This is an automated email from the ASF dual-hosted git repository.
jerryshao pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/main by this push:
new 5b1e3d792a [#13472] docs(trino-connector): Document authType=basic
forwardUser limitation (#13473)
5b1e3d792a is described below
commit 5b1e3d792a3dbb54fc673009d020d219501d9ee8
Author: Yuhui <[email protected]>
AuthorDate: Wed Sep 23 18:21:10 2026 +0800
[#13472] docs(trino-connector): Document authType=basic forwardUser
limitation (#13473)
### What changes were proposed in this pull request?
Documents that `gravitino.client.session.forwardUser` does not support
`authType=basic`, and explains why.
### Why are the changes needed?
`authType=basic` requires a real password, but Trino's SPI does not
propagate the session user's password to connectors after
coordinator-side authentication, so it cannot support forwardUser like
`simple`/`oauth2` do. Without this note, users may assume `basic`
behaves the same as the other auth types and be surprised that every
Trino query is authorized as the connector's fixed configured user
rather than the individual session user.
Fix: #13472
### Does this PR introduce any user-facing change?
Documentation only — no code change.
### How was this patch tested?
Docs-only change; no tests required.
Co-authored-by: Claude Sonnet 5 <[email protected]>
---
docs/trino-connector/authentication.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/docs/trino-connector/authentication.md
b/docs/trino-connector/authentication.md
index d95c926c1b..6f44668034 100644
--- a/docs/trino-connector/authentication.md
+++ b/docs/trino-connector/authentication.md
@@ -156,6 +156,8 @@
gravitino.client.kerberos.keytabFilePath=/path/to/user.keytab
Setting `gravitino.client.session.forwardUser=true` creates a dedicated
Gravitino client per Trino session user, so each user is visible in the
Gravitino audit log instead of the shared `gravitino.user` or service identity.
It is supported with `authType=simple` and `authType=oauth2`. For OAuth2
sessions without a forwarded token, the connector reuses the shared service
metadata instead.
+`authType=basic` does not support forwarding, and setting `forwardUser=true`
with `authType=basic` fails at connector startup — Trino's SPI does not
propagate the session user's password to connectors after coordinator-side
authentication, so there is no credential to forward. With `authType=basic`,
every Trino query is authorized against Gravitino as the configured
`gravitino.client.basic.username`, not the individual Trino session user;
Gravitino-side per-user authorization (e.g. table [...]
+
**Configuration (`authType=simple`):**
```properties