laserninja commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4140909040


##########
core/src/main/java/org/apache/gravitino/authorization/AuthorizationUtils.java:
##########
@@ -97,7 +97,10 @@ public class AuthorizationUtils {
           MetadataObject.Type.JOB_TEMPLATE,
           MetadataObject.Type.TAG,
           MetadataObject.Type.POLICY,
-          MetadataObject.Type.VIEW);
+          MetadataObject.Type.VIEW,
+          // Semantic models live only in Gravitino, underlying connectors 
know nothing about
+          // them, so there is no privilege to push down to an authorization 
plugin.
+          MetadataObject.Type.SEMANTIC_MODEL);

Review Comment:
   Fixed the future-grant path in 676b53af4. Each role is now filtered for the 
new catalog before both onGrantedRolesToUser and onGrantedRolesToGroup 
callbacks. Added mixed-role regression cases for users and groups with 
inherited SELECT_TABLE plus semantic-model privileges and an unrelated catalog 
grant. Both cases reproduced the unfiltered payload before the fix and now 
pass, while the original role remains unchanged. All 66 focused future-grant, 
authorization utility, and access-control tests passed, along with formatting 
checks.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to