lasdf1234 opened a new pull request, #13570:
URL: https://github.com/apache/gravitino/pull/13570

   ### What changes were proposed in this pull request?
   
   **Stacked on #13539** — please review the fileset recovery commit relative 
to that PR:
   
   
https://github.com/apache/gravitino/compare/lasdf1234:fix/hide-access-key-ids...lasdf1234:fix/fileset-static-credentials
   
   For **fileset** `getCredentials` requests: rebuild static secret-key 
credentials from fileset → schema → catalog merged plaintext when those 
provider types are already selected. Infer storage providers when the whole 
fileset/schema/catalog chain omits `credential-providers`. Do not force-append 
providers when the list is explicit. GVFS merges static credentials from 
**fileset** `getCredentials` only (skip `expireTimeInMs != 0`).
   
   ### Why are the changes needed?
   
   #13539 recovers catalog-level static keys via `getCredentials`, but 
fileset/schema AK/SK overrides were still ignored because catalog 
`CredentialProvider`s are initialized with catalog properties only. Explicit 
`credential-providers` (e.g. token-only) must win over auto-detected static 
keys.
   
   Depends on: #13539
   
   Fix: #13538
   
   ### Does this PR introduce _any_ user-facing change?
   
   Yes (on top of #13539):
   - Fileset `getCredentials` can return fileset/schema-overridden static 
secret-key credentials.
   - When no level sets `credential-providers`, providers may be inferred from 
merged storage keys.
   - GVFS no longer injects catalog static AK/SK via catalog `getCredentials`; 
it uses fileset `getCredentials` (static only).
   
   ### How was this patch tested?
   
   - `TestCredentialOperationDispatcher` (fileset overlay / inferred static)
   - `TestCredentialUtils` / `TestStaticSecretKeyCredentialFactory`
   - `TestNameIdentifierUtil.hasThreeLevelNamespace`
   - Catalog tests for explicit `credential-providers` (Glue / JDBC / Iceberg / 
Paimon)
   - GVFS Java/Python merge tests for fileset-only static credentials
   
   
   Made with [Cursor](https://cursor.com)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to