Marton Greber has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24864 )

Change subject: Require authentication for REST catalog DDL
......................................................................


Patch Set 2: Code-Review+2

(1 comment)

I just had an observation but that is probably a follow-up thing.
Otherwise looks good to me, thanks for working on this!

http://gerrit.cloudera.org:8080/#/c/24864/2/src/kudu/master/rest_catalog_path_handlers.cc
File src/kudu/master/rest_catalog_path_handlers.cc:

http://gerrit.cloudera.org:8080/#/c/24864/2/src/kudu/master/rest_catalog_path_handlers.cc@158
PS2, Line 158: void RestCatalogPathHandlers::HandleApiTableEndpoint(const 
Webserver::WebRequest& req,
non-blocking / follow-up change question:
ResolveRequestUser resolves user, but the GET path (HandleGetTable -> 
PrintTableObject -> GetTableInfo) never passes it to any authorization check, 
so any authenticated principal can read any table's full 
schema/owner/comment/extra_config. This is pre-existing (unchanged by this 
patch) and out of scope for "require authentication," but since this commit 
hardens exactly this surface: is that intended, or should single-table GET 
eventually gate on the caller the way ListTables does? Fine to defer to a 
follow-up - just flagging it isn't covered here.



--
To view, visit http://gerrit.cloudera.org:8080/24864
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ib0112638a3462c84e6366b881c9229a334ad3c25
Gerrit-Change-Number: 24864
Gerrit-PatchSet: 2
Gerrit-Owner: Gabriella Lotz <[email protected]>
Gerrit-Reviewer: Attila Bukor <[email protected]>
Gerrit-Reviewer: Gabriella Lotz <[email protected]>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Reviewer: Marton Greber <[email protected]>
Gerrit-Comment-Date: Tue, 22 Sep 2026 14:07:35 +0000
Gerrit-HasComments: Yes

Reply via email to