{"record":{"id":"4a2b316e72d30dd5","repo":"apache/seatunnel","slug":"paimon-privilege-is-enabled-user-and-password-is","errorCode":null,"errorMessage":"paimon privilege is enabled, user and password is required","messagePattern":"paimon privilege is enabled, user and password is required","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-paimon/src/main/java/org/apache/seatunnel/connectors/seatunnel/paimon/catalog/PaimonCatalogLoader.java","lineNumber":115,"sourceCode":"            optionsMap.put(CatalogOptions.URI.key(), catalogUri);\n            optionsMap.putAll(paimonHadoopConfiguration.getPropsWithPrefix(StringUtils.EMPTY));\n        }\n        final Options options = Options.fromMap(optionsMap);\n        PaimonSecurityContext.shouldEnableKerberos(paimonHadoopConfiguration);\n        final CatalogContext catalogContext =\n                CatalogContext.create(options, paimonHadoopConfiguration);\n        try {\n            // If paimon privilege enabled, there will be system tables named user.sys and\n            // privilege.sys in the warehouse.\n            // It returns a PrivilegedCatalog. Otherwise, it returns a CachingCatalog.\n            // If paimon privilege enabled, perform user and password verification accordingly.\n            Catalog catalog =\n                    PaimonSecurityContext.runSecured(\n                            () -> CatalogFactory.createCatalog(catalogContext));\n            if (catalog instanceof PrivilegedCatalog\n                    && StringUtils.isBlank(user)\n                    && StringUtils.isBlank(password)) {\n                throw new IllegalArgumentException(\n                        \"paimon privilege is enabled, user and password is required\");\n            }\n            return catalog;\n        } catch (Exception e) {\n            throw new PaimonConnectorException(\n                    PaimonConnectorErrorCode.LOAD_CATALOG, e.getMessage(), e);\n        }\n    }\n\n    void checkConfiguration(Configuration configuration, String key) {\n        Iterator<Map.Entry<String, String>> entryIterator = configuration.iterator();\n        while (entryIterator.hasNext()) {\n            Map.Entry<String, String> entry = entryIterator.next();\n            if (entry.getKey().equals(key)) {\n                if (StringUtils.isBlank(entry.getValue())) {\n                    throw new IllegalArgumentException(\"The value of\" + key + \" is required\");\n                }\n                return;","sourceCodeStart":97,"sourceCodeEnd":133,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-paimon/src/main/java/org/apache/seatunnel/connectors/seatunnel/paimon/catalog/PaimonCatalogLoader.java#L97-L133","documentation":"PaimonCatalogLoader.loadCatalog creates the Paimon catalog and, if the resulting catalog is a PrivilegedCatalog (Paimon privilege/access-control enabled), verifies that user and password were supplied. When both are blank it throws IllegalArgumentException stating that user and password are required. Paimon privilege mode authenticates every operation, so anonymous access is rejected before any table operation runs.","triggerScenarios":"Creating a PaimonCatalogLoader/catalog where the Paimon conf enables its privilege/access-control layer (PrivilegedCatalog is instantiated) but the SeaTunnel options PaimonBaseOptions.USER and PaimonBaseOptions.PASSWORD are unset or empty strings.","commonSituations":"Migrating a SeaTunnel job from a privilege-free Paimon cluster to one with access control enabled; user/password configured in paimon-conf instead of the SeaTunnel options (they must be in the connector options); blanks/whitespace-only values.","solutions":["Set the paimon.user (USER) and paimon.password (PASSWORD) options in the SeaTunnel catalog/source/sink configuration.","Check the Paimon conf used via paimon-conf-dir/warehouse settings: if privilege is intentionally off, disable it so PrivilegedCatalog is not created.","Ensure values are non-blank (no whitespace-only strings) and valid for the Paimon privilege system.","If credentials come from a secrets manager, verify the substitution actually produced non-empty values."],"exampleFix":"// before\nPaimon {\n  warehouse = \"hdfs://ns/paimon\"\n}\n// after\nPaimon {\n  warehouse = \"hdfs://ns/paimon\"\n  user = \"etl_user\"\n  password = \"${PAIMON_PASSWORD}\"\n}","handlingStrategy":"validation","validationCode":"String user = options.get(PaimonBaseOptions.USER);\nString password = options.get(PaimonBaseOptions.PASSWORD);\nif (privilegeEnabled && (isBlank(user) || isBlank(password))) {\n    throw new ConfigValidationException(\"paimon user/password required\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    Catalog c = loader.loadCatalog();\n} catch (IllegalArgumentException e) {\n    if (e.getMessage().contains(\"user and password is required\")) {\n        throw new ConfigException(\"add paimon user/password options\");\n    }\n    throw e;\n}","preventionTips":["Always set user and password options when Paimon access control is on","Keep credentials in connector options, not only paimon-conf","Inject secrets via env vars and verify they resolve","Document privilege requirements when migrating clusters"],"tags":["paimon","authentication","missing-credentials","catalog"],"backgroundTag":"missing-credentials","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}