laserninja opened a new pull request, #13512: URL: https://github.com/apache/gravitino/pull/13512
### What changes were proposed in this pull request? Follow-up to #12867, implementing the [caller-facing validation requested under #12594](https://github.com/apache/gravitino/issues/12594#issuecomment-5847493357). This draft depends on #12867 and #12625. Their commits are included in the branch; the follow-up implementation is commit `2759529a8`. The diff will shrink once those dependencies merge and this branch is rebased. - Registers `SemanticModelOperations` for authorization interception and adds create/load authorization annotations. - Adds reusable `SemanticModelSourceValidator`, invoked unconditionally before create, for source existence and primary-key, unique-key, and relationship-column validation. - Authorizes each Table/View lookup before loading metadata, including cross-catalog references within the request's metalake. Denied object types are never probed. - Uses the pass-through authorizer when authorization is disabled, so source existence and column checks still run. - Documents validation behavior. The validator can be reused by `replaceDefinition` when the alter REST endpoint lands; SQL expression interpretation and transitive view validation are outside scope. ### Why are the changes needed? Internal metadata lookups do not enforce caller visibility. Semantic Model creation must validate source references under the caller's permissions before persistence, while retaining existence and column checks when authorization is disabled. Related to #12594 and #12209. This PR does not close the remaining storage integration work. ### Does this PR introduce _any_ user-facing change? Create/load enforce Semantic Model authorization. Create rejects missing sources or columns with `400`, access denial with `403`, and source catalog connection failures with `502` / `CONNECTION_FAILED_CODE`. No configuration defaults change. ### How was this patch tested? With JDK 17, all 569 server tests passed, together with formatting checks and the Javadoc build: ```bash ./gradlew :server:check :server:javadoc -PskipITs ./gradlew :server:spotlessApply :core:spotlessApply ``` HTTP tests cover validation with authorization disabled, 400/403/502 responses, and no persistence after validation failure. Validator tests cover Table/View resolution, cross-catalog references, key and relationship columns, unavailable column metadata, deny precedence, and avoiding inaccessible object lookups. Interceptor tests cover create/load denial and owner access. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
