bhor-sanket opened a new pull request, #775:
URL: https://github.com/apache/atlas/pull/775

   
   ## What changes were proposed in this pull request?
   ### Background
   
   In header-based authentication environments (e.g., UDF/Trino deployments 
behind a trusted proxy), an external gateway injects authentication headers 
`(x-awc-username, x-awc-userroles, x-awc-requestid)` into requests before they 
reach Atlas. The Atlas server already supports this model via 
`AtlasHeaderPreAuthFilter`, which creates an `AtlasAuthenticationToken` with 
`AUTH_TYPE_TRUSTED_PROXY` when the appropriate headers are present.
   
   The trino-atlas plugin uses the REST notification channel (RestNotification) 
to send hook notifications to Atlas. In header-auth environments, client-side 
authentication (Basic Auth or Kerberos) is unnecessary and counterproductive — 
the gateway handles auth.
   
   
     #### Problem Statement                                                     
                                                                                
                                                         
                                                                                
                                                                                
                                                    
     - **Existing behavior:** RestNotification.setupAtlasClientV2() has only 
two auth paths: Basic Auth (when Kerberos is disabled) and Kerberos. When 
Kerberos is disabled, the Basic Auth path defaults to            
       admin/admin123 and can invoke 
AuthenticationUtil.getBasicAuthenticationInput(), which calls System.exit(1) if 
credentials are null and no console is available (daemon mode).                 
               
     - **Expected behavior:** When deployed behind a trusted proxy with 
header-based auth, the REST notification client should create an AtlasClientV2 
instance without any client-side authentication — no Basic Auth  
       credentials, no Kerberos negotiation.                                    
                                                                                
                                                    
     - **Root cause:** No mechanism existed to skip client-side authentication 
in RestNotification.                                                            
                                                         
     - I**mpact:** In header-auth environments, the trino-atlas plugin either 
sends unnecessary Basic Auth credentials (which the server ignores in favor of 
header-auth) or risks System.exit(1) in daemon mode when   
       credentials are not configured.
   
     #### How the patch resolves it     : 
   
   - **New configuration property:** `atlas.hook.rest.notification.auth.skip 
`(default: false)                                                               
                                                 
       - When true, RestNotification creates the Atlas client without any 
client-side authentication                                                      
                                                          
       - When false (default), existing Basic Auth / Kerberos behavior is 
preserved — no impact on existing deployments                                   
                                                          
       
   - **Implementation:** A new header-auth branch is added at the top of the 
auth decision tree in RestNotification.setupAtlasClientV2():                    
                                                         
     header-auth enabled → AtlasClientV2(endpoints, null)  // no auth           
                                                                                
                                                    
     Kerberos disabled   → AtlasClientV2(endpoints, creds)  // basic auth       
                                                                                
                                                    
     Kerberos enabled    → AtlasClientV2(endpoints)          // kerberos        
                                                                                
                                                    
       Calling new AtlasClientV2(urls, (String[]) null) leverages the existing 
implicit no-auth path in AtlasBaseClient: basicAuthUser/basicAuthPassword 
remain null (Basic Auth not registered), and ugi is null   
       (Kerberos check returns false), resulting in a plain HTTP client.        
                                                                                
                                                    
   
   - **Files changed:**                                                         
                                                                                
                                                      
       - intg/.../AtlasConfiguration.java — Added 
NOTIFICATION_HOOK_REST_HEADER_AUTH_ENABLED enum constant                        
                                                                                
  
       - notification/.../rest/RestNotification.java — Added header-auth branch 
in setupAtlasClientV2() (4 lines of production code)                            
                                                    
       - notification/.../RestNotificationTest.java — Added 5 new test methods 
and 1 helper method                                                             
                                                     
       
   - **Design decisions:**                                                      
                                                                                
                                                      
       - No changes to AtlasBaseClient or AtlasClientV2 — the existing no-auth 
path is reused                                                                  
                                                     
       - registerClientRequestFilter() approach was evaluated and rejected 
because Maven shade plugin class relocation in Trino causes 
javax.ws.rs.client.ClientRequestFilter lambdas compiled in the notification  
         module to silently fail at runtime                                     
                                                                                
