singhpk234 commented on code in PR #13879:
URL: https://github.com/apache/iceberg/pull/13879#discussion_r3684931228


##########
open-api/rest-catalog-open-api.yaml:
##########
@@ -1051,6 +1051,16 @@ paths:
         table. The configuration key "token" is used to pass an access token 
to be used as a bearer token
         for table requests. Otherwise, a token may be passed using a RFC 8693 
token type as a configuration
         key. For example, "urn:ietf:params:oauth:token-type:jwt=<JWT-token>".
+
+
+        The response may include a read-restrictions field. A reader that 
supports read

Review Comment:
   > vended credentials are identity-agnostic by design
   
   I am not sure if this is true ? the reality is vended creds are output of 
GRANTs one user has on the catalog ? for example if a user has SELECT grant it 
gets read only if it has UPDATE it get both R/W creds ? thats the whole 
credential vending story about the catalog, so i kind of disagree here its not 
identity based 
   
   >  it just isn't the per-user access control the name suggests, so the 
per-principal assumption is doing more work here than it does for creds
   
   Vended creds are output of one's grant based on caller identity and read 
restriction is output of policy one has ? 
   Read restriction are just more fine grained than the coarse grained grants. 



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to