mchades commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4130526030


##########
api/src/main/java/org/apache/gravitino/authorization/SecurableObjects.java:
##########
@@ -170,6 +170,22 @@ public static SecurableObject ofFunction(
     return of(MetadataObject.Type.FUNCTION, names, privileges);
   }
 
+  /**
+   * Create the semantic model {@link SecurableObject} with the given 
securable schema object,
+   * semantic model name and privileges.
+   *
+   * @param schema The schema securable object
+   * @param semanticModel The semantic model name
+   * @param privileges The privileges of the semantic model
+   * @return The created semantic model {@link SecurableObject}
+   */
+  public static SecurableObject ofSemanticModel(
+      SecurableObject schema, String semanticModel, List<Privilege> 
privileges) {
+    List<String> names = 
Lists.newArrayList(DOT_SPLITTER.splitToList(schema.fullName()));
+    names.add(semanticModel);
+    return of(MetadataObject.Type.SEMANTIC_MODEL, names, privileges);

Review Comment:
   [P2] Keep the public access-control contract in sync. This adds a 
server-side `SEMANTIC_MODEL` securable, but `docs/open-api/roles.yaml` still 
excludes `SEMANTIC_MODEL` from both `SecurableObject.type` and 
`metadataObjectTypeOfRole`, and its `Privilege.name` enum omits all three new 
privilege names. OpenAPI-generated clients therefore cannot create or represent 
the grants added here. Please update those enums and run `./gradlew 
:docs:build`.



##########
docs/security/access-control.md:
##########
@@ -276,6 +280,7 @@ return only the entries the caller is entitled to see, 
which for a metalake owne
 | Fileset  | `CREATE_FILESET`    | `READ_FILESET` or `WRITE_FILESET`       | 
`WRITE_FILESET`   | Owner |
 | Model    | `REGISTER_MODEL`    | `USE_MODEL`                             | 
Owner             | Owner |
 | Function | `REGISTER_FUNCTION` | `EXECUTE_FUNCTION` or `MODIFY_FUNCTION` | 
`MODIFY_FUNCTION` | Owner |
+| Semantic Model | `CREATE_SEMANTIC_MODEL` | `SELECT_SEMANTIC_MODEL` or 
`MODIFY_SEMANTIC_MODEL` | `MODIFY_SEMANTIC_MODEL` | Owner |

Review Comment:
   [P3] Update the surrounding access-control summary for Semantic Models. The 
Ownership section still omits Semantic Models, and the `MANAGE_GRANTS` row 
omits Semantic Model from “Grantable On”, even though this PR adds creator 
ownership and per-model grants.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to