dimas-b commented on code in PR #4831:
URL: https://github.com/apache/polaris/pull/4831#discussion_r3562403611
##########
polaris-core/src/main/java/org/apache/polaris/core/auth/PolarisAuthorizer.java:
##########
@@ -80,4 +80,19 @@ void authorizeOrThrow(
@NonNull PolarisAuthorizableOperation authzOp,
@Nullable List<PolarisResolvedPathWrapper> targets,
@Nullable List<PolarisResolvedPathWrapper> secondaries);
+
+ /**
+ * Filters a candidate list of securables to only those the principal is
authorized to see.
+ *
+ * <p>The default implementation returns all candidates unchanged,
preserving backward
+ * compatibility for authorizers that do not implement visibility filtering.
+ *
+ * <p>If filtering encounters an error, implementations should throw rather
than fall back to
+ * returning unfiltered results.
+ */
+ @NonNull
+ default List<PolarisSecurable> filterByVisibility(
+ @NonNull AuthorizationState authzState, @NonNull VisibilityFilterRequest
request) {
Review Comment:
Re: `List<AuthorizationDecision> authorize(state, batchRequest)` - that
LGTM :+1:
Re: `AuthorizationDecision authorize(state, request)` - this method exists,
but it is NOT currently called.
Perhaps it might be best to migrate all authZ callers to use
`authorize(state, request)` first, remove old `authorizeOrThrow` methods, then
add batches then revisit this PR. WDYT?
CC: @sungwy
Cf. #5034
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]