deniskuzZ commented on code in PR #6086: URL: https://github.com/apache/hive/pull/6086#discussion_r2376094412
########## standalone-metastore/metastore-common/src/main/java/org/apache/hadoop/hive/metastore/conf/MetastoreConf.java: ########## @@ -1873,8 +1873,55 @@ public enum ConfVars { " positive value will be used as-is." ), CATALOG_SERVLET_AUTH("metastore.catalog.servlet.auth", - "hive.metastore.catalog.servlet.auth", "jwt", new StringSetValidator("none", "simple", "jwt"), - "HMS Catalog servlet authentication method (none, simple, or jwt)." + "hive.metastore.catalog.servlet.auth", "jwt", new StringSetValidator("none", "simple", "jwt", "oauth2"), + "HMS Catalog servlet authentication method (none, simple, jwt, or oauth2)." + ), + CATALOG_SERVLET_AUTH_OAUTH2_ISSUER("metastore.catalog.servlet.auth.oauth2.issuer", + "hive.metastore.catalog.servlet.auth.oauth2.issuer", "", + "The issuer(iss)'s URI. This is required when you use metastore.catalog.servlet.auth=oauth2" + ), + CATALOG_SERVLET_AUTH_OAUTH2_VALIDATION_METHOD("metastore.catalog.servlet.auth.oauth2.validation.method", + "hive.metastore.catalog.servlet.auth.oauth2.validation.method", "jwt", + new StringSetValidator("jwt", "introspection"), + "How to evaluate an access token. When your authorization server issues opaque tokens or you need " + + "to consider additional security requirements such as token revocations, use introspection." + ), + CATALOG_SERVLET_AUTH_OAUTH2_AUDIENCE("metastore.catalog.servlet.auth.oauth2.audience", + "hive.metastore.catalog.servlet.auth.oauth2.audience", "", + "The acceptable name in the audience(aud) claim. This is required when you use " + + "metastore.catalog.servlet.auth=oauth2" + ), + CATALOG_SERVLET_AUTH_OAUTH2_CLIENT_ID("metastore.catalog.servlet.auth.oauth2.client.id", + "hive.metastore.catalog.servlet.auth.oauth2.client.id", "", + "The client ID of HMS as a resource server. This is required to use " + Review Comment: `This requires setting metastore.catalog.servlet.auth.oauth2.validation.method to introspection` ? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org For additional commands, e-mail: gitbox-h...@hive.apache.org