[ https://issues.apache.org/jira/browse/HIVE-25957?focusedWorklogId=729213&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-729213 ]
ASF GitHub Bot logged work on HIVE-25957: ----------------------------------------- Author: ASF GitHub Bot Created on: 17/Feb/22 20:02 Start Date: 17/Feb/22 20:02 Worklog Time Spent: 10m Work Description: yongzhi merged pull request #3028: URL: https://github.com/apache/hive/pull/3028 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org Issue Time Tracking ------------------- Worklog Id: (was: 729213) Time Spent: 1.5h (was: 1h 20m) > Fix password based authentication with SAML enabled > --------------------------------------------------- > > Key: HIVE-25957 > URL: https://issues.apache.org/jira/browse/HIVE-25957 > Project: Hive > Issue Type: Bug > Components: HiveServer2 > Affects Versions: 4.0.0 > Reporter: Yu-Wen Lai > Assignee: Yu-Wen Lai > Priority: Major > Labels: pull-request-available > Time Spent: 1.5h > Remaining Estimate: 0h > > In HIVE-25875, we allowed SAML to be set with other password based > authentication, but we pass NONE to the function doPasswordAuth. That is, any > requests use basic authentication header can bypass the password verification > because NONE means a no-op authentication. -- This message was sent by Atlassian Jira (v8.20.1#820001)