ltamber opened a new pull request #7234:
URL: https://github.com/apache/pulsar/pull/7234


   ### Motivation
   Currently,when pulsar AuthorizationService check lookup permission, if the 
role canProducer **or** canConsumer mean that canLookup, but actually in the 
code 
https://github.com/apache/pulsar/blob/master/pulsar-broker-common/src/main/java/org/apache/pulsar/broker/authorization/AuthorizationService.java#L267,
 if the method canProduce or canConsume throw exception, `canLookup` will just 
throw the exception and won't check the other permission.
   
   ### Modification
   invoke `canLookupAsync` instead.
   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to