1 Gerrit-Owner: mintao <[email protected]> Gerrit-Reviewer: Alexey Serbin <[email protected]> Gerrit-Reviewer: Kudu Jenkins (120) Gerrit-Reviewer: Zoltan Chovan <[email protected]> Gerrit-Comment-Date: Wed, 16 Sep 2026 11:40:37 +0000 Gerrit-HasComments: Yes
