Skip to content

TLS-required check for authentication does not cover Authorization headers passed via http_session / http_headers #642

Description

@aminghadersohi

Since 0.339.0, trino.dbapi.Connection raises TrinoAuthError when an auth object is combined with http_scheme="http". That keeps credentials off a plaintext connection. The check only looks at auth, though. Credentials can reach the server in two other ways, and neither is checked:

  • an http_session whose headers already contain Authorization. Frameworks use this to forward a per-user OAuth2 bearer token.
  • an Authorization entry in http_headers.

In both cases the header is sent in cleartext over HTTP before the server can reject it. A server without insecure authentication answers 403 Authentication over HTTP is not enabled, but by then the token has already been sent.

Reproduced with 0.339.0 against Trino 483 (plain-HTTP port, JWT authenticator on HTTPS):

import requests, trino

session = requests.Session()
session.headers["Authorization"] = "Bearer <token>"
conn = trino.dbapi.connect(host="localhost", port=8080, user="u",
                           http_scheme="http", http_session=session)
conn.cursor().execute("SELECT 1")   # header goes out over HTTP; server returns 403

Suggestion: apply the same client-side check when http_session.headers or http_headers carries an Authorization header and the scheme is HTTP. Honour the existing insecure-auth opt-out.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions