yuqi1129 opened a new issue, #13360:
URL: https://github.com/apache/gravitino/issues/13360

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   With authorization enabled, a service admin gets 403 and a metalake 
membership message when loading a metalake that does not exist. Dropping the 
same metalake twice also returns 403, although the drop API promises 
`dropped=false` when the metalake is absent.
   
   The existing 403 behavior for other callers protects resource existence. A 
service admin should be able to distinguish an absent metalake from an existing 
metalake they cannot access.
   
   ### Error message and/or stacktrace
   
   `403 ForbiddenException: Current user admin doesn't exist in the metalake 
<name>, you should add the user to the metalake first`
   
   ### How to reproduce
   
   1. Enable authorization and configure a service admin.
   2. GET `/api/metalakes/<missing-name>` as that admin. It returns 403 instead 
of 404.
   3. Create and drop a metalake, then DELETE `/api/metalakes/<name>` again. It 
returns 403 instead of `200` with `dropped=false`.
   
   ### Additional context
   
   The authorization interceptor handles missing metalakes before the REST 
operation can return its normal result. Keep 403 for callers who are not 
service admins.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to