ccoliu opened a new pull request, #74085: URL: https://github.com/apache/airflow/pull/74085
Starting with `trino` 0.339.0, the Python client refuses to send credentials over plain HTTP (`TrinoAuthError: TLS/SSL is required for authentication`). `trino` 0.340.0 added an `allow_insecure_auth` parameter for setups where the connection is encrypted below the application layer (e.g. an mTLS service-mesh sidecar such as Istio), but `TrinoHook` had no way to pass it, so password auth over `http` (including the UI "Test connection" button) could not work. This adds an opt-in `allow_insecure_auth` connection extra (default `false`). It is only passed to `trino.dbapi.connect()` when enabled, so behavior is unchanged for everyone else and older `trino` versions without the parameter keep working. It is deliberately not enabled by default, since that would allow credentials to be sent in cleartext. Verified against the real client (not mocked), basic auth over `http`: | trino | extra not set | `allow_insecure_auth: true` | |---|---|---| | 0.339.0 | `TrinoAuthError` | `TypeError` (param not supported; docs note `trino>=0.340.0` is required) | | 0.340.0 | `TrinoAuthError` (secure default kept) | connection created | Tests: added `test_get_conn_allow_insecure_auth` covering unset / false / true (bool and string). The `true` cases fail without the fix. Docs: documented the new extra in `connections.rst`. closes: #74080 --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes (please specify the tool below) Generated-by: Claude Code (Claude Opus 5.5) following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
