LuciferYang opened a new issue, #13397:
URL: https://github.com/apache/gravitino/issues/13397

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   `OwnerManager.setOwners`, the batch owner-assignment path, only calls 
`notifyOwnerChange` when the object already has an owner 
(`originOwner.ifPresent(...)`). Setting the first owner on a previously 
ownerless object therefore never reaches 
`GravitinoAuthorizer.handleMetadataOwnerChange`. This is the common case when a 
schema is created and its creator is assigned as the owner.
   
   The single-object `setOwner` path notifies unconditionally and passes a 
`null` old owner, and the SPI contract documents `oldOwnerId` as `null` when 
the first owner is set. The two paths disagree, so a custom 
`GravitinoAuthorizer` misses first-owner events and its authorization state 
drifts from the real ownership.
   
   ### How to reproduce
   
   1. Configure a custom `GravitinoAuthorizer`.
   2. Assign the first owner through the batch `setOwners` path to an object 
that currently has none (creating a schema does this automatically for its 
creator).
   3. `handleMetadataOwnerChange` is never invoked for that assignment, while 
the same assignment through the single-object API does invoke it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to