gianm opened a new pull request, #20075:
URL: https://github.com/apache/druid/pull/20075

   This patch adds a SchemaProvider interface, which can provide schemas based 
on the identity of the current user. SqlBindings#addSchemaProvider can be used 
by extension to add such providers.
   
   In core, this patch moves the "druid", "view", and "sys" schemas to use 
schema providers that filter out unauthorized tables and views. This improves 
the behavior for unauthorized tables. Previously unauthorized tables were 
explicitly filtered out of InformationSchema, so users could not see them in 
metadata queries. However, they were visible to the validator, so a query that 
explicitly named such a table would return a "Forbidden" error. Now the error 
is "table not found".
   
   To preserve the functioning of view expansion, views are now expanded using 
an escalated schema. Comments about the view security model are added to 
ViewManager's javadoc.
   
   To ensure that table validation happens as expected at ingestion time, 
INSERT and REPLACE now require READ access (in addition to WRITE) on the target 
table.
   
   A new configuration option "druid.sql.planner.authorizeTableVisibility" 
(default true) is added. If set explicitly to false, the old behavior is 
restored.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to