lucasfang opened a new issue, #369:
URL: https://github.com/apache/paimon-cpp/issues/369

   ## Search before asking
   
   - [x] I searched in the 
[issues](https://github.com/apache/paimon-cpp/issues) and found nothing similar.
   
   ## Motivation
   
   The C++ REST catalog can only read and write table data with the static 
credentials configured in the catalog options (`fs.oss.accessKeyId` and 
friends). A REST catalog that issues per-table temporary credentials (data 
tokens, e.g. DLF) has no way to have those credentials used for that table's 
data IO, and no way to keep them fresh before they expire. Callers that bring 
their own `FileSystem` also have no supported abstraction for sourcing 
credentials that expire.
   
   ## Solution
   
   Add data-token support to the REST catalog: when `data-token.enabled=true`, 
the catalog loads a table's temporary credentials and serves a refreshing 
`FileSystem` for that table through `Catalog::GetTableFileSystem(identifier)`. 
`ReadContextBuilder`, `ScanContextBuilder` and `WriteContextBuilder` gain 
`WithCatalog(catalog, identifier)` so the table's schema and file system are 
resolved from the catalog in one call. The credentials are cached and reloaded 
before expiry by rebuilding the delegate file system keyed by the issued token, 
so a rotation of one table's credentials does not disturb the others.
   
   Also add a generic `CredentialProvider` + `CredentialProviderFactory` 
extension point: a caller that brings its own `FileSystem` builds a provider 
with `CredentialProviderFactory::Get` and consults `GetCredentials()` at each 
access, then passes that file system in through `Catalog::Create` or a 
builder's `WithFileSystem`. The built-in file systems (`oss`, `s3`, `local`, 
`jindo`) keep signing with the static credentials of their own options.
   
   ## Anything else?
   
   `data-token.enabled` defaults to false, and the new API is additive, so the 
change is backward compatible.
   
   ## Are you willing to submit a PR?
   
   - [x] I'm willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to