Skip to content

HBASE-30042 Test AuthUtil.loginClient with existing Kerberos login#8002

Open
jinhyukify wants to merge 1 commit intoapache:masterfrom
jinhyukify:HBASE-30042
Open

HBASE-30042 Test AuthUtil.loginClient with existing Kerberos login#8002
jinhyukify wants to merge 1 commit intoapache:masterfrom
jinhyukify:HBASE-30042

Conversation

@jinhyukify
Copy link
Copy Markdown
Contributor


@Test
public void testAuthUtilLogin() throws Exception {
public void testAuthUtilLoginWithExistingLoginUser() throws Exception {
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's update this test to only cover the case where a Kerberos user is already logged in.

conf.set(AuthUtil.HBASE_CLIENT_KEYTAB_FILE, clientKeytab);
conf.set(AuthUtil.HBASE_CLIENT_KERBEROS_PRINCIPAL, clientPrincipal);
UserGroupInformation.setConfiguration(conf);
UserGroupInformation.loginUserFromKeytab(clientPrincipal, clientKeytab);
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, this issue has been bothering me for a while, and I can confirm this makes the test pass.

However, if we do this, we no longer test if AuthUtil.loginClient actually performs the login for the user. I think we could create a separate user principal, log in as that user, and then test whether ⁠AuthUtil.loginClient correctly logs in the original user and returns that user.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants