okumin commented on code in PR #6812:
URL: https://github.com/apache/hive/pull/6812#discussion_r4205614266
##########
standalone-metastore/metastore-rest-catalog/src/main/java/org/apache/iceberg/rest/IcebergAuthorizer.java:
##########
@@ -161,4 +165,100 @@ void validateStageCreateTable(String catalogName,
Namespace namespace, Map<Strin
throw new IllegalStateException("Failed to check privileges
stage-create", e);
}
}
+
+ /**
+ * Enforces authorization for REGISTER_TABLE. The request's {@code
metadataLocation} must be authorized, since
+ * REGISTER_TABLE is otherwise an arbitrary-file-read primitive that returns
any metadata file's contents to the
+ * caller. The {@code location()} embedded in that metadata file (which
becomes the table's HMS
+ * {@code StorageDescriptor.location}) is not checked here: it is authorized
transitively by HMS's own
+ * CREATE_TABLE authorization when {@code CatalogHandlers.registerTable}
creates the metastore table.
+ *
+ * <p>When no {@code HiveAuthorizer} is configured, falls back to requiring
the metadata location to be
+ * contained in the namespace's external root, since there is no policy to
otherwise decide whether the caller
+ * may read an arbitrary location with service credentials.
+ *
+ * @param catalogName the Hive catalog name
+ * @param namespace the Iceberg namespace
+ * @param namespaceMetadata the Iceberg namespace metadata
+ * @param request the register table request
+ * @throws ForbiddenException if the location is not authorized, or not
contained in the namespace
+ * @throws IllegalStateException if the authorization plugin fails
+ */
+ void validateRegisterTable(String catalogName, Namespace namespace,
Map<String, String> namespaceMetadata,
+ RegisterTableRequest request) {
+ Preconditions.checkArgument(namespace.levels().length == 1, "Hive does not
support multi-level namespaces");
+ var databaseName = namespace.level(0);
+ var commandString = "register table " + request.name();
+ checkLocationAuthorized(catalogName, databaseName, namespaceMetadata,
request.metadataLocation(), commandString);
+ }
+
+ /**
+ * Enforces authorization for DROP_TABLE with {@code purge=true}. Purge
deletes every file referenced by the
+ * table's current metadata using the catalog's shared, service-level {@code
FileIO}, so the location must be
+ * authorized like any other DFS_URI access.
+ *
+ * <p>Unlike {@link #validateRegisterTable}, there is no
namespace-containment fallback here: the structural
+ * fence in {@code HiveCatalog.dropTable} already restricts purge deletions
to files under the table's own
+ * location regardless of whether a {@code HiveAuthorizer} is configured, so
a deployment without one relies on
+ * that fence rather than this check.
+ *
+ * @param catalogName the Hive catalog name
+ * @param identifier the table identifier being dropped
+ * @param location the table's current location
+ * @throws ForbiddenException if the location is not authorized
+ * @throws IllegalStateException if the authorization plugin fails
+ */
+ void validateDropTablePurge(String catalogName, TableIdentifier identifier,
String location) {
+ var authorizer = authorizerSupplier.get();
+ if (authorizer == null) {
+ LOG.info("No pre-event listener is configured for catalog {}, skipping
drop-table-purge authorization for {}",
+ catalogName, identifier);
+ return;
+ }
+
+ var inputs = Collections.singletonList(
+ new
HivePrivilegeObject(HivePrivilegeObject.HivePrivilegeObjectType.DFS_URI,
location));
Review Comment:
I guess we should put this privilege object in both inputs and outputs.
As far as I've tested, DROP w/ PURGE succeeds as long as the user has READ
privilege on Ranger. Given the semantics, we may also require WRITE privilege
on the location.
<img width="1411" height="416" alt="Image"
src="https://github.com/user-attachments/assets/ef40a897-d049-4a81-a7b2-c5cb9c733b55"
/>
This part is the related implementation.
https://github.com/apache/ranger/blob/edfedfeca8efe1cf7bd4372771c521731ceaca6c/hive-agent/src/main/java/org/apache/ranger/authorization/hive/authorizer/RangerHiveAuthorizer.java#L1819
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]