roryqi commented on code in PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#discussion_r4132859999


##########
api/src/main/java/org/apache/gravitino/authorization/Privilege.java:
##########
@@ -161,10 +161,15 @@ enum Name {
     /** The privilege to list configured secrets providers. */
     VIEW_SECRET_PROVIDERS(0L, 1L << 36),
     /**
-     * The privilege to retrieve plaintext secrets and vend credentials for a 
metadata object via
-     * {@code getSecrets} / {@code getCredentials}.
+     * The privilege to retrieve plaintext secrets (including cloud access-key 
pairs) via {@code
+     * getSecrets}. Does not authorize {@code getCredentials}.
      */
-    USE_SECRET(0L, 1L << 37);
+    USE_SECRET(0L, 1L << 37),
+    /**
+     * The privilege to vend credentials via {@code getCredentials} and to 
retrieve plaintext
+     * secrets via {@code getSecrets} with cloud access-key pairs omitted (for 
connectors).
+     */
+    USE_CREDENTIAL(0L, 1L << 38);

Review Comment:
   Don't use `USE_CREDENTIAL`. This isn't good.
   If you have the privilege `read table` or `write table`, you can get 
credential from the table.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to