apache / apache/polaris

Support for OAuth Protected Resource Metadata (RFC 9728)

Open
#2,581 4 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
2.1k
Forks
522
Avg merge
1d 22h
Merged PRs (30d)
137

Description

### Is your feature request related to a problem? Please describe.

Quarkus 3.25 has introduced support for RFC 9728:

https://quarkus.io/guides/security-oidc-expanded-configuration#resource-metadata-properties

With that, Polaris servers could advertise the authorization server URL to interested clients.

For now, Iceberg REST clients do not leverage this possibility, but this could change in the future.

The Dremio Auth Manager has an issue to track support for this feature on its side:

https://github.com/dremio/iceberg-auth-manager/issues/46

### Describe the solution you'd like

_No response_

### Describe alternatives you've considered

_No response_

### Additional context

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reading RFC 9728, the linked Quarkus resource-metadata guide, and Dremio Auth Manager issue 46. The issue does not name Polaris files, tests, or a concrete client-side solution; done would require defining and implementing how Polaris and its clients use the advertised authorization server metadata.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, authentication
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.