LuciferYang opened a new pull request, #13525: URL: https://github.com/apache/gravitino/pull/13525
### What changes were proposed in this pull request? `SecretManager.deleteSecretsFromProperties` now deletes a stored URN only when it has the full write-through shape, decided by the new `SecretPropertyUtils.isWriteThroughUrn`: three identifier segments made of a known Gravitino entity type (`catalog`, `schema`, or `fileset`), a numeric entity id, and the storing property key. ### Why are the changes needed? The old code treated any three-segment URN as write-through and deleted it. The provider SPI lets external-reference URNs carry any identifier shape, so a conforming provider emitting a three-segment reference had its externally owned secret deleted on entity drop, breaking the invariant that external references are owned outside Gravitino. Only catalog, schema, and fileset create write-through secrets, so real write-through URNs still match and are deleted, while external references are left alone. Fix: #13520 ### Does this PR introduce _any_ user-facing change? No. ### How was this patch tested? Added `testDropCleanupDeletesWriteThroughButKeepsExternalReference`, which puts a three-segment external reference (entity type `path`) and a real write-through URN (`catalog`) in the same properties and asserts drop cleanup deletes only the write-through one; it fails against the pre-fix code, which deleted both. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
