This is an automated email from the ASF dual-hosted git repository.

jerryshao pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git


The following commit(s) were added to refs/heads/main by this push:
     new ca8ca7f0f6 [#13217] fix(common): guard RoleDTO.securableObjects 
against a null Jackson field (#13220)
ca8ca7f0f6 is described below

commit ca8ca7f0f67d4deadc4e9639ea18c730e232cef0
Author: YangJie <[email protected]>
AuthorDate: Sun Sep 20 05:38:33 2026 -0400

    [#13217] fix(common): guard RoleDTO.securableObjects against a null Jackson 
field (#13220)
    
    ### What changes were proposed in this pull request?
    
    `RoleDTO.securableObjects()` is null-guarded to return an empty list,
    matching `SecurableObjectDTO.privileges()`. The builder validation is
    unchanged.
    
    ### Why are the changes needed?
    
    Jackson deserialization with `securableObjects` absent bypasses the
    builder's null check, and `Arrays.asList(null)` then threw a
    `NullPointerException` from the accessor.
    
    Fix: #13217
    
    ### Does this PR introduce _any_ user-facing change?
    
    No API change. `RoleDTO.securableObjects()` returns an empty list
    instead of throwing `NullPointerException` when the field is absent
    during deserialization.
    
    ### How was this patch tested?
    
    Added `TestRoleDTO`, which pins that `securableObjects()` returns an
    empty list when the Jackson field is absent; it fails on the pre-fix
    tree with a `NullPointerException` and passes after the fix.
---
 .../gravitino/dto/authorization/RoleDTO.java       |  5 ++-
 .../gravitino/dto/authorization/TestRoleDTO.java   | 42 ++++++++++++++++++++++
 2 files changed, 46 insertions(+), 1 deletion(-)

diff --git 
a/common/src/main/java/org/apache/gravitino/dto/authorization/RoleDTO.java 
b/common/src/main/java/org/apache/gravitino/dto/authorization/RoleDTO.java
index d369913a0e..ba8dd2e318 100644
--- a/common/src/main/java/org/apache/gravitino/dto/authorization/RoleDTO.java
+++ b/common/src/main/java/org/apache/gravitino/dto/authorization/RoleDTO.java
@@ -21,6 +21,7 @@ package org.apache.gravitino.dto.authorization;
 import com.fasterxml.jackson.annotation.JsonProperty;
 import com.google.common.base.Preconditions;
 import java.util.Arrays;
+import java.util.Collections;
 import java.util.List;
 import java.util.Map;
 import javax.annotation.Nullable;
@@ -95,7 +96,9 @@ public class RoleDTO implements Role {
    */
   @Override
   public List<SecurableObject> securableObjects() {
-    return Arrays.asList(securableObjects);
+    // Jackson deserialization can leave the array null (field absent in the 
payload) because it
+    // bypasses the builder's null check.
+    return securableObjects == null ? Collections.emptyList() : 
Arrays.asList(securableObjects);
   }
 
   /**
diff --git 
a/common/src/test/java/org/apache/gravitino/dto/authorization/TestRoleDTO.java 
b/common/src/test/java/org/apache/gravitino/dto/authorization/TestRoleDTO.java
new file mode 100644
index 0000000000..55d5c6e657
--- /dev/null
+++ 
b/common/src/test/java/org/apache/gravitino/dto/authorization/TestRoleDTO.java
@@ -0,0 +1,42 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *  http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.gravitino.dto.authorization;
+
+import java.io.IOException;
+import java.util.Collections;
+import org.apache.gravitino.json.JsonUtils;
+import org.junit.jupiter.api.Assertions;
+import org.junit.jupiter.api.Test;
+
+public class TestRoleDTO {
+
+  @Test
+  public void testSecurableObjectsAbsentInJsonDoesNotThrow() throws 
IOException {
+    // Jackson deserialization bypasses the builder's null check, so a payload 
without the
+    // "securableObjects" field left the array null and Arrays.asList(null) 
threw an NPE.
+    RoleDTO roleDTO =
+        JsonUtils.objectMapper()
+            .readValue(
+                
"{\"name\":\"role1\",\"audit\":{\"creator\":\"a\",\"createTime\":\"2024-01-01T00:00:00Z\"}}",
+                RoleDTO.class);
+
+    Assertions.assertEquals("role1", roleDTO.name());
+    Assertions.assertEquals(Collections.emptyList(), 
roleDTO.securableObjects());
+  }
+}

Reply via email to