plusplusjiajia commented on code in PR #758:
URL: https://github.com/apache/paimon-rust/pull/758#discussion_r3995309182


##########
crates/paimon/src/table/mod.rs:
##########
@@ -322,6 +328,108 @@ impl Table {
         }
     }
 
+    /// The live counterpart of [`CoreOptions::ensure_read_authorized`], which
+    /// reads the schema this handle was loaded with.
+    pub(crate) async fn ensure_read_authorized_live(&self, path: &str) -> 
Result<()> {
+        let local = CoreOptions::new(self.schema.options());
+        local.ensure_type_paimon_served(&self.identifier.full_name())?;
+        if self.server_query_auth_enabled().await? {
+            return Err(query_auth::unsupported(&format!(
+                "{path} reads index files directly and cannot apply a row 
filter or column masking"
+            )));
+        }
+        Ok(())
+    }
+
+    /// Whether the server says this table is `query-auth.enabled` right now: 
the
+    /// handle's schema is a snapshot, and a cached `false` would skip the 
check.
+    pub(crate) async fn server_query_auth_enabled(&self) -> Result<bool> {
+        let local = 
CoreOptions::new(self.schema.options()).query_auth_enabled();
+        let Some(rest_env) = &self.rest_env else {
+            return Ok(local);
+        };
+        // Only ever strengthens: the name can be re-created over this handle's
+        // files, so the answer may be about a different table.
+        if local {
+            return Ok(true);
+        }
+        match rest_env.current_table().await?.schema.as_ref() {

Review Comment:
   @JingsongLi Agreed — a bare false proved nothing. It is now trusted only 
from the uuid this handle was loaded with; a different one errors and asks for 
a re-load, a missing one reads as true.



##########
crates/paimon/src/table/mod.rs:
##########
@@ -322,6 +328,108 @@ impl Table {
         }
     }
 
+    /// The live counterpart of [`CoreOptions::ensure_read_authorized`], which
+    /// reads the schema this handle was loaded with.
+    pub(crate) async fn ensure_read_authorized_live(&self, path: &str) -> 
Result<()> {
+        let local = CoreOptions::new(self.schema.options());
+        local.ensure_type_paimon_served(&self.identifier.full_name())?;
+        if self.server_query_auth_enabled().await? {
+            return Err(query_auth::unsupported(&format!(
+                "{path} reads index files directly and cannot apply a row 
filter or column masking"
+            )));
+        }
+        Ok(())
+    }
+
+    /// Whether the server says this table is `query-auth.enabled` right now: 
the
+    /// handle's schema is a snapshot, and a cached `false` would skip the 
check.
+    pub(crate) async fn server_query_auth_enabled(&self) -> Result<bool> {
+        let local = 
CoreOptions::new(self.schema.options()).query_auth_enabled();
+        let Some(rest_env) = &self.rest_env else {
+            return Ok(local);
+        };
+        // Only ever strengthens: the name can be re-created over this handle's
+        // files, so the answer may be about a different table.
+        if local {
+            return Ok(true);
+        }
+        match rest_env.current_table().await?.schema.as_ref() {

Review Comment:
   @JingsongLi This was asking about the wrong table. It now asks about the 
branch, as db.t$branch_x, built from the base name so a handle already loaded 
as a branch doesn't double the decoration, with main mapping back.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to