yuqi1129 opened a new pull request, #13362: URL: https://github.com/apache/gravitino/pull/13362
### What changes were proposed in this pull request? Cherry-pick of #13361 to branch-1.3. - Add `allowServiceAdminOnMissingMetalake` to `@AuthorizationExpression`. When the caller is a service admin and the target metalake does not exist, the interceptor proceeds to the resource method instead of returning 403, so the operation reports the missing metalake exactly as it did before authorization was added: 404 for load/alter/enable/disable, `200` with `dropped=false` for drop, including the events those operations emit. - Check metalake existence when JCasbin reports non-membership, preserving 403 for an existing metalake the caller cannot access and for callers who are not service admins. - Enable the flag on `loadMetalake`, `setMetalake`, `alterMetalake` and `dropMetalake`. Conflicts resolved: test imports (branch-1.3 has `TagsAssociateRequest` rather than `TagValuesAssociateRequest`), and the interceptor's user-validation helper is still named `validateCurrentUser` on this branch (no active-roles support), so the change is applied to that method. ### Why are the changes needed? The authorization interceptor currently returns 403 before metalake operations can report an absent metalake. This gives service admins a misleading membership error and breaks the drop API's `dropped=false` contract. Fix: #13360 ### Does this PR introduce _any_ user-facing change? For configured service admins, GET/PUT/PATCH on a missing metalake return 404 and repeated DELETE returns `200` with `dropped=false`. Other callers retain the existing 403 behavior. No API or configuration keys change. ### How was this patch tested? - `./gradlew :server:test --tests org.apache.gravitino.server.web.filter.TestGravitinoInterceptionService -PskipITs -PskipDockerTests=true` (19 passed) - `./gradlew :clients:client-java:test --tests org.apache.gravitino.client.integration.test.authorization.MetalakeAuthorizationIT -PskipDockerTests=false` (6 passed) - `./gradlew spotlessApply` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
