Skip to content

Return a generic 503 message when the metastore fails during authentication - #5363

Merged
adutra merged 1 commit into
apache:mainfrom
shyundev:fix/auth-503-generic-message
Aug 24, 2026
Merged

adutra merged 1 commit into
apache:mainfrom
shyundev:fix/auth-503-generic-message

Conversation

@shyundev

@shyundev shyundev commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to #5247, as agreed there: a client that is not yet authenticated should not learn which metastore lookup failed. The three 503s raised during authentication returned Unable to fetch principal entity, Unable to fetch principal grants and Unable to fetch securable entity; all three now return a fixed Service unavailable.

The suggestion there was to log the detail against a UUID handed back to the client. Nothing new has to be minted: the response already carries the request id as X-Request-ID, and the default log format prints the same id as requestId. That is the route #4406 took for the 403 path.

The three DefaultAuthenticatorTest metastore-failure tests now assert the response message.

Checklist

@github-project-automation github-project-automation Bot moved this to PRs In Progress in Basic Kanban Board Aug 24, 2026
@shyundev shyundev changed the title Stop naming the failing metastore lookup in authentication 503 responses Return a generic 503 message when the metastore fails during authentication Aug 24, 2026
@github-project-automation github-project-automation Bot moved this from PRs In Progress to Ready to merge in Basic Kanban Board Aug 24, 2026
@adutra
adutra enabled auto-merge (squash) August 24, 2026 15:16
@adutra
adutra merged commit a8ecbb2 into apache:main Aug 24, 2026
24 checks passed
@github-project-automation github-project-automation Bot moved this from Ready to merge to Done in Basic Kanban Board Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants