dwsmith1983 commented on PR #6059: URL: https://github.com/apache/datafusion-comet/pull/6059#issuecomment-6007366180
> Resolve `fs.azure.account.auth.type` against the URL's exact host and port before selecting or validating the mechanism. Add regressions for inactive endpoint suffixes and explicit-port overrides. Done in f4ddb8422. Every account-scoped lookup now reads Hadoop's one form, `<key>.<host>`, with the host taken from the URL authority as written, port included, then the global key. The other endpoint suffix and the bare `<key>.<account>` form are no longer probed anywhere, auth type and provider class included, and the container-scoped SAS keys and the WASB fallback build from the same host string. Both configurations from the review are tests: a global `OAuth` with `fs.azure.account.auth.type.myacct.blob.core.windows.net=SharedKey` builds the client-secret store for the `dfs` URL, and `OAuth` with its provider scoped to `myacct.dfs.core.windows.net:443` overrides a global `SharedKey` for the `:443` URL. Two more pin that a credential key under the blob host is not read for a `dfs` URL and that a key scoped to a Fabric host is. One consequence of the exact form: for a URL with an explicit port, the account-scoped `fs.azure.sas.fixed.token.<host>` has to carry the port too, as `a ccountConf` requires. The description and the data sources guide describe the lookup; the endpoint-suffix limitation is gone and a note says which hosts `object_store` builds a store for. That removes item 3 of #6605 and the Fabric part of item 2. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
