JingsongLi commented on PR #10322:
URL: https://github.com/apache/paimon/pull/10322#issuecomment-5936765291

   Re-reviewed `6c4ea3f042`: the original `/` prefix finding is fixed. All 23 
permission-management tests and 92 REST/API/client/catalog/signer regression 
tests passed (plus 6 subtests). Repository-configured Flake8 and Python 3.6 
grammar checks passed for all 17 changed files. The real HTTP tests now cover 
list/grant/revoke with encoded prefixes and the path actually sent.
   
   **[P2] Keep the encoded prefix compatible with the existing Java OpenAPI 
signing contract**
   
   At `resource_paths.py:44`, a prefix containing a space now becomes 
`catalog+id`. However, Python `DLFOpenApiSigner._build_canonicalized_resource` 
uses `unquote`, leaving `+` in the canonical resource, while the existing Java 
`DLFOpenApiSigner` uses `RESTUtil.decodeString`/`URLDecoder`, restoring the 
space. This changes previously matching Java/Python signatures for the 
space-containing prefix that the new tests explicitly support. The OpenAPI 
signer is automatically selected for `dlfnext` endpoints; the new HTTP test 
uses bearer auth and only records `parameter.path`, so it cannot catch this 
difference.
   
   I ran both actual signers with the same GET path, empty query/body, fixed 
date/nonce and test-only credentials:
   
   ```text
   prefix: catalog id
   wire/signing input path: /v1/catalog+id/permissions
   Python canonical resource: /v1/catalog+id/permissions
   Java canonical resource:   /v1/catalog id/permissions
   Python Authorization: acs TestAKId:BNMSl5OSsGHdIcfK56Ds4YrZqzQ=
   Java Authorization:   acs TestAKId:x37eWUnTGZTEQVUxYmkLf2RGxWM=
   ```
   
   The pre-fix raw-space prefix produced the Java signature. Slash, literal 
`+`, tilde/asterisk and Unicode controls still agree. A verifier using the 
existing Java canonicalization will reject the new Python signature; this is a 
reproduced signing-contract mismatch, not a claim that I exercised a live DLF 
gateway.
   
   Please align the OpenAPI path canonicalization with Java (for example, 
`unquote_plus` for this form-encoded path) and add a fixed Java/Python 
Authorization parity test for both a space and a literal `+` prefix. Keep the 
new encoded routing and the `~` wire-path handling.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to