Yida Wu has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24448 )

Change subject: IMPALA-14799: Add oauth_servers support and tests
......................................................................


Patch Set 19:

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc
File be/src/util/webserver.cc:

http://gerrit.cloudera.org:8080/#/c/24448/18/be/src/util/webserver.cc@777
PS18, Line 777:         if (use_jwt_) {
              :           if (OAuthTokenAuth(bearer_token, request_info, 
&response_headers)) {
              :             total_jwt_token_auth_success_->Increment(1);
              :             authenticated = true;
              :             check_csrf_protection = false;
              :             // TODO: cookies are not added, but are not needed 
right now
              :           }
              :         }
              :         if (!authenticated && use_oauth_) {
              :           if (OAuthTokenAuth(bearer_token, request_info, 
&response_headers)) {
              :             total_oauth_token_auth_success_->Increment(1);
              :             authenticated = true;
              :             check_csrf_protection = false;
              :             // TODO: cookies are not added, but are not needed 
right now
              :           }
              :         }
              :         if (!authenticated) {
              :           if (use_jwt_) {
              :             LOG(INFO) << "Invalid JWT token provided";
              :             total_jwt_token_auth_failure_->Increment(1);
              :           }
              :           if (use_oauth_) {
              :             LOG(INFO) << "Invalid OAuth token provided";
              :             total_oauth_token_auth_failure_->Increment(1);
              :           }
              :         }
> I kept the current structure intentionally so JWT and OAuth compatibility p
Since OAuthTokenAuth() now verifies the token against the unified 
OAuthServersManager and returns a simple boolean, how does the caller actually 
know which configuration (JWT or OAuth) successfully validated the token if 
both use_jwt_ and use_oauth_ are true here?



--
To view, visit http://gerrit.cloudera.org:8080/24448
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ib29ff36600406ba59c10f29d79cc632020f4a3f7
Gerrit-Change-Number: 24448
Gerrit-PatchSet: 19
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Mon, 24 Aug 2026 06:23:52 +0000
Gerrit-HasComments: Yes

Reply via email to