laserninja opened a new pull request, #13512:
URL: https://github.com/apache/gravitino/pull/13512

   ### What changes were proposed in this pull request?
   
   Follow-up to #12867, implementing the [caller-facing validation requested 
under 
#12594](https://github.com/apache/gravitino/issues/12594#issuecomment-5847493357).
   
   This draft depends on #12867 and #12625. Their commits are included in the 
branch; the follow-up implementation is commit `2759529a8`. The diff will 
shrink once those dependencies merge and this branch is rebased.
   
   - Registers `SemanticModelOperations` for authorization interception and 
adds create/load authorization annotations.
   - Adds reusable `SemanticModelSourceValidator`, invoked unconditionally 
before create, for source existence and primary-key, unique-key, and 
relationship-column validation.
   - Authorizes each Table/View lookup before loading metadata, including 
cross-catalog references within the request's metalake. Denied object types are 
never probed.
   - Uses the pass-through authorizer when authorization is disabled, so source 
existence and column checks still run.
   - Documents validation behavior. The validator can be reused by 
`replaceDefinition` when the alter REST endpoint lands; SQL expression 
interpretation and transitive view validation are outside scope.
   
   ### Why are the changes needed?
   
   Internal metadata lookups do not enforce caller visibility. Semantic Model 
creation must validate source references under the caller's permissions before 
persistence, while retaining existence and column checks when authorization is 
disabled.
   
   Related to #12594 and #12209. This PR does not close the remaining storage 
integration work.
   
   ### Does this PR introduce _any_ user-facing change?
   
   Create/load enforce Semantic Model authorization. Create rejects missing 
sources or columns with `400`, access denial with `403`, and source catalog 
connection failures with `502` / `CONNECTION_FAILED_CODE`. No configuration 
defaults change.
   
   ### How was this patch tested?
   
   With JDK 17, all 569 server tests passed, together with formatting checks 
and the Javadoc build:
   
   ```bash
   ./gradlew :server:check :server:javadoc -PskipITs
   ./gradlew :server:spotlessApply :core:spotlessApply
   ```
   
   HTTP tests cover validation with authorization disabled, 400/403/502 
responses, and no persistence after validation failure. Validator tests cover 
Table/View resolution, cross-catalog references, key and relationship columns, 
unavailable column metadata, deny precedence, and avoiding inaccessible object 
lookups. Interceptor tests cover create/load denial and owner access.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to