CalvinKirs opened a new pull request, #68555:
URL: https://github.com/apache/doris/pull/68555

   ### What problem does this PR solve?
   
   Issue Number: None
   
   Related PR: #32825
   
   Problem Summary:
   
   #32825 added Rule 4 to `GrantTablePrivilegeCommand.checkTablePrivileges`: a
   non-admin user issuing GRANT/REVOKE must hold GRANT_PRIV together with the
   privileges being granted. Column-level privileges are split out of the
   statement into `colPrivileges`, but Rule 4 only builds its predicate from the
   table-level `privileges`, so for column-level privileges only GRANT_PRIV was
   checked. This is inconsistent with table-level privileges.
   
   Fix: add Rule 6 after Rule 5 (which ensures column privileges target a
   specific table). For every column privilege in the statement, a non-admin
   grantor must hold that privilege on the table (directly or inherited from
   database/catalog/global level) or on each listed column. The check reuses
   `AccessControllerManager.checkColumnsPriv`, the same entry used by query
   analysis. GRANT_PRIV is still required by Rule 4. REVOKE reuses the same
   check.
   
   ### Release note
   
   GRANT/REVOKE of column-level SELECT_PRIV by a non-admin user now also 
requires
   SELECT_PRIV on the table or on the listed columns, the same as table-level
   privileges.
   
   ### Check List (For Author)
   
   - Test: Regression test / Unit Test
       - FE UT: GrantTablePrivilegeCommandTest, RevokeTablePrivilegeCommandTest
       - Regression: account_p0/test_grant_col_priv, account_p0/test_grant_priv,
         query_p0/authorization/column_authorization,
         auth_p0/test_select_column_auth
   - Behavior changed: Yes. GRANT/REVOKE of column-level SELECT_PRIV by a
     non-admin user requires the corresponding SELECT_PRIV, the same as
     table-level privileges.
   - Does this need documentation: No
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to