Anonymous Coward (934) has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24472 )

Change subject: IMPALA-12232: Validate JWT aud/iss claims
......................................................................


Patch Set 8:

(3 comments)

Done

http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/jwt-util.cc
File be/src/util/jwt-util.cc:

http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/jwt-util.cc@51
PS6, Line 51:
            : // Support only a single x5c certifica
> How about removing these, seems dead code
Good catch, done in PS8


http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc
File be/src/util/oauth-servers-manager.cc:

http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc@62
PS6, Line 62:   DCHECK(jwt_helpers_);
            :   DCHECK(username_out != nullptr);
            :   username_out->clear();
> For this, how about adding a test in oauth-servers-manager-test.cc involvin
Agreed. This is now handled in the per-server loop in Verify(), so claim 
mismatch on one matching server can continue to the next candidate server.

Done in PS8.


http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc@81
PS6, Line 81:     RETURN_IF_ERROR(FindMatchingServer(decoded_token, next_idx, 
&matched_server_idx));
> If move to here, maybe we can check like this, and this is lighter than che
Thanks. I kept signature verification before claim validation intentionally so 
claims are evaluated only after cryptographic verification of the token/server 
pair. With the latest flow, claims are still validated inside the per-server 
loop, so fallback behavior across matching servers is preserved.



--
To view, visit http://gerrit.cloudera.org:8080/24472
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375
Gerrit-Change-Number: 24472
Gerrit-PatchSet: 8
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anonymous Coward (934)
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Thu, 24 Sep 2026 12:26:05 +0000
Gerrit-HasComments: Yes

Reply via email to