laserninja commented on code in PR #12867: URL: https://github.com/apache/gravitino/pull/12867#discussion_r4126216894
########## core/src/main/java/org/apache/gravitino/hook/SemanticModelHookDispatcher.java: ########## @@ -0,0 +1,112 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.gravitino.hook; + +import java.util.Map; +import java.util.function.Supplier; +import javax.annotation.Nullable; +import org.apache.gravitino.Entity; +import org.apache.gravitino.NameIdentifier; +import org.apache.gravitino.Namespace; +import org.apache.gravitino.authorization.Owner; +import org.apache.gravitino.authorization.OwnerDispatcher; +import org.apache.gravitino.catalog.SemanticModelDispatcher; +import org.apache.gravitino.exceptions.IllegalSemanticModelException; +import org.apache.gravitino.exceptions.NoSuchSchemaException; +import org.apache.gravitino.exceptions.NoSuchSemanticModelException; +import org.apache.gravitino.exceptions.SemanticModelAlreadyExistsException; +import org.apache.gravitino.semantic.SemanticModel; +import org.apache.gravitino.semantic.SemanticModelChange; +import org.apache.gravitino.semantic.SemanticModelDefinition; +import org.apache.gravitino.utils.NameIdentifierUtil; +import org.apache.gravitino.utils.PrincipalUtils; + +/** + * {@code SemanticModelHookDispatcher} is a decorator for {@link SemanticModelDispatcher} that not + * only delegates Semantic Model operations to the underlying dispatcher but also executes some hook + * operations before or after the underlying operations. + */ +public class SemanticModelHookDispatcher implements SemanticModelDispatcher { + + private final SemanticModelDispatcher dispatcher; + private final Supplier<OwnerDispatcher> ownerDispatcher; + + /** + * Creates a Semantic Model hook dispatcher. + * + * @param dispatcher The underlying dispatcher. + * @param ownerDispatcher Supplies the owner dispatcher, or null when authorization is disabled. + */ + public SemanticModelHookDispatcher( + SemanticModelDispatcher dispatcher, Supplier<OwnerDispatcher> ownerDispatcher) { + this.dispatcher = dispatcher; + this.ownerDispatcher = ownerDispatcher; + } + + @Override + public NameIdentifier[] listSemanticModels(Namespace namespace) throws NoSuchSchemaException { + return dispatcher.listSemanticModels(namespace); + } + + @Override + public SemanticModel loadSemanticModel(NameIdentifier ident) throws NoSuchSemanticModelException { + return dispatcher.loadSemanticModel(ident); + } + + @Override + public boolean semanticModelExists(NameIdentifier ident) { + return dispatcher.semanticModelExists(ident); + } + + @Override + public SemanticModel createSemanticModel( + NameIdentifier ident, + @Nullable String comment, + SemanticModelDefinition definition, + Map<String, String> properties) + throws NoSuchSchemaException, SemanticModelAlreadyExistsException, + IllegalSemanticModelException { + SemanticModel semanticModel = + dispatcher.createSemanticModel(ident, comment, definition, properties); + + // Set the creator as the owner of the Semantic Model. + OwnerDispatcher ownerManager = ownerDispatcher.get(); + if (ownerManager != null) { + ownerManager.setOwner( + ident.namespace().level(0), + NameIdentifierUtil.toMetadataObject(ident, Entity.EntityType.SEMANTIC_MODEL), + PrincipalUtils.getCurrentUserName(), + Owner.Type.USER); Review Comment: Fixed in 3875436b3. Added SEMANTIC_MODEL owner-row locking against semantic_model_meta and registered its orphaned relation cleanup. The relational test now assigns and reads an owner, then verifies cleanup after model deletion while retaining a live model’s relations. Passed with H2. ########## server-common/src/main/java/org/apache/gravitino/server/authorization/MetadataIdConverter.java: ########## @@ -50,7 +50,8 @@ public class MetadataIdConverter { MetadataObject.Type.MODEL, Capability.Scope.MODEL, MetadataObject.Type.FILESET, Capability.Scope.FILESET, MetadataObject.Type.TOPIC, Capability.Scope.TOPIC, - MetadataObject.Type.COLUMN, Capability.Scope.COLUMN); + MetadataObject.Type.COLUMN, Capability.Scope.COLUMN, + MetadataObject.Type.SEMANTIC_MODEL, Capability.Scope.SEMANTIC_MODEL); Review Comment: Fixed in 3875436b3. MetadataIdConverter now applies catalog case normalization only to the parent namespace for Semantic Models. A regression test uses the real case-insensitive normalization path and verifies that the stored SalesModel leaf is preserved during ID lookup. ########## api/src/main/java/org/apache/gravitino/authorization/Privileges.java: ########## @@ -107,7 +115,8 @@ public class Privileges { MetadataObject.Type.TOPIC, MetadataObject.Type.FILESET, MetadataObject.Type.MODEL, - MetadataObject.Type.FUNCTION); + MetadataObject.Type.FUNCTION, + MetadataObject.Type.SEMANTIC_MODEL); Review Comment: Added the positive MANAGE_GRANTS binding assertion for SEMANTIC_MODEL in TestSecurableObjects.testPrivileges in 3875436b3. The API tests pass. ########## core/src/test/java/org/apache/gravitino/authorization/TestAuthorizationUtils.java: ########## @@ -516,6 +516,35 @@ void testRemoveTablePrivilegesNotifiesAuthorizationPluginWithExpectedChange() { Assertions.assertEquals(locations, removeChange.getLocations()); } + @Test + void testSemanticModelPrivilegesAreNotPushedToAuthorizationPlugin() { + // Semantic Models exist only in Gravitino, so underlying connectors have nothing to revoke or + // rename. Rename and remove must leave the authorization plugin untouched. + NameIdentifier ident = NameIdentifier.of("metalake", "catalog", "schema", "sales_model"); + + AccessControlDispatcher accessControlDispatcher = Mockito.mock(AccessControlDispatcher.class); + CatalogManager catalogManager = Mockito.mock(CatalogManager.class); + BaseCatalog<?> baseCatalog = Mockito.mock(BaseCatalog.class); + AuthorizationPlugin authorizationPlugin = Mockito.mock(AuthorizationPlugin.class); + CatalogTestUtils.mockDoWithCatalog(catalogManager, baseCatalog); + Mockito.when(baseCatalog.getAuthorizationPlugin()).thenReturn(authorizationPlugin); + + GravitinoEnv envMock = Mockito.mock(GravitinoEnv.class); + Mockito.when(envMock.accessControlDispatcher()).thenReturn(accessControlDispatcher); Review Comment: Corrected the stub to internalAccessControlDispatcher() in 3875436b3, so the test reaches the guarded authorization path before verifying that no connector notification occurs. TestAuthorizationUtils passes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
