bharos opened a new issue, #13510:
URL: https://github.com/apache/gravitino/issues/13510

   ### Describe the subtask
   
   Implement M1 from the tag-based access control design doc (#12757): the 
model and storage layer for access policies. Policies can be created, validated 
and bound to tags; nothing evaluates them yet.
   
   What lands:
   
   - `AccessControlContent` and its `validate()`, registered in 
`PolicyContents` and as `Policy.BuiltInType.ACCESS_CONTROL` 
(`system_access_control`).
   - The content DTO and its `DTOConverters` branches, so the type is creatable 
over REST.
   - The derived policy-to-role record, written on policy create and update, in 
the same shape as the existing `tag_relation_meta` and `policy_relation_meta` 
tables. Server-derived, not user-writable.
   
   Rests on OQ-3 — whether `validate()` rejects a reference to a role that does 
not exist.
   
   Blocked on #12757.
   
   ### Parent issue
   
   #12758
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to