bhor-sanket opened a new pull request, #775: URL: https://github.com/apache/atlas/pull/775
## What changes were proposed in this pull request?
### Background
In header-based authentication environments (e.g., UDF/Trino deployments
behind a trusted proxy), an external gateway injects authentication headers
`(x-awc-username, x-awc-userroles, x-awc-requestid)` into requests before they
reach Atlas. The Atlas server already supports this model via
`AtlasHeaderPreAuthFilter`, which creates an `AtlasAuthenticationToken` with
`AUTH_TYPE_TRUSTED_PROXY` when the appropriate headers are present.
The trino-atlas plugin uses the REST notification channel (RestNotification)
to send hook notifications to Atlas. In header-auth environments, client-side
authentication (Basic Auth or Kerberos) is unnecessary and counterproductive —
the gateway handles auth.
#### Problem Statement
- **Existing behavior:** RestNotification.setupAtlasClientV2() has only
two auth paths: Basic Auth (when Kerberos is disabled) and Kerberos. When
Kerberos is disabled, the Basic Auth path defaults to
admin/admin123 and can invoke
AuthenticationUtil.getBasicAuthenticationInput(), which calls System.exit(1) if
credentials are null and no console is available (daemon mode).
- **Expected behavior:** When deployed behind a trusted proxy with
header-based auth, the REST notification client should create an AtlasClientV2
instance without any client-side authentication — no Basic Auth
credentials, no Kerberos negotiation.
- **Root cause:** No mechanism existed to skip client-side authentication
in RestNotification.
- I**mpact:** In header-auth environments, the trino-atlas plugin either
sends unnecessary Basic Auth credentials (which the server ignores in favor of
header-auth) or risks System.exit(1) in daemon mode when
credentials are not configured.
#### How the patch resolves it :
- **New configuration property:** `atlas.hook.rest.notification.auth.skip
`(default: false)
- When true, RestNotification creates the Atlas client without any
client-side authentication
- When false (default), existing Basic Auth / Kerberos behavior is
preserved — no impact on existing deployments
- **Implementation:** A new header-auth branch is added at the top of the
auth decision tree in RestNotification.setupAtlasClientV2():
header-auth enabled → AtlasClientV2(endpoints, null) // no auth
Kerberos disabled → AtlasClientV2(endpoints, creds) // basic auth
Kerberos enabled → AtlasClientV2(endpoints) // kerberos
Calling new AtlasClientV2(urls, (String[]) null) leverages the existing
implicit no-auth path in AtlasBaseClient: basicAuthUser/basicAuthPassword
remain null (Basic Auth not registered), and ugi is null
(Kerberos check returns false), resulting in a plain HTTP client.
- **Files changed:**
- intg/.../AtlasConfiguration.java — Added
NOTIFICATION_HOOK_REST_HEADER_AUTH_ENABLED enum constant
- notification/.../rest/RestNotification.java — Added header-auth branch
in setupAtlasClientV2() (4 lines of production code)
- notification/.../RestNotificationTest.java — Added 5 new test methods
and 1 helper method
- **Design decisions:**
- No changes to AtlasBaseClient or AtlasClientV2 — the existing no-auth
path is reused
- registerClientRequestFilter() approach was evaluated and rejected
because Maven shade plugin class relocation in Trino causes
javax.ws.rs.client.ClientRequestFilter lambdas compiled in the notification
module to silently fail at runtime
- Property naming follows the existing atlas.hook.rest.notification.*
convention
- **Client-side configuration (header-auth mode)**:
atlas.hook.rest.notification.enabled=true
atlas.hook.rest.notification.address=http://<atlas-host>:31000/
atlas.hook.rest.notification.auth.skip=true
- **Corresponding server-side configuration (already existing)**:
atlas.authn.header.enabled=true
atlas.authn.header.username=x-awc-username
atlas.authn.header.roles=x-awc-userroles
atlas.authn.header.requestid=x-awc-requestid
## How was this patch tested?
### Setup
- Atlas REST notification webapp deployed
- trino-atlas plugin configured to send REST notifications
- Atlas server with AtlasHeaderPreAuthFilter support
### Use-cases validation
- Scenario 1: Header-auth enabled, no gateway headers, server header-auth
not configured
- Expected: 401 Unauthorized (proves unauthenticated request reaches
server without client-side auth)
- Actual: 401 Unauthorized — Spring Security rejects at filter level
before audit layer
- Status: Passed
- Scenario 2: Header-auth enabled, with gateway headers (x-awc-username,
x-awc-userroles, x-awc-requestid), server header-auth enabled
- Expected: Entities created successfully in Atlas via header-based
authentication
- Actual: Entities visible in Atlas UI
- Status: Passed
- Scenario 3: Header-auth disabled (default), Basic Auth configured
- Expected: Existing Basic Auth behavior preserved
- Actual: Entities created successfully via Basic Auth
- Status: Passed
- Scenario 4: Header-auth disabled (default), Kerberos configured
- Expected: Existing Kerberos behavior preserved
- Actual: Kerberos authentication works as expected
- Status: Passed
#### Unit testing
- Test class: org.apache.atlas.notification.RestNotificationTest
- New tests added (5):
- testRestNotificationHeaderAuthMode — Verifies header-auth mode creates
client with correct endpoint URL
- testHeaderAuthModeSkipsBasicAuth — Verifies basicAuthUser is null in
header-auth mode (no Basic Auth credentials set)
- testBasicAuthModeSetCredentials — Verifies Basic Auth credentials are
correctly set when header-auth is disabled
- testHeaderAuthModeFallsBackToDefaultUrl — Verifies default URL
(http://localhost:31000/) is used when no endpoint is configured in header-auth
mode
- testHeaderAuthDefaultsToFalseUsesBasicAuth — Verifies that when
header.auth.enabled is not set, Basic Auth is used (default behavior preserved)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
