bharos opened a new issue, #13510: URL: https://github.com/apache/gravitino/issues/13510
### Describe the subtask Implement M1 from the tag-based access control design doc (#12757): the model and storage layer for access policies. Policies can be created, validated and bound to tags; nothing evaluates them yet. What lands: - `AccessControlContent` and its `validate()`, registered in `PolicyContents` and as `Policy.BuiltInType.ACCESS_CONTROL` (`system_access_control`). - The content DTO and its `DTOConverters` branches, so the type is creatable over REST. - The derived policy-to-role record, written on policy create and update, in the same shape as the existing `tag_relation_meta` and `policy_relation_meta` tables. Server-derived, not user-writable. Rests on OQ-3 — whether `validate()` rejects a reference to a role that does not exist. Blocked on #12757. ### Parent issue #12758 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
