roryqi commented on code in PR #13469:
URL: https://github.com/apache/gravitino/pull/13469#discussion_r4081943782
##########
docs/security/access-control.md:
##########
@@ -73,6 +73,21 @@ Everything Gravitino manages is an object with a type and a
name. The name is th
below the metalake, so a table is `{catalog}.{schema}.{table}`, and requests
identify an object by
both type and name, since the same name can exist at more than one type.
+##### Local names containing one or more dots
+
+::::caution
+When authorization is enabled, Gravitino cannot authorize a federated object
whose local name
+contains one or more dots (`.`), because dots separate the components of a
qualified metadata object name.
+Loading such an object returns `400 Bad Request`. If a connector returns one
of these objects in a
+list, Gravitino rejects the entire list request with `400 Bad Request` and
identifies the unsupported
+name instead of returning a partial result. Consequently, one object with a
dotted name can prevent
+all sibling objects from appearing in list APIs.
+
+Rename or recreate the object in the source system with a name that does not
contain dots before
+using it with authorization. When authorization is disabled, names supported
by the connector
Review Comment:
Scoped the statement to listing and loading existing source objects when
authorization is disabled, without implying that Gravitino can create dotted
names.
##########
docs/kafka-catalog.md:
##########
@@ -48,6 +48,13 @@ Refer to [Schema
operation](./manage-messaging-metadata-using-gravitino.md#schem
- The Kafka catalog supports creating, updating, deleting, and listing topics.
+::::caution Topic names containing dots
+When authorization is enabled, topic names containing dots are unsupported,
and one such topic can
+cause the entire topic list request to fail. See
+[Names containing dots](./security/access-control.md#names-containing-dots)
for details and the
+workaround.
+::::
Review Comment:
Updated the PR description to remove the Explore reference and keep it
aligned with the documented load/list behavior.
##########
docs/kafka-catalog.md:
##########
@@ -48,6 +48,18 @@ Refer to [Schema
operation](./manage-messaging-metadata-using-gravitino.md#schem
- The Kafka catalog supports creating, updating, deleting, and listing topics.
+::::caution Topic names containing dots
Review Comment:
Added a short note in docs/tables-and-views.md that links to the central
access-control limitation and explains that a dotted table name can fail the
entire list request.
##########
docs/security/access-control.md:
##########
@@ -73,6 +73,21 @@ Everything Gravitino manages is an object with a type and a
name. The name is th
below the metalake, so a table is `{catalog}.{schema}.{table}`, and requests
identify an object by
both type and name, since the same name can exist at more than one type.
+##### Local names containing one or more dots
Review Comment:
Preserved the existing names-containing-dots anchor explicitly on the
renamed heading, so both links remain valid.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]