This is an automated email from the ASF dual-hosted git repository.

github-actions[bot] pushed a commit to branch cherry-pick-5b1e3d79-to-branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git

commit bd2a409b6d6309f9f830100c09f90b1f8ff9905b
Author: Yuhui <[email protected]>
AuthorDate: Wed Sep 23 18:21:10 2026 +0800

    [#13472] docs(trino-connector): Document authType=basic forwardUser 
limitation (#13473)
    
    ### What changes were proposed in this pull request?
    
    Documents that `gravitino.client.session.forwardUser` does not support
    `authType=basic`, and explains why.
    
    ### Why are the changes needed?
    
    `authType=basic` requires a real password, but Trino's SPI does not
    propagate the session user's password to connectors after
    coordinator-side authentication, so it cannot support forwardUser like
    `simple`/`oauth2` do. Without this note, users may assume `basic`
    behaves the same as the other auth types and be surprised that every
    Trino query is authorized as the connector's fixed configured user
    rather than the individual session user.
    
    Fix: #13472
    
    ### Does this PR introduce any user-facing change?
    
    Documentation only — no code change.
    
    ### How was this patch tested?
    
    Docs-only change; no tests required.
    
    Co-authored-by: Claude Sonnet 5 <[email protected]>
---
 docs/trino-connector/authentication.md | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/docs/trino-connector/authentication.md 
b/docs/trino-connector/authentication.md
index d95c926c1b..6f44668034 100644
--- a/docs/trino-connector/authentication.md
+++ b/docs/trino-connector/authentication.md
@@ -156,6 +156,8 @@ 
gravitino.client.kerberos.keytabFilePath=/path/to/user.keytab
 
 Setting `gravitino.client.session.forwardUser=true` creates a dedicated 
Gravitino client per Trino session user, so each user is visible in the 
Gravitino audit log instead of the shared `gravitino.user` or service identity. 
It is supported with `authType=simple` and `authType=oauth2`. For OAuth2 
sessions without a forwarded token, the connector reuses the shared service 
metadata instead.
 
+`authType=basic` does not support forwarding, and setting `forwardUser=true` 
with `authType=basic` fails at connector startup — Trino's SPI does not 
propagate the session user's password to connectors after coordinator-side 
authentication, so there is no credential to forward. With `authType=basic`, 
every Trino query is authorized against Gravitino as the configured 
`gravitino.client.basic.username`, not the individual Trino session user; 
Gravitino-side per-user authorization (e.g. table [...]
+
 **Configuration (`authType=simple`):**
 
 ```properties

Reply via email to