                                                    
       - Property naming follows the existing atlas.hook.rest.notification.* 
convention                                                                      
                                                       
     
   - **Client-side configuration (header-auth mode)**:                          
                                                                                
                                                      
     atlas.hook.rest.notification.enabled=true                                  
                                                                                
                                                    
     atlas.hook.rest.notification.address=http://<atlas-host>:31000/            
                                                                                
                                                    
     atlas.hook.rest.notification.auth.skip=true                                
                                                                                
                                          
     
   - **Corresponding server-side configuration (already existing)**:            
                                                                                
                                                      
     atlas.authn.header.enabled=true                                            
                                                                                
                                                    
     atlas.authn.header.username=x-awc-username                                 
                                                                                
                                                    
     atlas.authn.header.roles=x-awc-userroles                                   
                                                                                
                                                    
     atlas.authn.header.requestid=x-awc-requestid  
   
   ## How was this patch tested?
   ### Setup                                                                    
                                                                                
                                                      
                                                                                
                                                                                
                                                    
     - Atlas REST notification webapp deployed                                  
                                                                                
                                       
     - trino-atlas plugin configured to send REST notifications                 
                                                                                
                                                    
     - Atlas server with AtlasHeaderPreAuthFilter support                       
                                                                                
                                                    
                                                                                
                                                                                
                                                    
   ### Use-cases validation                                                     
                                                                                
                                                      
                                                                                
                                                                                
                                                    
     - Scenario 1: Header-auth enabled, no gateway headers, server header-auth 
not configured                                                                  
                                                     
       - Expected: 401 Unauthorized (proves unauthenticated request reaches 
server without client-side auth)                                                
                                                        
       - Actual: 401 Unauthorized — Spring Security rejects at filter level 
before audit layer                                                              
                                                        
       - Status: Passed                                                         
                                                                                
                                                    
     - Scenario 2: Header-auth enabled, with gateway headers (x-awc-username, 
x-awc-userroles, x-awc-requestid), server header-auth enabled                   
                                                      
       - Expected: Entities created successfully in Atlas via header-based 
authentication                                                                  
                                                         
       - Actual: Entities visible in Atlas UI                                   
                                                                                
                                                    
       - Status: Passed                                                         
                                                                                
                                                    
     - Scenario 3: Header-auth disabled (default), Basic Auth configured        
                                                                                
                                                    
       - Expected: Existing Basic Auth behavior preserved                       
                                                                                
                                                    
       - Actual: Entities created successfully via Basic Auth                   
                                                                                
                                                    
       - Status: Passed                                                         
                                                                                
                                                    
     - Scenario 4: Header-auth disabled (default), Kerberos configured          
                                                                                
                                                    
       - Expected: Existing Kerberos behavior preserved                         
                                                                                
                                                    
       - Actual: Kerberos authentication works as expected                      
                                                                                
                                                    
       - Status: Passed                                                         
                                                                                
                                                    
                                                                                
                                                                                
                                                    
     #### Unit testing                                                          
                                                                                
                                                         
                                                                                
                                                                                
                                                    
     - Test class: org.apache.atlas.notification.RestNotificationTest           
                                                                                
                                                    
     - New tests added (5):                                                     
                                                                                
                                                    
       - testRestNotificationHeaderAuthMode — Verifies header-auth mode creates 
client with correct endpoint URL                                                
                                                    
       - testHeaderAuthModeSkipsBasicAuth — Verifies basicAuthUser is null in 
header-auth mode (no Basic Auth credentials set)                                
                                                      
       - testBasicAuthModeSetCredentials — Verifies Basic Auth credentials are 
correctly set when header-auth is disabled                                      
                                                     
       - testHeaderAuthModeFallsBackToDefaultUrl — Verifies default URL 
(http://localhost:31000/) is used when no endpoint is configured in header-auth 
mode                                                        
       - testHeaderAuthDefaultsToFalseUsesBasicAuth — Verifies that when 
header.auth.enabled is not set, Basic Auth is used (default behavior preserved)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to