Akash3121 commented on code in PR #10141:
URL: https://github.com/apache/paimon/pull/10141#discussion_r4088808845
##########
paimon-python/pypaimon/common/options/config.py:
##########
@@ -256,3 +262,10 @@ class FuseOptions:
"'raw' uses URI path segments directly"
)
)
+
+
+def data_token_expiration_safe_time_millis(options=None) -> int:
+ """Return the refresh window for vended data tokens, in milliseconds."""
+ option = CatalogOptions.DATA_TOKEN_EXPIRATION_SAFE_TIME
+ value = option.default_value() if options is None else options.get(option)
+ return int(value.total_seconds() * 1000)
Review Comment:
Java explicitly rejects a negative `data-token.expiration-safe-time` , but
this shared PyPaimon helper accepts an already-typed negative `timedelta`
because `Options.get()` returns typed values unchanged. For example,
`Options({key: timedelta(minutes=-1)})` produces `-60000` .
`RESTTokenFileIO` then effectively refreshes only after expiry, while
`PaimonRealStorage.need_refresh()` compares directly against `-60000` and
can keep using a credential after it has expired (an expiry 30 seconds ago
still returns `False`). Please reject negative values in this shared helper so
both Python consumers fail fast, and add a typed-negative regression covering
PVFS as well as `RESTTokenFileIO`.
Current flow: String values such as `"-1 min"` are rejected by the
duration parser, but `Options` officially accepts already-typed values. A
negative `timedelta` reaches this helper unchanged.
Concrete failure: With a `-1 min` typed duration, PVFS does not rebuild a
filesystem until the credential has been expired for more than one minute,
causing storage operations to use expired credentials rather than rejecting the
invalid configuration at startup.
Minimal fix: Convert to milliseconds, check that the result is nonnegative,
and raise a `ValueError` naming `data-token.expiration-safe-time` otherwise.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]