ayushtkn opened a new pull request, #4963:
URL: https://github.com/apache/polaris/pull/4963

   Currently, `LocalIcebergCatalog.registerNewTable` properly enforces catalog 
storage governance by calling `validateLocationForTableLike` and 
`validateMetadataFileInTableDir` on the user-provided `metadataFileLocation`.
   
   However, `registerView` omits these checks, directly reading the provided 
metadata file URI before any authorization or structural containment checks 
occur. This creates a governance gap where a user could register a view using a 
metadata file stored outside of the catalog's allowed locations, potentially 
bypassing storage RBAC policies.
   
   This PR brings `registerView` into parity with `registerTable` by adding the 
missing validation checks
   
   ## Checklist
   - [ ] ๐Ÿ›ก๏ธ Don't disclose security issues! (contact [email protected])
   - [ ] ๐Ÿ”— Clearly explained why the changes are needed, or linked related 
issues: Fixes #
   - [ ] ๐Ÿงช Added/updated tests with good coverage, or manually tested (and 
explained how)
   - [ ] ๐Ÿ’ก Added comments for complex logic
   - [ ] ๐Ÿงพ Updated `CHANGELOG.md` (if needed)
   - [ ] ๐Ÿ“š Updated documentation in `site/content/in-dev/unreleased` (if needed)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to