rdblue commented on issue #16487:
URL: https://github.com/apache/iceberg/issues/16487#issuecomment-4510175252

   I agree, this is already deprecated. I think the report is also exaggerating 
the issue with the unsecured token. The intent of that is to allow a trusted 
engine to pass its user identity information. Since the engine is trusted, this 
is equivalent to the `referenced-by` addition we recently added that also 
passes context that must come from a trusted engine without a signature. This 
interpretation misunderstands the trust chain and is not valid.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to