sundapeng opened a new pull request, #10178: URL: https://github.com/apache/paimon/pull/10178
### Purpose `RESTTokenFileIO` merges the vended data token into the options of the delegate `FileIO`, and the OSS client signs with those static keys. A refresh builds a new delegate for later calls, but a stream that is already open keeps the token it was opened with and fails once that token expires (see the discussion in #10141). This makes `OSSFileIO` ask a credentials provider on every request. `RESTTokenFileIO` registers a supplier of its current token in `CredentialsSupplierRegistry` and passes the id to the delegate, so requests on open streams are signed with the refreshed token. The supplier is unregistered when the delegate leaves the cache. `OSSLoader` also accepts `fs.oss.credentials.provider` in place of the access keys, as #8679 did for S3. Jindo and S3 are unchanged. ### Tests `RegisteredCredentialsProviderTest`: 4 new tests; `RESTTokenFileIOTest`: 1 new, 11 passed; `OSSLoaderTest`: 1 new; `OSSFileIOTest` and `MockRESTCatalogTest` pass. Also verified end to end through the OSS plugin class loader against a local endpoint: an open input stream switched to the new access key mid-read. ### Documentation A Credentials Provider section in the OSS part of the filesystems page. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
