mchades commented on code in PR #13469:
URL: https://github.com/apache/gravitino/pull/13469#discussion_r4080772859
##########
docs/security/access-control.md:
##########
@@ -73,6 +73,21 @@ Everything Gravitino manages is an object with a type and a
name. The name is th
below the metalake, so a table is `{catalog}.{schema}.{table}`, and requests
identify an object by
both type and name, since the same name can exist at more than one type.
+##### Local names containing one or more dots
+
+::::caution
+When authorization is enabled, Gravitino cannot authorize a federated object
whose local name
+contains one or more dots (`.`), because dots separate the components of a
qualified metadata object name.
+Loading such an object returns `400 Bad Request`. If a connector returns one
of these objects in a
+list, Gravitino rejects the entire list request with `400 Bad Request` and
identifies the unsupported
+name instead of returning a partial result. Consequently, one object with a
dotted name can prevent
+all sibling objects from appearing in list APIs.
+
+Rename or recreate the object in the source system with a name that does not
contain dots before
+using it with authorization. When authorization is disabled, names supported
by the connector
Review Comment:
Could we scope 'remain accessible' to listing and loading existing source
objects? Gravitino's create path rejects dotted topic names even when
authorization is disabled, so the current wording could imply broader support.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]