Repository navigation
[fix][broker] Fix multi-role authorization regressions and optimize nested checks - #26551
Merged
lhotari merged 1 commit intoSep 12, 2026
Merged
Conversation
…ested checks Follow up to apache#26549 to fix authorization-provider initialization and proxy authorization regressions, and avoid repeating token validation in nested checks. Legacy subclasses need their initializer invoked, and standalone function workers need authorization to use the initialized authentication service. Anonymous and forwarded clients also need a consistent authorization context across lookup, produce, consume, and subscription checks. - Preserve legacy initialization in subclasses of `PulsarAuthorizationProvider`. - Share one authentication service across standalone worker authorization and HTTP handling, and close it on shutdown. - Allow the multi-role provider to initialize without a token provider when authorization is disabled. - Resolve token roles once per authorization operation and carry each resolved role through nested checks. - Use an explicit anonymous authentication context for binary connections and HTTP requests. - Authorize by the forwarded principal when original-client authentication is disabled. - Include the cause in role-extraction diagnostics. Validation: 177 tests across MultiRolesTokenAuthorizationProviderTest, ServerCnxTest, and ProxyWithJwtAuthorizationTest; quickCheck passed. Assisted-by: Codex
merlimat
approved these changes
Sep 12, 2026
lhotari
added a commit
that referenced
this pull request
Sep 12, 2026
…tion checks Fix the test introduced by e67d32f ([fix][broker] Fix multi-role authorization regressions and optimize nested checks, #26551), cherry-picked from 961aa59. The upstream and branch-4.2 provider default to the "roles" claim after the JJWT 0.13.0 upgrade (#25043; branch-4.2 commit 270120c). Branch-4.0 retains the "sub" default. The backported test still mocked and verified "roles", so its stub did not match the provider call. Use "sub" in the stub and verifications to exercise nested authorization with this branch's default claim. Validation: all 36 MultiRolesTokenAuthorizationProviderTest cases pass; Checkstyle passes.
2 of 3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Follow up to #26549 to fix authorization-provider initialization and proxy authorization regressions, and avoid repeating token validation in nested checks.
Legacy subclasses need their initializer invoked, and standalone function workers need authorization to use the initialized authentication service. Anonymous and forwarded clients also need a consistent authorization context across lookup, produce, consume, and subscription checks.
Modifications
PulsarAuthorizationProvider.Verifying this change
Regression coverage includes legacy and worker initialization, nested role resolution, anonymous-client binary and HTTP operations, and forwarded-principal permissions with credential forwarding enabled and disabled.
Local validation passed:
MultiRolesTokenAuthorizationProviderTest,ServerCnxTest, andProxyWithJwtAuthorizationTestclasses../gradlew quickCheck;./gradlew checkBinaryLicensealso passed during development.Does this pull request potentially affect one of the following parts: