Anubhav Jindal has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24472 )

Change subject: IMPALA-12232: Validate JWT aud/iss claims
......................................................................


Patch Set 13:

(3 comments)

Done

http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc
File be/src/util/oauth-server-config.cc:

http://gerrit.cloudera.org:8080/#/c/24472/12/be/src/util/oauth-server-config.cc@136
PS12, Line 136:   DCHECK(values_out != nullptr);
> Can we add a DCHECK(values_out != nullptr) similar to what SetJwksSource do
Done in PS13. I added DCHECK(values_out != nullptr), at the beginning of 
ReadOptionalStringArrayField() to match the defensive null-check pattern used 
in SetJwksSource().


http://gerrit.cloudera.org:8080/#/c/24472/12/fe/src/test/java/org/apache/impala/customcluster/JwtHttpTest.java
File fe/src/test/java/org/apache/impala/customcluster/JwtHttpTest.java:

http://gerrit.cloudera.org:8080/#/c/24472/12/fe/src/test/java/org/apache/impala/customcluster/JwtHttpTest.java@364
PS12, Line 364:     setUp(String.format(
> There needs to be another assertion that checks that auth failed because th
Done in PS13. I updated testJwtAuthWithWrongIssuerClaim to use 
THttpClientWithHeaders and now assert the WWW-Authenticate header contains 
invalid_token and Claim 'iss', so the failure is explicitly tied to issuer 
mismatch.


http://gerrit.cloudera.org:8080/#/c/24472/12/fe/src/test/java/org/apache/impala/customcluster/JwtHttpTest.java@439
PS12, Line 439:     setUp(String.format(
> There needs to be another assertion that checks that auth failed because th
Done in PS13. I updated testJwtAuthWithWrongAudienceClaim to use 
THttpClientWithHeaders and now assert the WWW-Authenticate header contains 
invalid_token and Claim 'aud', so the test proves failure is due to audience 
mismatch.



--
To view, visit http://gerrit.cloudera.org:8080/24472
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375
Gerrit-Change-Number: 24472
Gerrit-PatchSet: 13
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anonymous Coward (934)
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Reviewer: Yida Wu <[email protected]>
Gerrit-Comment-Date: Tue, 06 Oct 2026 16:24:22 +0000
Gerrit-HasComments: Yes

Reply via email to