Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix RESTful protocol security enabled evaluation #6001

Closed
wants to merge 3 commits into from

Conversation

pan3793
Copy link
Member

@pan3793 pan3793 commented Jan 19, 2024

🔍 Description

Issue References 🔗

#5568 (comment)

Describe Your Solution 🔧

Only when Kerberos is enabled or effectivePlainAuthType is not NONE, RESTful security is enabled

Types of changes 🔖

  • Bugfix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Test Plan 🧪

Behavior Without This Pull Request ⚰️

when kyuubi.authentication=KERBEROS and use RESTful API, the exception is thrown AuthenticationException("Kerberos is not supported for thrift http mode")

Behavior With This Pull Request 🎉

when kyuubi.authentication=KERBEROS, the RESTful API uses SPNego authN.

Related Unit Tests

Add some *KyuubiRestFrontendServiceSuite


Checklist 📝

Be nice. Be informative.

@pan3793 pan3793 requested a review from cfmcgrady January 19, 2024 13:03
@zhouyifan279
Copy link
Contributor

LGTM

@pan3793 pan3793 changed the title Fix RESTful security enabled evaluation Fix RESTful protocol security enabled evaluation Jan 19, 2024
@pan3793 pan3793 self-assigned this Jan 19, 2024
@pan3793 pan3793 added this to the v1.8.1 milestone Jan 19, 2024
@pan3793
Copy link
Member Author

pan3793 commented Jan 19, 2024

Merged to master/1.8

@pan3793 pan3793 closed this in bd83f89 Jan 19, 2024
pan3793 added a commit that referenced this pull request Jan 19, 2024
#5568 (comment)

Only when Kerberos is enabled or effectivePlainAuthType is not NONE, RESTful security is enabled

- [x] Bugfix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature that would cause existing functionality to change)

when `kyuubi.authentication=KERBEROS` and use RESTful API, the exception is thrown `AuthenticationException("Kerberos is not supported for thrift http mode")`

when `kyuubi.authentication=KERBEROS`, the RESTful API uses SPNego authN.

Add some `*KyuubiRestFrontendServiceSuite`

---

- [x] This patch was not authored or co-authored using [Generative Tooling](https://www.apache.org/legal/generative-tooling.html)

**Be nice. Be informative.**

Closes #6001 from pan3793/auth-krb.

Closes #6001

3640424 [Cheng Pan] nit
69d33fb [Cheng Pan] fix
f18cf84 [Cheng Pan] Fix RESTful security enabled evaluation

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Cheng Pan <[email protected]>
zhaohehuhu pushed a commit to zhaohehuhu/incubator-kyuubi that referenced this pull request Feb 5, 2024
# 🔍 Description
## Issue References 🔗

apache#5568 (comment)

## Describe Your Solution 🔧

Only when Kerberos is enabled or effectivePlainAuthType is not NONE, RESTful security is enabled

## Types of changes 🔖

- [x] Bugfix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature that would cause existing functionality to change)

## Test Plan 🧪

#### Behavior Without This Pull Request ⚰️

when `kyuubi.authentication=KERBEROS` and use RESTful API, the exception is thrown `AuthenticationException("Kerberos is not supported for thrift http mode")`

#### Behavior With This Pull Request 🎉

when `kyuubi.authentication=KERBEROS`, the RESTful API uses SPNego authN.

#### Related Unit Tests

Add some `*KyuubiRestFrontendServiceSuite`

---

# Checklist 📝

- [x] This patch was not authored or co-authored using [Generative Tooling](https://www.apache.org/legal/generative-tooling.html)

**Be nice. Be informative.**

Closes apache#6001 from pan3793/auth-krb.

Closes apache#6001

3640424 [Cheng Pan] nit
69d33fb [Cheng Pan] fix
f18cf84 [Cheng Pan] Fix RESTful security enabled evaluation

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Cheng Pan <[email protected]>
zhaohehuhu pushed a commit to zhaohehuhu/incubator-kyuubi that referenced this pull request Mar 21, 2024
# 🔍 Description
## Issue References 🔗

apache#5568 (comment)

## Describe Your Solution 🔧

Only when Kerberos is enabled or effectivePlainAuthType is not NONE, RESTful security is enabled

## Types of changes 🔖

- [x] Bugfix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature that would cause existing functionality to change)

## Test Plan 🧪

#### Behavior Without This Pull Request ⚰️

when `kyuubi.authentication=KERBEROS` and use RESTful API, the exception is thrown `AuthenticationException("Kerberos is not supported for thrift http mode")`

#### Behavior With This Pull Request 🎉

when `kyuubi.authentication=KERBEROS`, the RESTful API uses SPNego authN.

#### Related Unit Tests

Add some `*KyuubiRestFrontendServiceSuite`

---

# Checklist 📝

- [x] This patch was not authored or co-authored using [Generative Tooling](https://www.apache.org/legal/generative-tooling.html)

**Be nice. Be informative.**

Closes apache#6001 from pan3793/auth-krb.

Closes apache#6001

3640424 [Cheng Pan] nit
69d33fb [Cheng Pan] fix
f18cf84 [Cheng Pan] Fix RESTful security enabled evaluation

Authored-by: Cheng Pan <[email protected]>
Signed-off-by: Cheng Pan <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants