Gabriella Lotz has posted comments on this change. ( http://gerrit.cloudera.org:8080/24864 )
Change subject: Require authentication for REST catalog DDL ...................................................................... Patch Set 2: (2 comments) > Patch Set 1: > > (2 comments) > > Test coverage gaps: > - The new validator branch (master.cc:188) has no test: a short negative > startup test asserting the master refuses to start with > --enable_rest_api=true and no SPNEGO / password-file / anonymous flag. > - No coverage for the password-file path. A test that password-file auth is > accepted for POST but behaves correctly for PUT/DELETE would have surfaced > the gap above. I have added RestApiFlagValidatorTest.RejectsUnsafeCombinations covering the flag combinations. To make the validator reachable from a test I moved ValidateRestApiFlag out of the anonymous namespace into kudu::master. http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/master.cc File src/kudu/master/master.cc: http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/master.cc@188 PS1, Line 188: // squeasel as global_auth_file, which squeasel consults only for > The validator treats --webserver_password_file as a sufficient auth mode fo You're right. I've dropped --webserver_password_file from the validator, so SPNEGO is the only accepted auth mode now. Because we serve our handlers from squeasel's begin_request callback, its is_authorized_for_put check never runs for our paths, so password-file auth left PUT and DELETE unauthenticated rather than blocked. Same conclusion either way, and I've written the reasoning into a comment on the validator so it doesn't get re-added. http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/rest_catalog_path_handlers.cc File src/kudu/master/rest_catalog_path_handlers.cc: http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/rest_catalog_path_handlers.cc@413 PS1, Line 413: PrintTableObject(output, table_id, status_code); > The comment says setting the success code before PrintTableObject lets "a c Good catch, thanks. I have added an explicit null check returning 404 before taking the lock. I haven't added a test for it: forcing a delete between the dispatcher's lookup and the one in PrintTableObject would need a fault-injection hook that doesn't exist on this path. -- To view, visit http://gerrit.cloudera.org:8080/24864 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: kudu Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: Ib0112638a3462c84e6366b881c9229a334ad3c25 Gerrit-Change-Number: 24864 Gerrit-PatchSet: 2 Gerrit-Owner: Gabriella Lotz <[email protected]> Gerrit-Reviewer: Attila Bukor <[email protected]> Gerrit-Reviewer: Gabriella Lotz <[email protected]> Gerrit-Reviewer: Kudu Jenkins (120) Gerrit-Reviewer: Marton Greber <[email protected]> Gerrit-Comment-Date: Tue, 22 Sep 2026 09:31:35 +0000 Gerrit-HasComments: Yes
