Yida Wu has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24472 )

Change subject: IMPALA-12232: Validate JWT aud/iss claims
......................................................................


Patch Set 12: Code-Review+1

(2 comments)

Thanks for adding all the tests.

http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc
File be/src/util/oauth-server-config.cc:

http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc@172
PS10, Line 172:   RETURN_IF_ERROR(ReadOptionalStringField(obj, "usernameClaim", 
&config.username_claim));
              :   RETURN_IF_ERROR(ReadOptionalStringArrayField(
              :       obj, "audienceClaims", &config.audience_claims));
              :   RETURN_IF_ERROR(ReadOptionalStringArrayField(
> It looks like for JWKS parsing, an empty array would trigger a parse error.
The way of dealing with the array empty values ([] and [""]) is a design choice 
and not a bug, I am good with either approach


http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc
File be/src/util/oauth-server-config.cc:

http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc@136
PS12, Line 136:   if (!obj.HasMember(field_name)) return Status::OK();
Can we add a DCHECK(values_out != nullptr) similar to what SetJwksSource does?



--
To view, visit http://gerrit.cloudera.org:8080/24472
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375
Gerrit-Change-Number: 24472
Gerrit-PatchSet: 12
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anonymous Coward (934)
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Thu, 01 Oct 2026 22:57:42 +0000
Gerrit-HasComments: Yes

Reply via email to