Description
When kerberos authentication is not enabled, we should let the timeline server to work with pseudo authentication filter. In this way, the sever is able to detect the request user by checking "user.name".
On the other hand, timeline client should append "user.name" in un-secure case as well, such that ACLs can keep working in this case.