Yida Wu has posted comments on this change. ( http://gerrit.cloudera.org:8080/24472 )
Change subject: IMPALA-12232: Validate JWT aud/iss claims ...................................................................... Patch Set 10: (1 comment) http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc File be/src/util/oauth-server-config.cc: http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc@172 PS10, Line 172: RETURN_IF_ERROR(ReadOptionalStringArrayField( : obj, "audienceClaims", &config.audience_claims)); : RETURN_IF_ERROR(ReadOptionalStringArrayField( : obj, "issuerClaims", &config.issuer_claims)); > To maintain backwards compatibility, empty values indicate to accept any au It looks like for JWKS parsing, an empty array would trigger a parse error. https://github.com/apache/impala/blob/master/be/src/util/jwt-util.cc#L128-L131. For consistency, it seems to make more sense if we apply the same strictness to audienceClaims and issuerClaims since they are also arrays. A testcase would also be good to add for these corner cases -- To view, visit http://gerrit.cloudera.org:8080/24472 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375 Gerrit-Change-Number: 24472 Gerrit-PatchSet: 10 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Abhishek Rawat <[email protected]> Gerrit-Reviewer: Anonymous Coward (934) Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Gokul Kolady <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Reviewer: Yida Wu <[email protected]> Gerrit-Comment-Date: Thu, 01 Oct 2026 02:34:20 +0000 Gerrit-HasComments: Yes
