okumin commented on code in PR #6812:
URL: https://github.com/apache/hive/pull/6812#discussion_r4205614266


##########
standalone-metastore/metastore-rest-catalog/src/main/java/org/apache/iceberg/rest/IcebergAuthorizer.java:
##########
@@ -161,4 +165,100 @@ void validateStageCreateTable(String catalogName, 
Namespace namespace, Map<Strin
       throw new IllegalStateException("Failed to check privileges 
stage-create", e);
     }
   }
+
+  /**
+   * Enforces authorization for REGISTER_TABLE. The request's {@code 
metadataLocation} must be authorized, since
+   * REGISTER_TABLE is otherwise an arbitrary-file-read primitive that returns 
any metadata file's contents to the
+   * caller. The {@code location()} embedded in that metadata file (which 
becomes the table's HMS
+   * {@code StorageDescriptor.location}) is not checked here: it is authorized 
transitively by HMS's own
+   * CREATE_TABLE authorization when {@code CatalogHandlers.registerTable} 
creates the metastore table.
+   *
+   * <p>When no {@code HiveAuthorizer} is configured, falls back to requiring 
the metadata location to be
+   * contained in the namespace's external root, since there is no policy to 
otherwise decide whether the caller
+   * may read an arbitrary location with service credentials.
+   *
+   * @param catalogName the Hive catalog name
+   * @param namespace the Iceberg namespace
+   * @param namespaceMetadata the Iceberg namespace metadata
+   * @param request the register table request
+   * @throws ForbiddenException if the location is not authorized, or not 
contained in the namespace
+   * @throws IllegalStateException if the authorization plugin fails
+   */
+  void validateRegisterTable(String catalogName, Namespace namespace, 
Map<String, String> namespaceMetadata,
+      RegisterTableRequest request) {
+    Preconditions.checkArgument(namespace.levels().length == 1, "Hive does not 
support multi-level namespaces");
+    var databaseName = namespace.level(0);
+    var commandString = "register table " + request.name();
+    checkLocationAuthorized(catalogName, databaseName, namespaceMetadata, 
request.metadataLocation(), commandString);
+  }
+
+  /**
+   * Enforces authorization for DROP_TABLE with {@code purge=true}. Purge 
deletes every file referenced by the
+   * table's current metadata using the catalog's shared, service-level {@code 
FileIO}, so the location must be
+   * authorized like any other DFS_URI access.
+   *
+   * <p>Unlike {@link #validateRegisterTable}, there is no 
namespace-containment fallback here: the structural
+   * fence in {@code HiveCatalog.dropTable} already restricts purge deletions 
to files under the table's own
+   * location regardless of whether a {@code HiveAuthorizer} is configured, so 
a deployment without one relies on
+   * that fence rather than this check.
+   *
+   * @param catalogName the Hive catalog name
+   * @param identifier the table identifier being dropped
+   * @param location the table's current location
+   * @throws ForbiddenException if the location is not authorized
+   * @throws IllegalStateException if the authorization plugin fails
+   */
+  void validateDropTablePurge(String catalogName, TableIdentifier identifier, 
String location) {
+    var authorizer = authorizerSupplier.get();
+    if (authorizer == null) {
+      LOG.info("No pre-event listener is configured for catalog {}, skipping 
drop-table-purge authorization for {}",
+          catalogName, identifier);
+      return;
+    }
+
+    var inputs = Collections.singletonList(
+        new 
HivePrivilegeObject(HivePrivilegeObject.HivePrivilegeObjectType.DFS_URI, 
location));

Review Comment:
   I guess we should put this privilege object in both inputs and outputs.
   As far as I've tested, DROP w/ PURGE succeeds as long as the user has READ 
privilege on Ranger. Given the semantics, we may also require WRITE privilege 
on the location.
   <img width="1411" height="416" alt="Image" 
src="https://github.com/user-attachments/assets/ef40a897-d049-4a81-a7b2-c5cb9c733b55";
 />
   
   This part is the related implementation.
   
https://github.com/apache/ranger/blob/edfedfeca8efe1cf7bd4372771c521731ceaca6c/hive-agent/src/main/java/org/apache/ranger/authorization/hive/authorizer/RangerHiveAuthorizer.java#L1819



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to