apache / apache/kyuubi

[FEATURE] Support to return authentication subject with PasswdAuthenticationProvider

Open
#4,630 2 comments 0 reactions 0 assignees View on GitHub
help wanted kind:feature priority:major
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/kyuubi/issues?q=is%3Aissue) and found no similar issues.

### Describe the feature

Now the PasswdAuthenticationProvider only authenticate whether the specified user name and password is valid, and nothing return.
```
trait PasswdAuthenticationProvider {
@throws[AuthenticationException]
def authenticate(user: String, password: String): Unit
}
```

In fact, in some use case, the transferred user name is not the valid user name.
It might be a key pair, and is a limited secret used for some use cases.

It is better that we can add a new method to return a subject to provided more authentication info.

Such as :

```
trait PasswdAuthenticationProvider {
@throws[AuthenticationException]
def authenticate(user: String, password: String): Unit

def authenticateAndReturnSubject(user: String, password: String): Subject = {
authenticate(user, password)
new Subject(user)
}
}
```

### Motivation

cover more password authentication use case.

### Describe the solution

_No response_

### Additional context

_No response_

### Are you willing to submit PR?

- [ ] Yes. I would be willing to submit a PR with guidance from the Kyuubi community to improve.
- [ ] No. I cannot submit a PR at this time.

Contributor guide

Open the contributing guide

Research direction

Start by locating the PasswdAuthenticationProvider trait and the authentication call sites that depend on its current Unit return type. Determine how a returned Subject should preserve existing authentication behavior and what compatibility requirements apply, then add coverage for the key-pair or alternate-identity use case and verify the existing password flow remains unchanged.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala
Domain
authentication, backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.