Gabriella Lotz has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24864 )

Change subject: Require authentication for REST catalog DDL
......................................................................


Patch Set 2:

(2 comments)

> Patch Set 1:
>
> (2 comments)
>
> Test coverage gaps:
> - The new validator branch (master.cc:188) has no test: a short negative 
> startup test asserting the master refuses to start with 
> --enable_rest_api=true and no SPNEGO / password-file / anonymous flag.
> - No coverage for the password-file path. A test that password-file auth is 
> accepted for POST but behaves correctly for PUT/DELETE would have surfaced 
> the gap above.


I have added RestApiFlagValidatorTest.RejectsUnsafeCombinations covering the 
flag combinations. To make the validator reachable from a test I moved 
ValidateRestApiFlag out of the anonymous namespace into kudu::master.

http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/master.cc
File src/kudu/master/master.cc:

http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/master.cc@188
PS1, Line 188:   // squeasel as global_auth_file, which squeasel consults only 
for
> The validator treats --webserver_password_file as a sufficient auth mode fo
You're right. I've dropped --webserver_password_file from the validator, so 
SPNEGO is the only accepted auth mode now.

Because we serve our handlers from squeasel's begin_request callback, its 
is_authorized_for_put check never runs for our paths, so password-file auth 
left PUT and DELETE unauthenticated rather than blocked. Same conclusion either 
way, and I've written the reasoning into a comment on the validator so it 
doesn't get re-added.


http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/rest_catalog_path_handlers.cc
File src/kudu/master/rest_catalog_path_handlers.cc:

http://gerrit.cloudera.org:8080/#/c/24864/1/src/kudu/master/rest_catalog_path_handlers.cc@413
PS1, Line 413:   PrintTableObject(output, table_id, status_code);
> The comment says setting the success code before PrintTableObject lets "a c
Good catch, thanks. I have added an explicit null check returning 404 before 
taking the lock. I haven't added a test for it: forcing a delete between the 
dispatcher's lookup and the one in PrintTableObject would need a 
fault-injection hook that doesn't exist on this path.



--
To view, visit http://gerrit.cloudera.org:8080/24864
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ib0112638a3462c84e6366b881c9229a334ad3c25
Gerrit-Change-Number: 24864
Gerrit-PatchSet: 2
Gerrit-Owner: Gabriella Lotz <[email protected]>
Gerrit-Reviewer: Attila Bukor <[email protected]>
Gerrit-Reviewer: Gabriella Lotz <[email protected]>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Reviewer: Marton Greber <[email protected]>
Gerrit-Comment-Date: Tue, 22 Sep 2026 09:31:35 +0000
Gerrit-HasComments: Yes

Reply via email to