This is an automated email from the ASF dual-hosted git repository. github-actions[bot] pushed a commit to branch cherry-pick-5b1e3d79-to-branch-1.3 in repository https://gitbox.apache.org/repos/asf/gravitino.git
commit bd2a409b6d6309f9f830100c09f90b1f8ff9905b Author: Yuhui <[email protected]> AuthorDate: Wed Sep 23 18:21:10 2026 +0800 [#13472] docs(trino-connector): Document authType=basic forwardUser limitation (#13473) ### What changes were proposed in this pull request? Documents that `gravitino.client.session.forwardUser` does not support `authType=basic`, and explains why. ### Why are the changes needed? `authType=basic` requires a real password, but Trino's SPI does not propagate the session user's password to connectors after coordinator-side authentication, so it cannot support forwardUser like `simple`/`oauth2` do. Without this note, users may assume `basic` behaves the same as the other auth types and be surprised that every Trino query is authorized as the connector's fixed configured user rather than the individual session user. Fix: #13472 ### Does this PR introduce any user-facing change? Documentation only — no code change. ### How was this patch tested? Docs-only change; no tests required. Co-authored-by: Claude Sonnet 5 <[email protected]> --- docs/trino-connector/authentication.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/trino-connector/authentication.md b/docs/trino-connector/authentication.md index d95c926c1b..6f44668034 100644 --- a/docs/trino-connector/authentication.md +++ b/docs/trino-connector/authentication.md @@ -156,6 +156,8 @@ gravitino.client.kerberos.keytabFilePath=/path/to/user.keytab Setting `gravitino.client.session.forwardUser=true` creates a dedicated Gravitino client per Trino session user, so each user is visible in the Gravitino audit log instead of the shared `gravitino.user` or service identity. It is supported with `authType=simple` and `authType=oauth2`. For OAuth2 sessions without a forwarded token, the connector reuses the shared service metadata instead. +`authType=basic` does not support forwarding, and setting `forwardUser=true` with `authType=basic` fails at connector startup — Trino's SPI does not propagate the session user's password to connectors after coordinator-side authentication, so there is no credential to forward. With `authType=basic`, every Trino query is authorized against Gravitino as the configured `gravitino.client.basic.username`, not the individual Trino session user; Gravitino-side per-user authorization (e.g. table [...] + **Configuration (`authType=simple`):** ```properties
