The GitHub Actions job "Required Checks" on texera.git/feat/model-api-for-ui 
has succeeded.
Run started by GitHub user tanishqgandhi1908 (triggered by tanishqgandhi1908).

Head commit for run:
2a1877e0280adc9b07ffb0824a5ae53ff52b5ecd / Tanishq Gandhi 
<[email protected]>
fix(file-service): enforce the model download switch on presigned URLs

Addresses review feedback on the model file API.

getModelVersionZip refused a non-owner when is_downloadable was off, but
the presign routes did not, so the same bytes were reachable one file at
a time — a public model with downloads disabled could be pulled by an
anonymous caller, and a READ-grantee could walk every file via the
version list. Carry is_downloadable on ResourceTables and check it in
requireReadAccessToRepository, enforced on the model presign routes.

Datasets pass the descriptor but leave the gate off: their presign also
backs file preview, so switching it on would change shipped behaviour.

Also reject latest=false on getModelVersionZip instead of treating any
non-null value as latest, matching DatasetResource.

Report URL: https://github.com/apache/texera/actions/runs/32927658643

With regards,
GitHub Actions via GitBox

Reply via email to