yuqi1129 opened a new issue, #13557:
URL: https://github.com/apache/gravitino/issues/13557

   ### Describe the subtask
   
   The built-in authorizer caches metadata name→id mappings. It relies on 
`AuthorizationUtils.notifyEntityNameIdMappingChange` to evict an entry when a 
name may now resolve to a different id. `ModelHookDispatcher`, 
`TagHookDispatcher` and `PolicyHookDispatcher` never call it on delete or 
rename. If a model, tag or policy is deleted or renamed and another object is 
later created under the old name, authorization on this node evaluates the new 
object against the old object's cached id.
   
   Proposed fix: after a successful delete, and after an alter that contains a 
rename, evict the old name's mapping, following 
`FunctionHookDispatcher.dropFunction`. Add unit tests.
   
   Target: `main`, backport to `branch-1.3`.
   
   ### Parent issue
   
   #13303
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to