This is an automated email from the ASF dual-hosted git repository.
bharos pushed a commit to branch branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/branch-1.3 by this push:
new 6e668e0262 [Cherry-pick to branch-1.3] [#13472] docs(trino-connector):
Document authType=basic forwardUser limitation (#13473) (#13485)
6e668e0262 is described below
commit 6e668e02629bb53ff053f3e39c32e14e5d28385c
Author: github-actions[bot]
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Wed Sep 23 12:56:23 2026 -0700
[Cherry-pick to branch-1.3] [#13472] docs(trino-connector): Document
authType=basic forwardUser limitation (#13473) (#13485)
**Cherry-pick Information:**
- Original commit: 5b1e3d792a3dbb54fc673009d020d219501d9ee8
- Target branch: `branch-1.3`
- Status: ✅ Clean cherry-pick (no conflicts)
Co-authored-by: Yuhui <[email protected]>
Co-authored-by: Claude Sonnet 5 <[email protected]>
---
docs/trino-connector/authentication.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/docs/trino-connector/authentication.md
b/docs/trino-connector/authentication.md
index d95c926c1b..6f44668034 100644
--- a/docs/trino-connector/authentication.md
+++ b/docs/trino-connector/authentication.md
@@ -156,6 +156,8 @@
gravitino.client.kerberos.keytabFilePath=/path/to/user.keytab
Setting `gravitino.client.session.forwardUser=true` creates a dedicated
Gravitino client per Trino session user, so each user is visible in the
Gravitino audit log instead of the shared `gravitino.user` or service identity.
It is supported with `authType=simple` and `authType=oauth2`. For OAuth2
sessions without a forwarded token, the connector reuses the shared service
metadata instead.
+`authType=basic` does not support forwarding, and setting `forwardUser=true`
with `authType=basic` fails at connector startup — Trino's SPI does not
propagate the session user's password to connectors after coordinator-side
authentication, so there is no credential to forward. With `authType=basic`,
every Trino query is authorized against Gravitino as the configured
`gravitino.client.basic.username`, not the individual Trino session user;
Gravitino-side per-user authorization (e.g. table [...]
+
**Configuration (`authType=simple`):**
```properties