apache/gravitino

[Improvement] Invalid metadata object type causes authorization interceptor to return internal error

Open

#10,626 创建于 2026年4月1日

在 GitHub 查看
 (1 评论) (0 反应) (1 负责人)Java (887 fork)auto 404
good first issueimprovement

仓库指标

Star
 (3,058 star)
PR 合并指标
 (PR 指标待抓取)

描述

What would you like to be improved?

When a request includes an unsupported metadataObjectType path value, Gravitino can fail during authorization context construction and return an internal server error instead of a clean client-facing validation error.

The problem happens before the REST handler runs:

  • ParameterUtil.java converts the path parameter with MetadataObject.Type.valueOf(...)
  • GravitinoInterceptionService.java catches that exception in the authorization interceptor
  • the interceptor then returns Authorization failed due to system internal error

This makes invalid user input look like a server-side authorization failure.

How should we improve?

Handle invalid metadata object types explicitly during authorization parameter extraction.

Options:

  • Catch IllegalArgumentException around MetadataObject.Type.valueOf(...) in ParameterUtil.extractNameIdentifierFromParameters and convert it to a normal invalid-argument path.
  • In GravitinoInterceptionService, treat invalid request-parameter parsing errors as bad requests instead of internal authorization failures.
  • Add tests covering unsupported metadataObjectType values for object-based endpoints to verify they return a clean 4xx response rather than 500.

贡献者指南