ranger.pdp.authn.jwt.audiences
diff --git a/pdp/src/main/java/org/apache/ranger/pdp/RangerPdpServer.java b/pdp/src/main/java/org/apache/ranger/pdp/RangerPdpServer.java
index a3027184fe..dc74e0716a 100644
--- a/pdp/src/main/java/org/apache/ranger/pdp/RangerPdpServer.java
+++ b/pdp/src/main/java/org/apache/ranger/pdp/RangerPdpServer.java
@@ -230,7 +230,6 @@ private void addAuthFilter(Context ctx) {
authFilterDef.addInitParameter(RangerPdpConstants.PROP_AUTHN_JWT_ENABLED, Boolean.toString(config.isJwtAuthnEnabled()));
authFilterDef.addInitParameter(RangerPdpConstants.PROP_AUTHN_JWT_PROVIDER_URL, config.getJwtProviderUrl());
authFilterDef.addInitParameter(RangerPdpConstants.PROP_AUTHN_JWT_PUBLIC_KEY, config.getJwtPublicKey());
- authFilterDef.addInitParameter(RangerPdpConstants.PROP_AUTHN_JWT_COOKIE_NAME, config.getJwtCookieName());
authFilterDef.addInitParameter(RangerPdpConstants.PROP_AUTHN_JWT_AUDIENCES, config.getJwtAudiences());
// Kerberos / SPNEGO
diff --git a/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConfig.java b/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConfig.java
index 11aea39ea8..68b8e687b3 100644
--- a/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConfig.java
+++ b/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConfig.java
@@ -156,10 +156,6 @@ public String getJwtPublicKey() {
return get(RangerPdpConstants.PROP_AUTHN_JWT_PUBLIC_KEY, "");
}
- public String getJwtCookieName() {
- return get(RangerPdpConstants.PROP_AUTHN_JWT_COOKIE_NAME, "hadoop-jwt");
- }
-
public String getJwtAudiences() {
return get(RangerPdpConstants.PROP_AUTHN_JWT_AUDIENCES, "");
}
diff --git a/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConstants.java b/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConstants.java
index c1a4313514..c195185408 100644
--- a/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConstants.java
+++ b/pdp/src/main/java/org/apache/ranger/pdp/config/RangerPdpConstants.java
@@ -71,7 +71,6 @@ private RangerPdpConstants() {
public static final String PROP_AUTHN_JWT_ENABLED = PROP_AUTHN_JWT_PREFIX + "enabled";
public static final String PROP_AUTHN_JWT_PROVIDER_URL = PROP_AUTHN_JWT_PREFIX + "provider.url";
public static final String PROP_AUTHN_JWT_PUBLIC_KEY = PROP_AUTHN_JWT_PREFIX + "public.key";
- public static final String PROP_AUTHN_JWT_COOKIE_NAME = PROP_AUTHN_JWT_PREFIX + "cookie.name";
public static final String PROP_AUTHN_JWT_AUDIENCES = PROP_AUTHN_JWT_PREFIX + "audiences";
// Kerberos/SPNEGO auth
diff --git a/pdp/src/main/java/org/apache/ranger/pdp/security/JwtAuthNHandler.java b/pdp/src/main/java/org/apache/ranger/pdp/security/JwtAuthNHandler.java
index 4e45c00311..6c9a33840a 100644
--- a/pdp/src/main/java/org/apache/ranger/pdp/security/JwtAuthNHandler.java
+++ b/pdp/src/main/java/org/apache/ranger/pdp/security/JwtAuthNHandler.java
@@ -33,15 +33,14 @@
/**
* Authenticates requests using a JWT bearer token.
*
- * Checks for the token in the {@code Authorization: Bearer } header first,
- * then in the configured JWT cookie. Delegates signature verification and expiry/audience
+ * Checks for the token in the {@code Authorization: Bearer } header
+ * Delegates signature verification and expiry/audience
* checks to {@link RangerDefaultJwtAuthHandler} from the {@code ranger-authn} module.
*
* Configuration keys (all prefixed with {@code ranger.pdp.authn.jwt.}):
*
* - {@code provider.url} – JWKS endpoint URL (optional if public key is set)
*
- {@code public.key} – PEM-encoded public key (optional if provider URL is set)
- *
- {@code cookie.name} – JWT cookie name (default: {@code hadoop-jwt})
*
- {@code audiences} – comma-separated list of accepted audiences (optional)
*
*/
@@ -58,7 +57,6 @@ public void init(Properties config) throws Exception {
copyIfPresent(config, RangerPdpConstants.PROP_AUTHN_JWT_PROVIDER_URL, jwtConfig, RangerDefaultJwtAuthHandler.KEY_PROVIDER_URL);
copyIfPresent(config, RangerPdpConstants.PROP_AUTHN_JWT_PUBLIC_KEY, jwtConfig, RangerDefaultJwtAuthHandler.KEY_JWT_PUBLIC_KEY);
- copyIfPresent(config, RangerPdpConstants.PROP_AUTHN_JWT_COOKIE_NAME, jwtConfig, RangerDefaultJwtAuthHandler.KEY_JWT_COOKIE_NAME);
copyIfPresent(config, RangerPdpConstants.PROP_AUTHN_JWT_AUDIENCES, jwtConfig, RangerDefaultJwtAuthHandler.KEY_JWT_AUDIENCES);
delegate = new RangerDefaultJwtAuthHandler();
diff --git a/pdp/src/main/resources/ranger-pdp-default.xml b/pdp/src/main/resources/ranger-pdp-default.xml
index ddf2ff9346..758573e70e 100644
--- a/pdp/src/main/resources/ranger-pdp-default.xml
+++ b/pdp/src/main/resources/ranger-pdp-default.xml
@@ -163,12 +163,6 @@
PEM-encoded public key for verifying JWT signatures.
-