gianm opened a new pull request, #20075: URL: https://github.com/apache/druid/pull/20075
This patch adds a SchemaProvider interface, which can provide schemas based on the identity of the current user. SqlBindings#addSchemaProvider can be used by extension to add such providers. In core, this patch moves the "druid", "view", and "sys" schemas to use schema providers that filter out unauthorized tables and views. This improves the behavior for unauthorized tables. Previously unauthorized tables were explicitly filtered out of InformationSchema, so users could not see them in metadata queries. However, they were visible to the validator, so a query that explicitly named such a table would return a "Forbidden" error. Now the error is "table not found". To preserve the functioning of view expansion, views are now expanded using an escalated schema. Comments about the view security model are added to ViewManager's javadoc. To ensure that table validation happens as expected at ingestion time, INSERT and REPLACE now require READ access (in addition to WRITE) on the target table. A new configuration option "druid.sql.planner.authorizeTableVisibility" (default true) is added. If set explicitly to false, the old behavior is restored. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
