yuqi1129 opened a new pull request, #13361:
URL: https://github.com/apache/gravitino/pull/13361

   ### What changes were proposed in this pull request?
   
   - Let service admins receive 404 when loading a missing metalake and `200` 
with `dropped=false` when dropping it again.
   - Check metalake existence when JCasbin reports non-membership, preserving 
403 for an existing metalake the caller cannot access and for callers who are 
not service admins.
   - Cover both interceptor paths and the client-facing behavior with tests.
   
   ### Why are the changes needed?
   
   The authorization interceptor currently returns 403 before metalake 
operations can report an absent metalake. This gives service admins a 
misleading membership error and breaks the drop API's `dropped=false` contract.
   
   Fix: #13360
   
   ### Does this PR introduce _any_ user-facing change?
   
   For configured service admins, GET on a missing metalake returns 404 and 
repeated DELETE returns `200` with `dropped=false`. Other callers retain the 
existing 403 behavior. No API or configuration keys change.
   
   ### How was this patch tested?
   
   - `./gradlew :server:test --tests 
org.apache.gravitino.server.web.filter.TestGravitinoInterceptionService 
-PskipITs -PskipDockerTests=true` (24 passed)
   - `./gradlew :clients:client-java:test --tests 
org.apache.gravitino.client.integration.test.authorization.MetalakeAuthorizationIT
 -PskipDockerTests=false` (6 passed)
   - `./gradlew spotlessApply`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to