CalvinKirs opened a new pull request, #68549:
URL: https://github.com/apache/doris/pull/68549
### What problem does this PR solve?
Issue Number: None
Related PR: #32643
Problem Summary:
`BaseController.checkWithCookie(request, response, true)` is what
`AuthInterceptor` runs for
the Web UI endpoints under `/rest/v1`, and what `/rest/v1/login` runs. It
accepts either a
session cookie or an HTTP Basic `Authorization` header, and the two branches
did not apply the
same checks:
- session cookie: `ADMIN_OR_NODE` whenever `checkAuth` is true;
- HTTP Basic: `ADMIN_OR_NODE` only in cloud mode.
#32643 added the cloud overdue-warehouse check to the HTTP Basic branch by
turning
`if (checkAuth)` into `if (Config.isCloudMode() && checkAuth)`, which also
put the existing
`ADMIN_OR_NODE` check under the cloud-only condition. branch-2.1, which
predates #32643, still
applies it in both branches.
The fix:
- The HTTP Basic branch applies `ADMIN_OR_NODE` whenever `checkAuth` is
true, in every
deployment mode, like the cookie branch. Only the overdue check stays
cloud-only, through the
existing `checkInstanceOverdueIfCloud`. Cloud mode behaves exactly as
before.
- `/rest/v1/login` is the other caller passing `checkAuth = true`. The new
Web UI
(`ui/src/api/auth.ts`) expects login to accept any valid account and
leaves the ADMIN
decision to `/rest/v1/ui/me`, so that it can say "not authorized" rather
than "sign-in
failed". Login now only authenticates (`checkWithCookie(.., false)` plus
the overdue check),
which keeps that working. The session it issues still goes through the
cookie branch's check
on every later `/rest/v1` request.
### Release note
Outside cloud mode, HTTP Basic requests to the Web UI endpoints under
`/rest/v1` now go through
the same ADMIN/NODE check as session-cookie requests. `/rest/v1/login`
accepts any valid
account in every deployment mode; the Web UI then reports an account without
ADMIN as not
authorized to use the console.
### Check List (For Author)
- Test <!-- At least one of them must be included. -->
- [x] Regression test: `auth_p0/test_http_rest_v1_auth` (new)
- [x] Unit Test: `BaseControllerBasicAuthTest` (new),
`UiAuthInterceptorTest`, `WebSqlAuthInterceptorTest`
- [ ] Manual test (add detailed scripts or steps below)
- [ ] No need to test or manual test. Explain why:
- [ ] This is a refactor/code format and no logic has been changed.
- [ ] Previous test can cover this change.
- [ ] No code files have been changed.
- [ ] Other reason <!-- Add your reason? -->
- Behavior changed:
- [ ] No.
- [x] Yes. Outside cloud mode, HTTP Basic callers of `/rest/v1/*`
without ADMIN or NODE now get `code: 401`, as cookie callers already did. In
cloud mode, `/rest/v1/login` now accepts an account without ADMIN or NODE; the
endpoints behind it still turn it away.
- Does this need documentation?
- [x] No.
- [ ] Yes. <!-- Add document PR link here. eg:
https://github.com/apache/doris-website/pull/1214 -->
### Check List (For Reviewer who merge this PR)
- [ ] Confirm the release note
- [ ] Confirm test cases
- [ ] Confirm document
- [ ] Add branch pick label <!-- Add branch pick label that this PR should
merge into -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]