yuqi1129 opened a new pull request, #13362:
URL: https://github.com/apache/gravitino/pull/13362

   ### What changes were proposed in this pull request?
   
   Cherry-pick of #13361 to branch-1.3.
   
   - Add `allowServiceAdminOnMissingMetalake` to `@AuthorizationExpression`. 
When the caller is a service admin and the target metalake does not exist, the 
interceptor proceeds to the resource method instead of returning 403, so the 
operation reports the missing metalake exactly as it did before authorization 
was added: 404 for load/alter/enable/disable, `200` with `dropped=false` for 
drop, including the events those operations emit.
   - Check metalake existence when JCasbin reports non-membership, preserving 
403 for an existing metalake the caller cannot access and for callers who are 
not service admins.
   - Enable the flag on `loadMetalake`, `setMetalake`, `alterMetalake` and 
`dropMetalake`.
   
   Conflicts resolved: test imports (branch-1.3 has `TagsAssociateRequest` 
rather than `TagValuesAssociateRequest`), and the interceptor's user-validation 
helper is still named `validateCurrentUser` on this branch (no active-roles 
support), so the change is applied to that method.
   
   ### Why are the changes needed?
   
   The authorization interceptor currently returns 403 before metalake 
operations can report an absent metalake. This gives service admins a 
misleading membership error and breaks the drop API's `dropped=false` contract.
   
   Fix: #13360
   
   ### Does this PR introduce _any_ user-facing change?
   
   For configured service admins, GET/PUT/PATCH on a missing metalake return 
404 and repeated DELETE returns `200` with `dropped=false`. Other callers 
retain the existing 403 behavior. No API or configuration keys change.
   
   ### How was this patch tested?
   
   - `./gradlew :server:test --tests 
org.apache.gravitino.server.web.filter.TestGravitinoInterceptionService 
-PskipITs -PskipDockerTests=true` (19 passed)
   - `./gradlew :clients:client-java:test --tests 
org.apache.gravitino.client.integration.test.authorization.MetalakeAuthorizationIT
 -PskipDockerTests=false` (6 passed)
   - `./gradlew spotlessApply`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to