mchades commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4130540268


##########
core/src/main/java/org/apache/gravitino/authorization/AuthorizationUtils.java:
##########
@@ -97,7 +97,10 @@ public class AuthorizationUtils {
           MetadataObject.Type.JOB_TEMPLATE,
           MetadataObject.Type.TAG,
           MetadataObject.Type.POLICY,
-          MetadataObject.Type.VIEW);
+          MetadataObject.Type.VIEW,
+          // Semantic models live only in Gravitino, underlying connectors 
know nothing about
+          // them, so there is no privilege to push down to an authorization 
plugin.
+          MetadataObject.Type.SEMANTIC_MODEL);

Review Comment:
   This is still incomplete for privilege updates. 
`PermissionManager.grantPrivilegesToRole`, `revokePrivilegesFromRole`, and 
`overridePrivilegesInRole` call `callAuthorizationPluginForMetadataObject` and 
pass unfiltered `RoleChange` objects to `onRoleUpdated`. For a `METALAKE`, 
`CATALOG`, or `SCHEMA` target, Semantic Model privileges therefore still reach 
the connector plugin. Please filter callback selection and `RoleChange` 
payloads on these paths, and cover grant, revoke, and override with 
semantic-only and mixed parent-scope privileges.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to