apache / apache/gravitino

[Improvement] In the Kerberos security mode, after the Knox proxy Gravitino UI is enabled, Gravitino initiates authentication. Users passing through the Knox proxy are not directly transmitted to the Gravitino user system

Open
#8,876 1 comment 0 reactions 0 assignees View on GitHub
improvement
Dominant language
Java
Stars
3.2k
Forks
935
Avg merge
1d 16h
Merged PRs (30d)
298

Description

### What would you like to be improved?

Generally, if kereros is enabled, the UI interface cannot be opened. In our production environment, we have inherited the Knox proxy Gravitino Web UI, and the interface can be successfully opened. However, after Gravitino enables authentication, it cannot obtain the Knox login user. Gravitino needs to enhance its ability to obtain the proxy user.

### How should we improve?

_No response_

Contributor guide

Open the contributing guide

Research direction

The issue mentions Kerberos authentication, the Knox proxy, and the Gravitino Web UI, but names no files, tests, or entry points. Start by locating the authentication flow and how proxy users are handled, then determine the expected authenticated user propagation through Knox. Done means the Gravitino system can obtain the Knox login user when authentication is enabled.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.