CalvinKirs opened a new pull request, #68549:
URL: https://github.com/apache/doris/pull/68549

   ### What problem does this PR solve?
   
   Issue Number: None
   
   Related PR: #32643
   
   Problem Summary:
   
   `BaseController.checkWithCookie(request, response, true)` is what 
`AuthInterceptor` runs for
   the Web UI endpoints under `/rest/v1`, and what `/rest/v1/login` runs. It 
accepts either a
   session cookie or an HTTP Basic `Authorization` header, and the two branches 
did not apply the
   same checks:
   
   - session cookie: `ADMIN_OR_NODE` whenever `checkAuth` is true;
   - HTTP Basic: `ADMIN_OR_NODE` only in cloud mode.
   
   #32643 added the cloud overdue-warehouse check to the HTTP Basic branch by 
turning
   `if (checkAuth)` into `if (Config.isCloudMode() && checkAuth)`, which also 
put the existing
   `ADMIN_OR_NODE` check under the cloud-only condition. branch-2.1, which 
predates #32643, still
   applies it in both branches.
   
   The fix:
   
   - The HTTP Basic branch applies `ADMIN_OR_NODE` whenever `checkAuth` is 
true, in every
     deployment mode, like the cookie branch. Only the overdue check stays 
cloud-only, through the
     existing `checkInstanceOverdueIfCloud`. Cloud mode behaves exactly as 
before.
   - `/rest/v1/login` is the other caller passing `checkAuth = true`. The new 
Web UI
     (`ui/src/api/auth.ts`) expects login to accept any valid account and 
leaves the ADMIN
     decision to `/rest/v1/ui/me`, so that it can say "not authorized" rather 
than "sign-in
     failed". Login now only authenticates (`checkWithCookie(.., false)` plus 
the overdue check),
     which keeps that working. The session it issues still goes through the 
cookie branch's check
     on every later `/rest/v1` request.
   
   ### Release note
   
   Outside cloud mode, HTTP Basic requests to the Web UI endpoints under 
`/rest/v1` now go through
   the same ADMIN/NODE check as session-cookie requests. `/rest/v1/login` 
accepts any valid
   account in every deployment mode; the Web UI then reports an account without 
ADMIN as not
   authorized to use the console.
   
   ### Check List (For Author)
   
   - Test <!-- At least one of them must be included. -->
       - [x] Regression test: `auth_p0/test_http_rest_v1_auth` (new)
       - [x] Unit Test: `BaseControllerBasicAuthTest` (new), 
`UiAuthInterceptorTest`, `WebSqlAuthInterceptorTest`
       - [ ] Manual test (add detailed scripts or steps below)
       - [ ] No need to test or manual test. Explain why:
           - [ ] This is a refactor/code format and no logic has been changed.
           - [ ] Previous test can cover this change.
           - [ ] No code files have been changed.
           - [ ] Other reason <!-- Add your reason?  -->
   
   - Behavior changed:
       - [ ] No.
       - [x] Yes. Outside cloud mode, HTTP Basic callers of `/rest/v1/*` 
without ADMIN or NODE now get `code: 401`, as cookie callers already did. In 
cloud mode, `/rest/v1/login` now accepts an account without ADMIN or NODE; the 
endpoints behind it still turn it away.
   
   - Does this need documentation?
       - [x] No.
       - [ ] Yes. <!-- Add document PR link here. eg: 
https://github.com/apache/doris-website/pull/1214 -->
   
   ### Check List (For Reviewer who merge this PR)
   
   - [ ] Confirm the release note
   - [ ] Confirm test cases
   - [ ] Confirm document
   - [ ] Add branch pick label <!-- Add branch pick label that this PR should 
merge into -->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to