LuciferYang opened a new issue, #13520:
URL: https://github.com/apache/gravitino/issues/13520

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   `SecretManager.deleteSecretsFromProperties` treats any URN with three 
identifier segments as a write-through secret and deletes it from the provider. 
The provider SPI lets external-reference URNs carry any identifier shape, so a 
conforming provider that emits a three-segment reference (for example a 
Vault-style `mount:path:key`) has its externally owned secret deleted when the 
entity is dropped. This breaks the documented invariant that external 
references are owned outside Gravitino.
   
   ### Error message and/or stacktrace
   
   No exception. The externally owned secret is silently deleted from the 
provider on entity drop (data loss).
   
   ### How to reproduce
   
   Bind an external-reference secret whose provider-built URN has three 
identifier segments to a catalog/schema/fileset property, then drop that 
catalog/schema/fileset. The external secret is deleted from the provider.
   
   ### Additional context
   
   Only catalog, schema, and fileset create write-through secrets, so drop 
cleanup should require the full write-through shape (a known entity type, a 
numeric entity id, and the storing property key) before deleting.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to