JingsongLi commented on PR #10141: URL: https://github.com/apache/paimon/pull/10141#issuecomment-5805717932
This addresses a real production issue: a one-hour refresh window causes continuous re-vending for common one-hour STS credentials. The Java and Python REST paths retain the minimum-validity check, and the configurable default makes the behavior operationally tunable. I reproduced the Python issue already reported by @Akash3121: a typed `timedelta(minutes=-1)` yields `-60000`, and `PaimonRealStorage.need_refresh()` returns false for a credential that expired 30 seconds ago. Please reject a negative window in the shared Python helper and add a PVFS regression before merge. Local verification: 25 RESTTokenFileIO Python tests passed. The 7 PVFS integration tests could not bind their local HTTP server in this sandbox (`PermissionError: Operation not permitted`); the Java JDK 8 reactor compiled, but 13 Mockito-based RESTTokenFileIO tests were blocked by this host’s ByteBuddy attach failure (3 tests passed). I could not use those environment failures to assess the PR’s runtime behavior. The change has end-to-end value; the negative-window bug is the remaining production blocker I can confirm. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
