mchades commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4130526030
##########
api/src/main/java/org/apache/gravitino/authorization/SecurableObjects.java:
##########
@@ -170,6 +170,22 @@ public static SecurableObject ofFunction(
return of(MetadataObject.Type.FUNCTION, names, privileges);
}
+ /**
+ * Create the semantic model {@link SecurableObject} with the given
securable schema object,
+ * semantic model name and privileges.
+ *
+ * @param schema The schema securable object
+ * @param semanticModel The semantic model name
+ * @param privileges The privileges of the semantic model
+ * @return The created semantic model {@link SecurableObject}
+ */
+ public static SecurableObject ofSemanticModel(
+ SecurableObject schema, String semanticModel, List<Privilege>
privileges) {
+ List<String> names =
Lists.newArrayList(DOT_SPLITTER.splitToList(schema.fullName()));
+ names.add(semanticModel);
+ return of(MetadataObject.Type.SEMANTIC_MODEL, names, privileges);
Review Comment:
[P2] Keep the public access-control contract in sync. This adds a
server-side `SEMANTIC_MODEL` securable, but `docs/open-api/roles.yaml` still
excludes `SEMANTIC_MODEL` from both `SecurableObject.type` and
`metadataObjectTypeOfRole`, and its `Privilege.name` enum omits all three new
privilege names. OpenAPI-generated clients therefore cannot create or represent
the grants added here. Please update those enums and run `./gradlew
:docs:build`.
##########
docs/security/access-control.md:
##########
@@ -276,6 +280,7 @@ return only the entries the caller is entitled to see,
which for a metalake owne
| Fileset | `CREATE_FILESET` | `READ_FILESET` or `WRITE_FILESET` |
`WRITE_FILESET` | Owner |
| Model | `REGISTER_MODEL` | `USE_MODEL` |
Owner | Owner |
| Function | `REGISTER_FUNCTION` | `EXECUTE_FUNCTION` or `MODIFY_FUNCTION` |
`MODIFY_FUNCTION` | Owner |
+| Semantic Model | `CREATE_SEMANTIC_MODEL` | `SELECT_SEMANTIC_MODEL` or
`MODIFY_SEMANTIC_MODEL` | `MODIFY_SEMANTIC_MODEL` | Owner |
Review Comment:
[P3] Update the surrounding access-control summary for Semantic Models. The
Ownership section still omits Semantic Models, and the `MANAGE_GRANTS` row
omits Semantic Model from “Grantable On”, even though this PR adds creator
ownership and per-model grants.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]