Yida Wu has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24472 )

Change subject: IMPALA-12232: Validate JWT aud/iss claims
......................................................................


Patch Set 10:

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc
File be/src/util/oauth-server-config.cc:

http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc@172
PS10, Line 172:   RETURN_IF_ERROR(ReadOptionalStringArrayField(
              :       obj, "audienceClaims", &config.audience_claims));
              :   RETURN_IF_ERROR(ReadOptionalStringArrayField(
              :       obj, "issuerClaims", &config.issuer_claims));
> To maintain backwards compatibility, empty values indicate to accept any au
It looks like for JWKS parsing, an empty array would trigger a parse error.
https://github.com/apache/impala/blob/master/be/src/util/jwt-util.cc#L128-L131.
For consistency, it seems to make more sense if we apply the same strictness to 
audienceClaims and issuerClaims since they are also arrays. A testcase would 
also be good to add for these corner cases



--
To view, visit http://gerrit.cloudera.org:8080/24472
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375
Gerrit-Change-Number: 24472
Gerrit-PatchSet: 10
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anonymous Coward (934)
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Thu, 01 Oct 2026 02:34:20 +0000
Gerrit-HasComments: Yes

Reply via email to