Add failover to accessToken for OAuth2 with refresh token #14949
+14
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Right now when we can't deserialize tokens, that we expect to be encrypted we are failing authentication and send challenges to clients. With this change we will allow for further processing, in case when the format of the token is not parsable
This case occurs for cases when a tool sends valid accessToken obtained outside from Trino, but has configured Oauth2 with refresh tokens enabled, for other clients that benefit from that flow directly
Non-technical explanation
This allows people to send valid accessTokens through our clients, without the need to configure separate jwt authentication, which in terms allow for a single oauth2 implementation to support both direct and passthrough usages.
Release notes
( ) This is not user-visible or docs only and no release notes are required.
( ) Release notes are required, please propose a release note for me.
(x) Release notes are required, with the following suggested text: