Skip to content

[fix][broker] Fix multi-role authorization regressions and optimize nested checks - #26551

Merged
lhotari merged 1 commit into
apache:masterfrom
lhotari:followup-26549-multi-role-improvements
Sep 12, 2026
Merged

lhotari merged 1 commit into
apache:masterfrom
lhotari:followup-26549-multi-role-improvements

Conversation

@lhotari

@lhotari lhotari commented Sep 11, 2026

Copy link
Copy Markdown
Member

Motivation

Follow up to #26549 to fix authorization-provider initialization and proxy authorization regressions, and avoid repeating token validation in nested checks.

Legacy subclasses need their initializer invoked, and standalone function workers need authorization to use the initialized authentication service. Anonymous and forwarded clients also need a consistent authorization context across lookup, produce, consume, and subscription checks.

Modifications

  • Preserve legacy initialization in subclasses of PulsarAuthorizationProvider.
  • Share one authentication service across standalone worker authorization and HTTP handling, and close it on shutdown.
  • Allow the multi-role provider to initialize without a token provider when authorization is disabled.
  • Resolve token roles once per authorization operation and carry each resolved role through nested checks.
  • Use an explicit anonymous authentication context for binary connections and HTTP requests.
  • Authorize by the forwarded principal when original-client authentication is disabled.
  • Include the cause in role-extraction diagnostics.

Verifying this change

Regression coverage includes legacy and worker initialization, nested role resolution, anonymous-client binary and HTTP operations, and forwarded-principal permissions with credential forwarding enabled and disabled.

Local validation passed:

  • 177 tests across the full MultiRolesTokenAuthorizationProviderTest, ServerCnxTest, and ProxyWithJwtAuthorizationTest classes.
  • Authorization-service, authentication-service, authentication-filter, and standalone-worker tests during development.
  • ./gradlew quickCheck; ./gradlew checkBinaryLicense also passed during development.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API — restores legacy authorization-provider initialization.
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol — updates anonymous and forwarded-principal connection context handling.
  • The REST endpoints — updates anonymous HTTP authentication context handling.
  • The admin CLI options
  • The metrics
  • Anything that affects deployment — fixes standalone function-worker initialization.

…ested checks

Follow up to apache#26549 to fix authorization-provider initialization and proxy authorization regressions, and avoid repeating token validation in nested checks.

Legacy subclasses need their initializer invoked, and standalone function workers need authorization to use the initialized authentication service. Anonymous and forwarded clients also need a consistent authorization context across lookup, produce, consume, and subscription checks.

- Preserve legacy initialization in subclasses of `PulsarAuthorizationProvider`.
- Share one authentication service across standalone worker authorization and HTTP handling, and close it on shutdown.
- Allow the multi-role provider to initialize without a token provider when authorization is disabled.
- Resolve token roles once per authorization operation and carry each resolved role through nested checks.
- Use an explicit anonymous authentication context for binary connections and HTTP requests.
- Authorize by the forwarded principal when original-client authentication is disabled.
- Include the cause in role-extraction diagnostics.

Validation: 177 tests across MultiRolesTokenAuthorizationProviderTest,
ServerCnxTest, and ProxyWithJwtAuthorizationTest; quickCheck passed.

Assisted-by: Codex
@lhotari
lhotari requested a review from merlimat September 11, 2026 23:24
@lhotari lhotari added this to the 5.0.0-M2 milestone Sep 11, 2026
@lhotari
lhotari merged commit 961aa59 into apache:master Sep 12, 2026
82 of 84 checks passed
lhotari added a commit that referenced this pull request Sep 12, 2026
lhotari added a commit that referenced this pull request Sep 12, 2026
lhotari added a commit that referenced this pull request Sep 12, 2026
…tion checks

Fix the test introduced by e67d32f
([fix][broker] Fix multi-role authorization regressions and optimize
nested checks, #26551), cherry-picked from
961aa59.

The upstream and branch-4.2 provider default to the "roles" claim after
the JJWT 0.13.0 upgrade (#25043; branch-4.2 commit 270120c).
Branch-4.0 retains the "sub" default. The backported test still mocked
and verified "roles", so its stub did not match the provider call.
Use "sub" in the stub and verifications to exercise nested authorization
with this branch's default claim.

Validation: all 36 MultiRolesTokenAuthorizationProviderTest cases pass;
Checkstyle passes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants