[Improvement] In the Kerberos security mode, after the Knox proxy Gravitino UI is enabled, Gravitino initiates authentication. Users passing through the Knox proxy are not directly transmitted to the Gravitino user system
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 935
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 298
Description
### What would you like to be improved?
Generally, if kereros is enabled, the UI interface cannot be opened. In our production environment, we have inherited the Knox proxy Gravitino Web UI, and the interface can be successfully opened. However, after Gravitino enables authentication, it cannot obtain the Knox login user. Gravitino needs to enhance its ability to obtain the proxy user.
### How should we improve?
_No response_
Contributor guide
Research direction
The issue mentions Kerberos authentication, the Knox proxy, and the Gravitino Web UI, but names no files, tests, or entry points. Start by locating the authentication flow and how proxy users are handled, then determine the expected authenticated user propagation through Knox. Done means the Gravitino system can obtain the Knox login user when authentication is enabled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, backend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100