danhuawang opened a new issue, #9266:
URL: https://github.com/apache/gravitino/issues/9266

   ### What would you like to be improved?
   
   There's no access control for the open api list objects for tag 
https://gravitino.apache.org/docs/1.0.1/api/rest/list-tag-objects 
   
   I can list objects for tag with any user
   
   <img width="934" height="543" alt="Image" 
src="https://github.com/user-attachments/assets/1982dbb9-4729-421c-8448-e7aae1dd2bc9";
 />
   
   ### How should we improve?
   
   Implement the access control like the description in access control doc:
   
   <meta charset="utf-8"><b style="font-weight:normal;" 
id="docs-internal-guid-d5c0167d-7fff-2eea-d8ac-37ba04e35200"><div dir="ltr" 
style="margin-left:0pt;" align="left">
   list objects for tag | Requires both permission to get the tag and 
permission to load metadata objects.
   -- | --
   
   
   </div></b>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to