zml1206 commented on code in PR #5596:
URL: https://github.com/apache/kyuubi/pull/5596#discussion_r1381210254
##########
extensions/spark/kyuubi-spark-authz/src/test/scala/org/apache/kyuubi/plugin/spark/authz/ranger/DeltaCatalogRangerSparkExtensionSuite.scala:
##########
@@ -189,6 +163,62 @@ class DeltaCatalogRangerSparkExtensionSuite extends
RangerSparkExtensionSuite {
s"does not have [alter] privilege on [$namespace1/$table1]")
}
}
+
+ test("delete from table") {
+ withCleanTmpResources(Seq((s"$namespace1.$table1", "table"),
(s"$namespace1", "database"))) {
+ doAs(admin, sql(s"CREATE DATABASE IF NOT EXISTS $namespace1"))
+ doAs(admin, sql(createTableSql(namespace1, table1)))
+ interceptContains[AccessControlException](
+ doAs(someone, sql(s"DELETE FROM $namespace1.$table1 WHERE birthDate <
'1955-01-01'")))(
+ s"does not have [update] privilege on [$namespace1/$table1]")
+ }
+ }
+
+ test("insert table") {
+ withSingleCallEnabled {
+ withCleanTmpResources(Seq(
+ (s"$namespace1.$table1", "table"),
+ (s"$namespace1.$table2", "table"),
+ (s"$namespace1", "database"))) {
+ doAs(admin, sql(s"CREATE DATABASE IF NOT EXISTS $namespace1"))
+ doAs(admin, sql(createTableSql(namespace1, table1)))
+ doAs(admin, sql(createTableSql(namespace1, table2)))
+
+ // insert into
+ interceptContains[AccessControlException](
+ doAs(
+ someone,
+ sql(s"INSERT INTO $namespace1.$table1" +
+ s" SELECT * FROM $namespace1.$table2")))(
+ s"does not have [select] privilege on
[$namespace1/$table2/id,$namespace1/$table2/name," +
+ s"$namespace1/$table2/gender,$namespace1/$table2/birthDate]," +
+ s" [update] privilege on [$namespace1/$table1]")
+
+ // insert overwrite
+ interceptContains[AccessControlException](
+ doAs(
+ someone,
+ sql(s"INSERT OVERWRITE $namespace1.$table1" +
+ s" SELECT * FROM $namespace1.$table2")))(
+ s"does not have [select] privilege on
[$namespace1/$table2/id,$namespace1/$table2/name," +
+ s"$namespace1/$table2/gender,$namespace1/$table2/birthDate]," +
+ s" [update] privilege on [$namespace1/$table1]")
+ }
+ }
+ }
+
+ test("update table") {
+ withCleanTmpResources(Seq((s"$namespace1.$table1", "table"),
(s"$namespace1", "database"))) {
+ doAs(admin, sql(s"CREATE DATABASE IF NOT EXISTS $namespace1"))
+ doAs(admin, sql(createTableSql(namespace1, table1)))
+ interceptContains[AccessControlException](
+ doAs(
+ someone,
Review Comment:
Done
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]