Repository navigation
Tags: apache/impala
Tags
IMPALA-12232: Validate JWT aud/iss claims Validate configured audienceClaims and issuerClaims after token signature verification for both JWT and OAuth auth flows, including HS2 HTTP and webserver paths. Extend oauth_servers parsing to accept audienceClaims/issuerClaims and align claim validation behavior with JWT RFC requirements for aud/iss semantics. Address follow-up review feedback by adding targeted null checks, preserving HTTP error response headers in test transport code, and strengthening JwtHttp negative tests to assert claim-specific auth failures from WWW-Authenticate headers. Remove obsolete --jwt_validate_signature usage in JwtHttpTest startup flags so custom-cluster tests use supported oauth_servers options. Testing: - Linux: fe mvn test -Dtest='JwtHttpTest#testJwtAuthWithWrongIssuerClaim+ testJwtAuthWithWrongAudienceClaim+testJwtAuthWithMissingAudienceClaim' - Linux: be/build/debug/util/oauth-server-config-test Change-Id: I0a00b126359f2bc7e2f73d894cebc2b9014c7375 Assisted-by: GPT-5.3 (Cursor) Reviewed-on: http://gerrit.cloudera.org:8080/24472 Tested-by: Impala Public Jenkins <impala-public-jenkins@cloudera.com> Reviewed-by: Jason Fehr <jfehr@cloudera.com>
PreviousNext