JingsongLi commented on PR #10141:
URL: https://github.com/apache/paimon/pull/10141#issuecomment-5805717932

   This addresses a real production issue: a one-hour refresh window causes 
continuous re-vending for common one-hour STS credentials. The Java and Python 
REST paths retain the minimum-validity check, and the configurable default 
makes the behavior operationally tunable.
   
   I reproduced the Python issue already reported by @Akash3121: a typed 
`timedelta(minutes=-1)` yields `-60000`, and `PaimonRealStorage.need_refresh()` 
returns false for a credential that expired 30 seconds ago. Please reject a 
negative window in the shared Python helper and add a PVFS regression before 
merge. Local verification: 25 RESTTokenFileIO Python tests passed. The 7 PVFS 
integration tests could not bind their local HTTP server in this sandbox 
(`PermissionError: Operation not permitted`); the Java JDK 8 reactor compiled, 
but 13 Mockito-based RESTTokenFileIO tests were blocked by this host’s 
ByteBuddy attach failure (3 tests passed). I could not use those environment 
failures to assess the PR’s runtime behavior.
   
   The change has end-to-end value; the negative-window bug is the remaining 
production blocker I can confirm.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to