dkranchii opened a new pull request, #18251:
URL: https://github.com/apache/iceberg/pull/18251

   ## Which Iceberg project does this PR belong to?
   
   Core / REST
   
   ## What changes are proposed in this pull request?
   
   Addresses the question raised in #17518, where `AuthSessionCache`'s use of
   `expireAfterAccess` was read as a bug that keeps expired auth sessions alive.
   
   The current policy is intentional and this PR does not change it. An 
`AuthSession`
   keeps its own token fresh through `OAuth2Util.scheduleTokenRefresh`, so the 
cache
   timeout governs *idleness* — evict sessions nobody is using — and is 
deliberately
   decoupled from token lifetime. Switching to `expireAfterWrite` would force
   re-authentication on healthy long-lived sessions, and would not help a 
session
   configured with a static `token`, which reloads to the same value.
   
   The 401s reported in the issue were traced by the reporter to constructing
   `RESTCatalog` with an empty `SessionContext`. The separate case where a 
session
   holds a dead token after its refresh chain gives up is tracked in #17756 and
   patched by #17768; that is out of scope here.
   
   What this PR changes:
   
   - Document on `AuthSessionCache` that eviction tracks inactivity and that 
keeping
     credentials valid is the session's own responsibility.
   - Record that rationale in a short comment at the `expireAfterAccess` call, 
which is
     the line the issue points to.
   - Add javadoc to `CatalogProperties.AUTH_SESSION_TIMEOUT_MS`, which had none.
   - Add `accessRenewsSessionLifetime`, which pins the semantics: a repeatedly 
requested
     session is retained well past the timeout without being reloaded, then is 
evicted
     and closed once access stops.
   
   No behavior change.
   
   ## Tests
   
   `accessRenewsSessionLifetime` fails under `expireAfterWrite` on both the
   loader-invocation count and the premature `close()`, so the policy cannot be 
flipped
   silently. Existing `TestAuthSessionCache` cases are unchanged.
   
   ---
   **AI Disclosure**
   - Platform/Tool: Cursor
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to