CalvinKirs opened a new pull request, #68555:
URL: https://github.com/apache/doris/pull/68555
### What problem does this PR solve?
Issue Number: None
Related PR: #32825
Problem Summary:
#32825 added Rule 4 to `GrantTablePrivilegeCommand.checkTablePrivileges`: a
non-admin user issuing GRANT/REVOKE must hold GRANT_PRIV together with the
privileges being granted. Column-level privileges are split out of the
statement into `colPrivileges`, but Rule 4 only builds its predicate from the
table-level `privileges`, so for column-level privileges only GRANT_PRIV was
checked. This is inconsistent with table-level privileges.
Fix: add Rule 6 after Rule 5 (which ensures column privileges target a
specific table). For every column privilege in the statement, a non-admin
grantor must hold that privilege on the table (directly or inherited from
database/catalog/global level) or on each listed column. The check reuses
`AccessControllerManager.checkColumnsPriv`, the same entry used by query
analysis. GRANT_PRIV is still required by Rule 4. REVOKE reuses the same
check.
### Release note
GRANT/REVOKE of column-level SELECT_PRIV by a non-admin user now also
requires
SELECT_PRIV on the table or on the listed columns, the same as table-level
privileges.
### Check List (For Author)
- Test: Regression test / Unit Test
- FE UT: GrantTablePrivilegeCommandTest, RevokeTablePrivilegeCommandTest
- Regression: account_p0/test_grant_col_priv, account_p0/test_grant_priv,
query_p0/authorization/column_authorization,
auth_p0/test_select_column_auth
- Behavior changed: Yes. GRANT/REVOKE of column-level SELECT_PRIV by a
non-admin user requires the corresponding SELECT_PRIV, the same as
table-level privileges.
- Does this need documentation: No
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]