What would you like to be improved?
A caller with CREATE_TABLE but no read permission can use CreateTable(mode=exist_ok) to obtain an existing table's location and properties even though DescribeTable returns 403. Review the analogous namespace paths as well.
Parent: #9087. Follow-up from the review of #12954.
How should we improve?
Authorize access to the existing object before returning its metadata, reusing Gravitino authorization rules. Keep authorization tied to the resolved object across concurrent creation or replacement; preserve normal creation of absent objects.
Add unit and HTTP integration tests covering create-only callers, authorized readers, namespace paths, and concurrent replacement without hidden-metadata disclosure.
What would you like to be improved?
A caller with CREATE_TABLE but no read permission can use CreateTable(mode=exist_ok) to obtain an existing table's location and properties even though DescribeTable returns 403. Review the analogous namespace paths as well.
Parent: #9087. Follow-up from the review of #12954.
How should we improve?
Authorize access to the existing object before returning its metadata, reusing Gravitino authorization rules. Keep authorization tied to the resolved object across concurrent creation or replacement; preserve normal creation of absent objects.
Add unit and HTTP integration tests covering create-only callers, authorized readers, namespace paths, and concurrent replacement without hidden-metadata disclosure.