Yida Wu has posted comments on this change. ( http://gerrit.cloudera.org:8080/24472 )
Change subject: IMPALA-12232: Validate JWT aud/iss claims ...................................................................... Patch Set 12: Code-Review+1 (2 comments) Thanks for adding all the tests. http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc File be/src/util/oauth-server-config.cc: http://gerrit.cloudera.org:8080/#/c/24472/10/be/src/util/oauth-server-config.cc@172 PS10, Line 172: RETURN_IF_ERROR(ReadOptionalStringField(obj, "usernameClaim", &config.username_claim)); : RETURN_IF_ERROR(ReadOptionalStringArrayField( : obj, "audienceClaims", &config.audience_claims)); : RETURN_IF_ERROR(ReadOptionalStringArrayField( > It looks like for JWKS parsing, an empty array would trigger a parse error. The way of dealing with the array empty values ([] and [""]) is a design choice and not a bug, I am good with either approach http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc File be/src/util/oauth-server-config.cc: http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc@136 PS12, Line 136: if (!obj.HasMember(field_name)) return Status::OK(); Can we add a DCHECK(values_out != nullptr) similar to what SetJwksSource does? -- To view, visit http://gerrit.cloudera.org:8080/24472 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375 Gerrit-Change-Number: 24472 Gerrit-PatchSet: 12 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Abhishek Rawat <[email protected]> Gerrit-Reviewer: Anonymous Coward (934) Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Gokul Kolady <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Reviewer: Yida Wu <[email protected]> Gerrit-Comment-Date: Thu, 01 Oct 2026 22:57:42 +0000 Gerrit-HasComments: Yes
