ccoliu opened a new pull request, #74085:
URL: https://github.com/apache/airflow/pull/74085

   Starting with `trino` 0.339.0, the Python client refuses to send credentials 
over plain HTTP (`TrinoAuthError: TLS/SSL is required for authentication`). 
`trino` 0.340.0 added an `allow_insecure_auth` parameter for setups where the 
connection is encrypted below the application layer (e.g. an mTLS service-mesh 
sidecar such as Istio), but `TrinoHook` had no way to pass it, so password auth 
over `http` (including the UI "Test connection" button) could not work.
   
   This adds an opt-in `allow_insecure_auth` connection extra (default 
`false`). It is only passed to `trino.dbapi.connect()` when enabled, so 
behavior is unchanged for everyone else and older `trino` versions without the 
parameter keep working. It is deliberately not enabled by default, since that 
would allow credentials to be sent in cleartext.
   
   Verified against the real client (not mocked), basic auth over `http`:
   
   | trino | extra not set | `allow_insecure_auth: true` |
   |---|---|---|
   | 0.339.0 | `TrinoAuthError` | `TypeError` (param not supported; docs note 
`trino>=0.340.0` is required) |
   | 0.340.0 | `TrinoAuthError` (secure default kept) | connection created |
   
   Tests: added `test_get_conn_allow_insecure_auth` covering unset / false / 
true (bool and string). The `true` cases fail without the fix. Docs: documented 
the new extra in `connections.rst`.
   
   closes: #74080
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes (please specify the tool below)
   
   Generated-by: Claude Code (Claude Opus 5.5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to