mchades commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4140723992
##########
core/src/main/java/org/apache/gravitino/authorization/AuthorizationUtils.java:
##########
@@ -97,7 +97,10 @@ public class AuthorizationUtils {
MetadataObject.Type.JOB_TEMPLATE,
MetadataObject.Type.TAG,
MetadataObject.Type.POLICY,
- MetadataObject.Type.VIEW);
+ MetadataObject.Type.VIEW,
+ // Semantic models live only in Gravitino, underlying connectors
know nothing about
+ // them, so there is no privilege to push down to an authorization
plugin.
+ MetadataObject.Type.SEMANTIC_MODEL);
Review Comment:
The grant/revoke/override paths are fixed, but
`FutureGrantManager.grantNewlyCreatedCatalog` still forwards unfiltered roles
to the user/group callbacks. A role with metalake-level `SELECT_TABLE` and a
`SEMANTIC_MODEL` grant qualifies for future grants, then JDBC translation
throws `Don't support metadata object type SEMANTIC_MODEL`, causing
`CatalogHookDispatcher` to roll back the new catalog. Reproduced for both users
and groups on `532fb560`; filtering the role makes the control test pass.
Please filter each role for the new catalog before both callbacks and add
mixed-role future-grant tests.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]