Anonymous Coward (934) has posted comments on this change. ( http://gerrit.cloudera.org:8080/24472 )
Change subject: IMPALA-12232: Validate JWT aud/iss claims ...................................................................... Patch Set 8: (3 comments) Done http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/jwt-util.cc File be/src/util/jwt-util.cc: http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/jwt-util.cc@51 PS6, Line 51: : // Support only a single x5c certifica > How about removing these, seems dead code Good catch, done in PS8 http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc File be/src/util/oauth-servers-manager.cc: http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc@62 PS6, Line 62: DCHECK(jwt_helpers_); : DCHECK(username_out != nullptr); : username_out->clear(); > For this, how about adding a test in oauth-servers-manager-test.cc involvin Agreed. This is now handled in the per-server loop in Verify(), so claim mismatch on one matching server can continue to the next candidate server. Done in PS8. http://gerrit.cloudera.org:8080/#/c/24472/6/be/src/util/oauth-servers-manager.cc@81 PS6, Line 81: RETURN_IF_ERROR(FindMatchingServer(decoded_token, next_idx, &matched_server_idx)); > If move to here, maybe we can check like this, and this is lighter than che Thanks. I kept signature verification before claim validation intentionally so claims are evaluated only after cryptographic verification of the token/server pair. With the latest flow, claims are still validated inside the per-server loop, so fallback behavior across matching servers is preserved. -- To view, visit http://gerrit.cloudera.org:8080/24472 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375 Gerrit-Change-Number: 24472 Gerrit-PatchSet: 8 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Abhishek Rawat <[email protected]> Gerrit-Reviewer: Anonymous Coward (934) Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Gokul Kolady <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Reviewer: Yida Wu <[email protected]> Gerrit-Comment-Date: Thu, 24 Sep 2026 12:26:05 +0000 Gerrit-HasComments: Yes
