Skip to content

[Improvement] Authorize existing metadata returned by Lance REST exist_ok #12955

Description

@yuqi1129

What would you like to be improved?

A caller with CREATE_TABLE but no read permission can use CreateTable(mode=exist_ok) to obtain an existing table's location and properties even though DescribeTable returns 403. Review the analogous namespace paths as well.

Parent: #9087. Follow-up from the review of #12954.

How should we improve?

Authorize access to the existing object before returning its metadata, reusing Gravitino authorization rules. Keep authorization tied to the resolved object across concurrent creation or replacement; preserve normal creation of absent objects.

Add unit and HTTP integration tests covering create-only callers, authorized readers, namespace paths, and concurrent replacement without hidden-metadata disclosure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    improvementImprovements on everything

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions