fix: clear inherited credential on token-exchange derived sessions - #17602
Open
waterWang wants to merge 1 commit into
Open
fix: clear inherited credential on token-exchange derived sessions#17602waterWang wants to merge 1 commit into
waterWang wants to merge 1 commit into
Conversation
uros-b
reviewed
Aug 11, 2026
uros-b
left a comment
Member
There was a problem hiding this comment.
@waterWang Is this already in progress (#17601)? cc @bharos
Contributor
@waterWang I already have a PR out for the fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #17600
Problem
When
token-exchange-enabledis set tofalse, a session created by token exchange (AuthSession.fromTokenExchange) inherits the parent catalog config — includingcredentialandexchangeEnabled=false. On refresh,OAuth2Util.refreshTokenchecksexchangeEnabled, finds itfalse, and falls back to theclient_credentialsflow using the inherited credential. The refreshed token now identifies the catalog client rather than the exchanged subject, silently changing the session identity.Root cause
AuthSession.fromTokenExchangecallsfromTokenResponse, which copies the parent config viaAuthConfig.builder().from(parent.config()). This propagates bothcredentialandexchangeEnabled=falseto the child session. TheexchangeEnabledflag was intended by #13809 to control how credential-derived sessions refresh, but applying it to token-exchange-derived sessions changes which principal the session represents.Fix
After building the session from
fromTokenResponse, clear the inheritedcredentialand setexchangeEnabled=trueon the child session. This ensures that:exchangeEnabledflag only affects catalog-level credential-derived sessions as intended