dkranchii opened a new pull request, #18251:
URL: https://github.com/apache/iceberg/pull/18251
## Which Iceberg project does this PR belong to?
Core / REST
## What changes are proposed in this pull request?
Addresses the question raised in #17518, where `AuthSessionCache`'s use of
`expireAfterAccess` was read as a bug that keeps expired auth sessions alive.
The current policy is intentional and this PR does not change it. An
`AuthSession`
keeps its own token fresh through `OAuth2Util.scheduleTokenRefresh`, so the
cache
timeout governs *idleness* — evict sessions nobody is using — and is
deliberately
decoupled from token lifetime. Switching to `expireAfterWrite` would force
re-authentication on healthy long-lived sessions, and would not help a
session
configured with a static `token`, which reloads to the same value.
The 401s reported in the issue were traced by the reporter to constructing
`RESTCatalog` with an empty `SessionContext`. The separate case where a
session
holds a dead token after its refresh chain gives up is tracked in #17756 and
patched by #17768; that is out of scope here.
What this PR changes:
- Document on `AuthSessionCache` that eviction tracks inactivity and that
keeping
credentials valid is the session's own responsibility.
- Record that rationale in a short comment at the `expireAfterAccess` call,
which is
the line the issue points to.
- Add javadoc to `CatalogProperties.AUTH_SESSION_TIMEOUT_MS`, which had none.
- Add `accessRenewsSessionLifetime`, which pins the semantics: a repeatedly
requested
session is retained well past the timeout without being reloaded, then is
evicted
and closed once access stops.
No behavior change.
## Tests
`accessRenewsSessionLifetime` fails under `expireAfterWrite` on both the
loader-invocation count and the premature `close()`, so the policy cannot be
flipped
silently. Existing `TestAuthSessionCache` cases are unchanged.
---
**AI Disclosure**
- Platform/Tool: Cursor
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]