dimas-b commented on code in PR #4409:
URL: https://github.com/apache/polaris/pull/4409#discussion_r3270870173


##########
polaris-core/src/main/java/org/apache/polaris/core/auth/AuthorizationIntent.java:
##########
@@ -0,0 +1,74 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.polaris.core.auth;
+
+import jakarta.annotation.Nonnull;
+import jakarta.annotation.Nullable;
+import org.apache.polaris.core.entity.PolarisEntityType;
+
+/** Authorization intent describing an operation and its target resource 
shape. */
+public sealed interface AuthorizationIntent
+    permits TargetlessAuthorizationIntent,
+        SingleTargetAuthorizationIntent,
+        PairwiseTargetAuthorizationIntent {
+  static AuthorizationIntent of(@Nonnull PolarisAuthorizableOperation 
operation) {
+    return new TargetlessAuthorizationIntent(operation);
+  }
+
+  static AuthorizationIntent of(
+      @Nonnull PolarisAuthorizableOperation operation, @Nonnull 
PolarisSecurable target) {
+    return new SingleTargetAuthorizationIntent(operation, target);
+  }
+
+  static AuthorizationIntent of(
+      @Nonnull PolarisAuthorizableOperation operation,
+      @Nullable PolarisSecurable target,
+      @Nullable PolarisSecurable secondary) {
+    return new PairwiseTargetAuthorizationIntent(operation, target, secondary);
+  }
+
+  @Nonnull
+  PolarisAuthorizableOperation getOperation();
+
+  @Nullable
+  PolarisSecurable getTarget();

Review Comment:
   However with the tuple approach we do not really gain much by having 
concrete sub-classes. All data could be represented by operation type (enum) + 
list(tuple of securables), I think.
   
   IIRC, the idea for sub-types was mainly to allow exact semantics to be 
specified in terms of java access methods, which, I assume, would be different 
in each sub-class. However, my impression now is that we're gravitating towards 
a more generic representation at the java level. So, I think tuples should work 
just fine and each operation type will have to describe (javadoc) the tuple 
structure it goes along with.
   
   That said, please feel free to keep sub-types if you think they are useful.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to