lasdf1234 commented on code in PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#discussion_r4132925246
##########
api/src/main/java/org/apache/gravitino/authorization/Privilege.java:
##########
@@ -161,10 +161,15 @@ enum Name {
/** The privilege to list configured secrets providers. */
VIEW_SECRET_PROVIDERS(0L, 1L << 36),
/**
- * The privilege to retrieve plaintext secrets and vend credentials for a
metadata object via
- * {@code getSecrets} / {@code getCredentials}.
+ * The privilege to retrieve plaintext secrets (including cloud access-key
pairs) via {@code
+ * getSecrets}. Does not authorize {@code getCredentials}.
*/
- USE_SECRET(0L, 1L << 37);
+ USE_SECRET(0L, 1L << 37),
+ /**
+ * The privilege to vend credentials via {@code getCredentials} and to
retrieve plaintext
+ * secrets via {@code getSecrets} with cloud access-key pairs omitted (for
connectors).
+ */
+ USE_CREDENTIAL(0L, 1L << 38);
Review Comment:
The getCredential interface and the getSecret interface now share the same
permission. However, after checking most industry products, permissions are
typically separated. So my question is, what are the corresponding permissions
for the getCredential interface and the getSecret interface? What permissions
does the "getSecret" interface rely on to distinguish the returned information?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]