singhpk234 commented on code in PR #13879:
URL: https://github.com/apache/iceberg/pull/13879#discussion_r3684931228
##########
open-api/rest-catalog-open-api.yaml:
##########
@@ -1051,6 +1051,16 @@ paths:
table. The configuration key "token" is used to pass an access token
to be used as a bearer token
for table requests. Otherwise, a token may be passed using a RFC 8693
token type as a configuration
key. For example, "urn:ietf:params:oauth:token-type:jwt=<JWT-token>".
+
+
+ The response may include a read-restrictions field. A reader that
supports read
Review Comment:
> vended credentials are identity-agnostic by design
I am not sure if this is true ? the reality is vended creds are output of
GRANTs one user has on the catalog ? for example if a user has SELECT grant it
gets read only if it has UPDATE it get both R/W creds ? thats the whole
credential vending story about the catalog, so i kind of disagree here its not
identity based
> it just isn't the per-user access control the name suggests, so the
per-principal assumption is doing more work here than it does for creds
Vended creds are output of one's grant based on caller identity and read
restriction is output of policy one has ?
Read restriction are just more fine grained than the coarse grained grants.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]