roryqi commented on code in PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#discussion_r4132897324
##########
api/src/main/java/org/apache/gravitino/authorization/Privilege.java:
##########
@@ -161,10 +161,15 @@ enum Name {
/** The privilege to list configured secrets providers. */
VIEW_SECRET_PROVIDERS(0L, 1L << 36),
/**
- * The privilege to retrieve plaintext secrets and vend credentials for a
metadata object via
- * {@code getSecrets} / {@code getCredentials}.
+ * The privilege to retrieve plaintext secrets (including cloud access-key
pairs) via {@code
+ * getSecrets}. Does not authorize {@code getCredentials}.
*/
- USE_SECRET(0L, 1L << 37);
+ USE_SECRET(0L, 1L << 37),
+ /**
+ * The privilege to vend credentials via {@code getCredentials} and to
retrieve plaintext
+ * secrets via {@code getSecrets} with cloud access-key pairs omitted (for
connectors).
+ */
+ USE_CREDENTIAL(0L, 1L << 38);
Review Comment:
Disagree.
Don't change the permission of interface `getCredentials`.
You can add the privilege `RETRIEVE_CREDENTIAL_SECRET`. The privilege only
affects the behavior of the interface `getSecrets`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]