thswlsqls opened a new pull request, #10228:
URL: https://github.com/apache/paimon/pull/10228

   
   ### Purpose
   
   fix #10227
   
   - `S3FileIO` mirrors hyphenated `access-key`/`secret-key` to the dotted S3A 
keys, but not the session token.
   - `s3.session-token` became `fs.s3a.session-token`, which S3A never reads, 
so temporary STS credentials passed via Flink/Spark/Hive catalog options were 
signed without the token (403).
   - Adds `{"fs.s3a.session-token", "fs.s3a.session.token"}` to 
`MIRRORED_CONFIG_KEYS`; precedence matches the existing mirrors. Dotted 
`s3.session.token` is unaffected.
   - Aligns with PyPaimon, which accepts `s3.session-token` (#7712).
   - Documents `s3.session-token` in the S3 section of `filesystems.mdx`.
   
   ### Tests
   
   - Added offline `S3FileIOConfigTest`: `testHyphenSessionTokenIsMirrored` 
(conf key plus resolved `AwsSessionCredentials`), `testDotSessionTokenIsKept`.
   - Without the fix, `testHyphenSessionTokenIsMirrored` fails 
(`fs.s3a.session.token` is null).
   - `mvn -pl paimon-filesystems/paimon-s3-impl clean install` green on JDK 11 
(`S3FileIOConfigTest` 2/2, spotless/checkstyle); Docker-based MinIO tests not 
run locally.
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to