This is an automated email from the ASF dual-hosted git repository.

bharos pushed a commit to branch branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git


The following commit(s) were added to refs/heads/branch-1.3 by this push:
     new 6e668e0262 [Cherry-pick to branch-1.3] [#13472] docs(trino-connector): 
Document authType=basic forwardUser limitation (#13473) (#13485)
6e668e0262 is described below

commit 6e668e02629bb53ff053f3e39c32e14e5d28385c
Author: github-actions[bot] 
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Wed Sep 23 12:56:23 2026 -0700

    [Cherry-pick to branch-1.3] [#13472] docs(trino-connector): Document 
authType=basic forwardUser limitation (#13473) (#13485)
    
    **Cherry-pick Information:**
    - Original commit: 5b1e3d792a3dbb54fc673009d020d219501d9ee8
    - Target branch: `branch-1.3`
    - Status: ✅ Clean cherry-pick (no conflicts)
    
    Co-authored-by: Yuhui <[email protected]>
    Co-authored-by: Claude Sonnet 5 <[email protected]>
---
 docs/trino-connector/authentication.md | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/docs/trino-connector/authentication.md 
b/docs/trino-connector/authentication.md
index d95c926c1b..6f44668034 100644
--- a/docs/trino-connector/authentication.md
+++ b/docs/trino-connector/authentication.md
@@ -156,6 +156,8 @@ 
gravitino.client.kerberos.keytabFilePath=/path/to/user.keytab
 
 Setting `gravitino.client.session.forwardUser=true` creates a dedicated 
Gravitino client per Trino session user, so each user is visible in the 
Gravitino audit log instead of the shared `gravitino.user` or service identity. 
It is supported with `authType=simple` and `authType=oauth2`. For OAuth2 
sessions without a forwarded token, the connector reuses the shared service 
metadata instead.
 
+`authType=basic` does not support forwarding, and setting `forwardUser=true` 
with `authType=basic` fails at connector startup — Trino's SPI does not 
propagate the session user's password to connectors after coordinator-side 
authentication, so there is no credential to forward. With `authType=basic`, 
every Trino query is authorized against Gravitino as the configured 
`gravitino.client.basic.username`, not the individual Trino session user; 
Gravitino-side per-user authorization (e.g. table [...]
+
 **Configuration (`authType=simple`):**
 
 ```properties

Reply via email to