LiJie20190102 opened a new pull request, #13022:
URL: https://github.com/apache/gravitino/pull/13022
<!--
1. Title: [#<issue>] <type>(<scope>): <subject>
Examples:
- "[#123] feat(operator): Support xxx"
- "[#233] fix: Check null before access result in xxx"
- "[MINOR] refactor: Fix typo in variable name"
- "[MINOR] docs: Fix typo in README"
- "[#255] test: Fix flaky test NameOfTheTest"
Reference: https://www.conventionalcommits.org/en/v1.0.0/
2. If the PR is unfinished, please mark this PR as draft.
-->
### What changes were proposed in this pull request?
CreateTable(mode=exist_ok) and CreateNamespace(mode=exist_ok) return the
existing object's metadata (location, properties, schema) when the object
already exists, but the authorization interceptor only checked CREATE_TABLE /
CREATE_SCHEMA privileges. A caller without read privileges could therefore
obtain metadata that DescribeTable or DescribeNamespace would deny.
Add EXIST_OK_TABLE_AUTHORIZATION_EXPRESSION and
EXIST_OK_NAMESPACE_AUTHORIZATION_EXPRESSION that require the same read
privilege as a describe request. Extend OverwriteAuthzHandler to
CreateModeAuthzHandler so that exist_ok mode is authorized against the read
expression before the method proceeds, in addition to the existing overwrite
handling.
The mode alone decides the authorization path, without probing whether the
object exists, avoiding the TOCTOU race that an existence probe at
authorization time would introduce.
### Why are the changes needed?
(Please clarify why the changes are needed. For instance,
1. If you propose a new API, clarify the use case for a new API.
2. If you fix a bug, describe the bug.)
Fix: #12955
### Does this PR introduce _any_ user-facing change?
(Please list the user-facing changes introduced by your change, including
1. Change in user-facing APIs.
2. Addition or removal of property keys.)
### How was this patch tested?
(Please test your changes, and provide instructions on how to test it:
1. If you add a feature or fix a bug, add a test to cover your changes.
2. If you fix a flaky test, repeat it for many times to prove it works.)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]