mchades commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4130540268
##########
core/src/main/java/org/apache/gravitino/authorization/AuthorizationUtils.java:
##########
@@ -97,7 +97,10 @@ public class AuthorizationUtils {
MetadataObject.Type.JOB_TEMPLATE,
MetadataObject.Type.TAG,
MetadataObject.Type.POLICY,
- MetadataObject.Type.VIEW);
+ MetadataObject.Type.VIEW,
+ // Semantic models live only in Gravitino, underlying connectors
know nothing about
+ // them, so there is no privilege to push down to an authorization
plugin.
+ MetadataObject.Type.SEMANTIC_MODEL);
Review Comment:
This is still incomplete for privilege updates.
`PermissionManager.grantPrivilegesToRole`, `revokePrivilegesFromRole`, and
`overridePrivilegesInRole` call `callAuthorizationPluginForMetadataObject` and
pass unfiltered `RoleChange` objects to `onRoleUpdated`. For a `METALAKE`,
`CATALOG`, or `SCHEMA` target, Semantic Model privileges therefore still reach
the connector plugin. Please filter callback selection and `RoleChange`
payloads on these paths, and cover grant, revoke, and override with
semantic-only and mixed parent-scope privileges.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]