gp1314 opened a new pull request, #8763:
URL: https://github.com/apache/hadoop/pull/8763
…cipal
<!--
Thanks for sending a pull request!
1. If this is your first time, please read our contributor guidelines:
https://cwiki.apache.org/confluence/display/HADOOP/How+To+Contribute
2. Make sure your PR title starts with JIRA issue id, e.g.,
'HADOOP-17799. Your PR title ...'.
-->
### Description of PR
Supersedes #6326, which was closed by the stale bot.
Fix secure QJM edit-log fetch authorization when standard SPNEGO exposes a
short remote user but a full Kerberos principal.
HDFS-16686 moved this path to `DfsServlet`/`JspHelper`.
`JspHelper#getUGI` used `request.getRemoteUser()`, which can be a short name
under the authentication filter. The JournalNode allow-list uses full
NameNode Kerberos principals, so a valid NameNode request to `/getJournal`
can be rejected with HTTP 403.
Prefer `request.getUserPrincipal().getName()` when available, retaining
`getRemoteUser()` as a fallback.
JIRA: https://issues.apache.org/jira/browse/HDFS-17276
Contains content generated by Codex.
### How was this patch tested?
- `git diff --check`
- Not run locally because the test environment is unavailable.
- GitHub Actions will run for this PR.
### For code changes:
- [x] Does the title of this PR start with the corresponding JIRA issue id?
- [x] Object storage integration tests: not applicable.
- [x] No dependencies were added.
- [x] No `LICENSE`, `LICENSE-binary`, or `NOTICE-binary` updates are
applicable.
### AI Tooling
- [x] The PR includes the phrase "Contains content generated by Codex".
- [ ] My use of AI contributions follows the ASF legal policy:
https://www.apache.org/legal/generative-tooling.html
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]