Copilot commented on code in PR #13525:
URL: https://github.com/apache/gravitino/pull/13525#discussion_r4115261915


##########
core/src/main/java/org/apache/gravitino/secret/SecretPropertyUtils.java:
##########
@@ -266,6 +270,33 @@ public static boolean isWriteThroughForEntity(
     }
   }
 
+  /**
+   * Whether the URN stored under {@code propertyKey} is shaped like a 
write-through secret URN:
+   * three identifier segments {@code entityType:entityId:propertyKey} with a 
known Gravitino entity
+   * type, a numeric entity id, and the storing property key. Providers may 
emit external-reference
+   * URNs with any identifier shape, so entity-drop cleanup must only treat 
URNs of exactly this
+   * shape as Gravitino-owned write-through secrets.
+   *
+   * @param propertyKey the property key the URN is stored under
+   * @param value the stored URN string
+   * @return true when the URN is a write-through URN owned by Gravitino
+   */
+  public static boolean isWriteThroughUrn(String propertyKey, @Nullable String 
value) {
+    if (!isSecretProperty(propertyKey, value)) {
+      return false;
+    }
+    try {
+      SecretUrn urn = SecretUrn.parse(value);
+      List<String> segments = urn.identifierSegments();
+      return segments.size() == 3
+          && WRITE_THROUGH_ENTITY_TYPES.contains(segments.get(0))
+          && segments.get(1).chars().allMatch(Character::isDigit)
+          && propertyKey.equals(segments.get(2));
+    } catch (IllegalArgumentException e) {
+      return false;
+    }

Review Comment:
   `SecretUrn.buildWriteThrough` defines a valid entity ID by calling 
`Long.parseLong`, but this predicate only checks that the segment contains 
digits. Consequently an external-reference URN such as 
`...:catalog:9223372036854775808:my-key` (which cannot be produced by the 
write-through builder) is classified as Gravitino-owned and will be deleted 
during drop cleanup. Validate the ID with the same `long` range as the builder 
before accepting it.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to