yuqi1129 opened a new pull request, #13361: URL: https://github.com/apache/gravitino/pull/13361
### What changes were proposed in this pull request? - Let service admins receive 404 when loading a missing metalake and `200` with `dropped=false` when dropping it again. - Check metalake existence when JCasbin reports non-membership, preserving 403 for an existing metalake the caller cannot access and for callers who are not service admins. - Cover both interceptor paths and the client-facing behavior with tests. ### Why are the changes needed? The authorization interceptor currently returns 403 before metalake operations can report an absent metalake. This gives service admins a misleading membership error and breaks the drop API's `dropped=false` contract. Fix: #13360 ### Does this PR introduce _any_ user-facing change? For configured service admins, GET on a missing metalake returns 404 and repeated DELETE returns `200` with `dropped=false`. Other callers retain the existing 403 behavior. No API or configuration keys change. ### How was this patch tested? - `./gradlew :server:test --tests org.apache.gravitino.server.web.filter.TestGravitinoInterceptionService -PskipITs -PskipDockerTests=true` (24 passed) - `./gradlew :clients:client-java:test --tests org.apache.gravitino.client.integration.test.authorization.MetalakeAuthorizationIT -PskipDockerTests=false` (6 passed) - `./gradlew spotlessApply` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
