Since 0.339.0, trino.dbapi.Connection raises TrinoAuthError when an auth object is combined with http_scheme="http". That keeps credentials off a plaintext connection. The check only looks at auth, though. Credentials can reach the server in two other ways, and neither is checked:
- an
http_session whose headers already contain Authorization. Frameworks use this to forward a per-user OAuth2 bearer token.
- an
Authorization entry in http_headers.
In both cases the header is sent in cleartext over HTTP before the server can reject it. A server without insecure authentication answers 403 Authentication over HTTP is not enabled, but by then the token has already been sent.
Reproduced with 0.339.0 against Trino 483 (plain-HTTP port, JWT authenticator on HTTPS):
import requests, trino
session = requests.Session()
session.headers["Authorization"] = "Bearer <token>"
conn = trino.dbapi.connect(host="localhost", port=8080, user="u",
http_scheme="http", http_session=session)
conn.cursor().execute("SELECT 1") # header goes out over HTTP; server returns 403
Suggestion: apply the same client-side check when http_session.headers or http_headers carries an Authorization header and the scheme is HTTP. Honour the existing insecure-auth opt-out.
Since 0.339.0,
trino.dbapi.ConnectionraisesTrinoAuthErrorwhen anauthobject is combined withhttp_scheme="http". That keeps credentials off a plaintext connection. The check only looks atauth, though. Credentials can reach the server in two other ways, and neither is checked:http_sessionwhose headers already containAuthorization. Frameworks use this to forward a per-user OAuth2 bearer token.Authorizationentry inhttp_headers.In both cases the header is sent in cleartext over HTTP before the server can reject it. A server without insecure authentication answers
403 Authentication over HTTP is not enabled, but by then the token has already been sent.Reproduced with 0.339.0 against Trino 483 (plain-HTTP port, JWT authenticator on HTTPS):
Suggestion: apply the same client-side check when
http_session.headersorhttp_headerscarries anAuthorizationheader and the scheme is HTTP. Honour the existing insecure-auth opt-out.