laserninja commented on code in PR #12867:
URL: https://github.com/apache/gravitino/pull/12867#discussion_r4140909040
##########
core/src/main/java/org/apache/gravitino/authorization/AuthorizationUtils.java:
##########
@@ -97,7 +97,10 @@ public class AuthorizationUtils {
MetadataObject.Type.JOB_TEMPLATE,
MetadataObject.Type.TAG,
MetadataObject.Type.POLICY,
- MetadataObject.Type.VIEW);
+ MetadataObject.Type.VIEW,
+ // Semantic models live only in Gravitino, underlying connectors
know nothing about
+ // them, so there is no privilege to push down to an authorization
plugin.
+ MetadataObject.Type.SEMANTIC_MODEL);
Review Comment:
Fixed the future-grant path in 676b53af4. Each role is now filtered for the
new catalog before both onGrantedRolesToUser and onGrantedRolesToGroup
callbacks. Added mixed-role regression cases for users and groups with
inherited SELECT_TABLE plus semantic-model privileges and an unrelated catalog
grant. Both cases reproduced the unfiltered payload before the fix and now
pass, while the original role remains unchanged. All 66 focused future-grant,
authorization utility, and access-control tests passed, along with formatting
checks.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]