imbajin commented on code in PR #3159:
URL: https://github.com/apache/hugegraph/pull/3159#discussion_r3804453716


##########
hugegraph-server/hugegraph-api/src/main/java/org/apache/hugegraph/auth/HugeGraphAuthProxy.java:
##########
@@ -2461,4 +2518,36 @@ public String toString() {
             return this.origin.toString();
         }
     }
+
+    private static Set<HugePermission> traversalPermissions(
+                                       Traversal.Admin<?, ?> traversal) {
+        Set<HugePermission> permissions = EnumSet.noneOf(HugePermission.class);
+        collectTraversalPermissions(traversal, permissions);
+        return permissions;
+    }
+
+    private static void collectTraversalPermissions(
+                        Traversal.Admin<?, ?> traversal,
+                        Set<HugePermission> permissions) {
+        for (Step<?, ?> step : traversal.getSteps()) {
+            if (step instanceof AddVertexStartStep ||

Review Comment:
   Correction: this Server branch is pinned to TinkerPop 3.5.1, where 
MergeVertexStep and MergeEdgeStep do not exist. Hubble does not depend on those 
steps; its mergeV/mergeE entries are editor syntax hints only. The 
forward-looking 3.7 guard and test fixtures were therefore speculative scope 
and have been fully reverted in 6f78df53. The current tree is identical to 
28641f54. Merge-step authorization should be handled with the real classes and 
runtime evidence in a dedicated TinkerPop upgrade change.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to