Skip to content

[fix][proxy] Refresh auth data if ProxyLookupRequests - #20067

Merged
michaeljmarshall merged 14 commits into
apache:masterfrom
michaeljmarshall:pip-257-proxy-token-refresh
Apr 11, 2023
Merged

[fix][proxy] Refresh auth data if ProxyLookupRequests#20067
michaeljmarshall merged 14 commits into
apache:masterfrom
michaeljmarshall:pip-257-proxy-token-refresh

Conversation

@michaeljmarshall

@michaeljmarshall michaeljmarshall commented Apr 11, 2023

Copy link
Copy Markdown
Member

Fixes: #10816
PIP: #19771
Supersedes: #19026
Depends on: #20062

Motivation

The Pulsar Proxy does not properly handle authentication data refresh when in state ProxyLookupRequests. The consequence is described in #10816. Essentially, the problem is that the proxy caches stale authentication data and sends it to the broker leading to connection failures.

#17831 attempted to fix the underlying problem, but it missed an important edge cases. Specifically, it missed the case that the ConnectionPool will have multiple connections when a lookup gets redirected. As such, the following problem exists (and is fixed by this PR):

  1. Client opens connection to perform lookups.
  2. Proxy connects to broker 1 to get the topic ownership info.
  3. Time passes.
  4. Client does an additional lookup, and this topic is on a newly created broker 2. In this case, the proxy opens a new connection with the stale client auth data.
  5. Broker 2 rejects the connection because it fails with expired authentication.

Modifications

  • Remove some of the implementation from [fix][proxy] Fix refresh client auth #17831. This new implementation still allows a broker to challenge the client through the proxy, but notably, it limits the number of challenges sent to the client. Further, the proxy does not challenge the client when the auth data is not expired.
  • Introduce authentication refresh in the proxy so that the proxy challenges the client any time the auth data is expired.
  • Update the ProxyClientCnx to get the clientAuthData from the ProxyConnection to ensure that it gets new authentication data.
  • Add clock skew to the AuthenticationProviderToken. This is necessary to make some of the testing not flaky and it will also be necessary for users to configure in their clusters.

Verifying this change

The ProxyRefreshAuthTest covers the existing behavior and I expanded it to cover the edge case described above.

Additionally, testing this part of the code will be much easier to test once we implement #19624.

Documentation

  • doc-not-needed

Matching PR in forked repository

PR in forked repository: the relevant tests pass locally, so I am going to skip the forked tests.

@michaeljmarshall michaeljmarshall added type/bug The PR fixed a bug or issue reported a bug area/proxy doc-not-needed Your PR changes do not impact docs area/authn ready-to-test labels Apr 11, 2023
@michaeljmarshall michaeljmarshall self-assigned this Apr 11, 2023

@lhotari lhotari left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread pulsar-proxy/src/main/java/org/apache/pulsar/proxy/server/ProxyConnection.java Outdated
Comment thread pulsar-proxy/src/main/java/org/apache/pulsar/proxy/server/ProxyConnection.java Outdated
Comment thread pulsar-proxy/src/main/java/org/apache/pulsar/proxy/server/ProxyConnection.java Outdated

@nodece nodece left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@michaeljmarshall michaeljmarshall added this to the 3.0.0 milestone Apr 11, 2023
@michaeljmarshall

Copy link
Copy Markdown
Member Author

@cbornet - I think this is a necessary bug fix for 3.0. Without it, OIDC will not work correctly through the pulsar proxy. This bug was not introduced recently, but it didn't matter until now because the OIDC work exposes the bug. I've been fighting with CI all day due to flaky tests (and some legitimate failures, too). If we're able to hold off on creating branch-3.0 just a little longer, I'd really appreciate it. Thanks!

@michaeljmarshall
michaeljmarshall merged commit 075b625 into apache:master Apr 11, 2023
@michaeljmarshall
michaeljmarshall deleted the pip-257-proxy-token-refresh branch April 11, 2023 20:39
michaeljmarshall added a commit to michaeljmarshall/pulsar that referenced this pull request Apr 20, 2023
Fixes: apache#10816
PIP: apache#19771
Supersedes: apache#19026
Depends on: apache#20062

The Pulsar Proxy does not properly handle authentication data refresh when in state `ProxyLookupRequests`. The consequence is described in apache#10816. Essentially, the problem is that the proxy caches stale authentication data and sends it to the broker leading to connection failures.

apache#17831 attempted to fix the underlying problem, but it missed an important edge cases. Specifically, it missed the case that the `ConnectionPool` will have multiple connections when a lookup gets redirected. As such, the following problem exists (and is fixed by this PR):

1. Client opens connection to perform lookups.
2. Proxy connects to broker 1 to get the topic ownership info.
3. Time passes.
4. Client does an additional lookup, and this topic is on a newly created broker 2. In this case, the proxy opens a new connection with the stale client auth data.
5. Broker 2 rejects the connection because it fails with expired authentication.

* Remove some of the implementation from apache#17831. This new implementation still allows a broker to challenge the client through the proxy, but notably, it limits the number of challenges sent to the client. Further, the proxy does not challenge the client when the auth data is not expired.
* Introduce authentication refresh in the proxy so that the proxy challenges the client any time the auth data is expired.
* Update the `ProxyClientCnx` to get the `clientAuthData` from the `ProxyConnection` to ensure that it gets new authentication data.
* Add clock skew to the `AuthenticationProviderToken`. This is necessary to make some of the testing not flaky and it will also be necessary for users to configure in their clusters.

The `ProxyRefreshAuthTest` covers the existing behavior and I expanded it to cover the edge case described above.

Additionally, testing this part of the code will be much easier to test once we implement apache#19624.

- [x] `doc-not-needed`

PR in forked repository: the relevant tests pass locally, so I am going to skip the forked tests.

(cherry picked from commit 075b625)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/authn area/proxy doc-not-needed Your PR changes do not impact docs ready-to-test type/bug The PR fixed a bug or issue reported a bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PulsarProxy does not always refresh authentication tokens received from client

4 participants