morrySnow opened a new pull request, #68088:
URL: https://github.com/apache/doris/pull/68088
### What problem does this PR solve?
Issue Number: N/A
Related PR: N/A
Problem Summary:
The `binlog()` table-valued function resolved and scanned its target OLAP
table without checking the caller's table privileges. A user denied direct
`SELECT` on the table could still read row-binlog contents through the TVF.
This change checks `SELECT` on the target table before loading its metadata
and returns the same table access-denied error used by ordinary table scans.
### Release note
The `binlog()` table-valued function now requires `SELECT` privilege on its
target table.
### Check List (For Author)
- Test
- [x] Regression test
- [x] Unit Test
- [ ] Manual test (add detailed scripts or steps below)
- [ ] No need to test or manual test. Explain why:
- [ ] This is a refactor/code format and no logic has been changed.
- [ ] Previous test can cover this change.
- [ ] No code files have been changed.
- [ ] Other reason
Validation performed:
- `./run-fe-ut.sh --run
org.apache.doris.tablefunction.TableBinlogFunctionAuthTest`
- `mvn checkstyle:check -pl fe-core`
- Added `test_binlog_tvf_auth`; validated its Groovy syntax locally. Cluster
execution is left to CI.
- Behavior changed:
- [ ] No.
- [x] Yes. Unauthorized users can no longer query row-binlog content
through `binlog()`.
- Does this need documentation?
- [x] No.
- [ ] Yes.
### Check List (For Reviewer who merge this PR)
- [ ] Confirm the release note
- [ ] Confirm test cases
- [ ] Confirm document
- [ ] Add branch pick label
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]