Marton Greber has posted comments on this change. ( http://gerrit.cloudera.org:8080/24864 )
Change subject: Require authentication for REST catalog DDL ...................................................................... Patch Set 2: Code-Review+2 (1 comment) I just had an observation but that is probably a follow-up thing. Otherwise looks good to me, thanks for working on this! http://gerrit.cloudera.org:8080/#/c/24864/2/src/kudu/master/rest_catalog_path_handlers.cc File src/kudu/master/rest_catalog_path_handlers.cc: http://gerrit.cloudera.org:8080/#/c/24864/2/src/kudu/master/rest_catalog_path_handlers.cc@158 PS2, Line 158: void RestCatalogPathHandlers::HandleApiTableEndpoint(const Webserver::WebRequest& req, non-blocking / follow-up change question: ResolveRequestUser resolves user, but the GET path (HandleGetTable -> PrintTableObject -> GetTableInfo) never passes it to any authorization check, so any authenticated principal can read any table's full schema/owner/comment/extra_config. This is pre-existing (unchanged by this patch) and out of scope for "require authentication," but since this commit hardens exactly this surface: is that intended, or should single-table GET eventually gate on the caller the way ListTables does? Fine to defer to a follow-up - just flagging it isn't covered here. -- To view, visit http://gerrit.cloudera.org:8080/24864 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: kudu Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: Ib0112638a3462c84e6366b881c9229a334ad3c25 Gerrit-Change-Number: 24864 Gerrit-PatchSet: 2 Gerrit-Owner: Gabriella Lotz <[email protected]> Gerrit-Reviewer: Attila Bukor <[email protected]> Gerrit-Reviewer: Gabriella Lotz <[email protected]> Gerrit-Reviewer: Kudu Jenkins (120) Gerrit-Reviewer: Marton Greber <[email protected]> Gerrit-Comment-Date: Tue, 22 Sep 2026 14:07:35 +0000 Gerrit-HasComments: Yes
