lasdf1234 commented on code in PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#discussion_r4132877996


##########
api/src/main/java/org/apache/gravitino/authorization/Privilege.java:
##########
@@ -161,10 +161,15 @@ enum Name {
     /** The privilege to list configured secrets providers. */
     VIEW_SECRET_PROVIDERS(0L, 1L << 36),
     /**
-     * The privilege to retrieve plaintext secrets and vend credentials for a 
metadata object via
-     * {@code getSecrets} / {@code getCredentials}.
+     * The privilege to retrieve plaintext secrets (including cloud access-key 
pairs) via {@code
+     * getSecrets}. Does not authorize {@code getCredentials}.
      */
-    USE_SECRET(0L, 1L << 37);
+    USE_SECRET(0L, 1L << 37),
+    /**
+     * The privilege to vend credentials via {@code getCredentials} and to 
retrieve plaintext
+     * secrets via {@code getSecrets} with cloud access-key pairs omitted (for 
connectors).
+     */
+    USE_CREDENTIAL(0L, 1L << 38);

Review Comment:
   The USE_SECRET permission allows the invocation of the getSecrets interface 
but not the getCredentials interface. This permission calls the getSecrets 
interface and returns the ak/sk information, which is for user use.
   
   The USE_CREDENTIAL permission enables the invocation of both the 
getCredentials interface and the getSecrets interface. However, when calling 
the getSecrets interface, ak/sk information is not returned, and it is for use 
by the connector.
   
   Users and connectors should have different levels of permissions, which will 
enhance security.This is the best solution.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to