Skip to content

fix(AF-1089): match table preview allow-list to the query gate - #1090

Merged
babltiga merged 2 commits into
fix/AF-936-scope-schema-introspectionfrom
fix/AF-1089-sample-preview-allow-list
Sep 24, 2026
Merged

babltiga merged 2 commits into
fix/AF-936-scope-schema-introspectionfrom
fix/AF-1089-sample-preview-allow-list

Conversation

@babltiga

Copy link
Copy Markdown
Contributor

Closes #1089

Stacked on #1088 (AF-936) — base is fix/AF-936-scope-schema-introspection, which introduces core.api.AllowedTables and core.internal.SchemaViewPermissionFilter. Retarget to main once #1088 merges.

What

DefaultSampleDataService.targetAllowed let a bare allowed_tables entry ([orders]) admit a schema-qualified preview (?schema=archive&table=orders) that the query gate refuses (SELECT * FROM archive.orders → AllowedTables.coveringEntry finds no entry).

  • The preview now matches through core.api.AllowedTables (normalize / normalizeEntry / coveringEntry), the gate's matcher. The private normalizeList / normalize copies are gone.
  • Bare-entry decision: a bare entry admits a schema-qualified target only when no other schema in the database has a table of that name, and fails closed otherwise (the core: scope schema introspection to the caller's allow-list #936 SchemaViewPermissionFilter rule). The count runs over the unfiltered catalog (introspectSchemaForSystem, fetched lazily only on this fallback), because the caller's filtered view may already hide the twin: ["orders", "cat.archive.orders"] shows archive.orders through the suffix rule and hides public.orders. A target with no schema name is covered by a bare entry only.
  • DefaultQueryDryRunService: its duplicate normalizeList and inline matcher are replaced by AllowedTables, with no behaviour change.

Tests

  • DefaultSampleDataServiceTest: 9 new cases:
    • ambiguous bare entry, unique bare entry, and the filtered-view twin case;
    • the unfiltered catalog is never fetched when a qualified or schema grant covers the target;
    • a qualified entry does not cover another schema, and a schema grant does cover an ambiguous name;
    • quoted, mixed-case normalisation;
    • two unnamed-schema cases.
  • DefaultQueryDryRunServiceTest: 2 new admission-path cases (a schema or qualified entry covers the table; a restricted allow-list with no referenced tables passes).
  • The targeted tests, test-compile, ApplicationModulesTest, ApiPackageDependencyTest, spotless and checkstyle all pass. A full mvn verify was not run locally.

Docs

  • docs/05-backend.md: step 1 of "Sample data path (AF-443)" (bare-entry rule, the one documented looser case, the catalog-suffix gap) and step 1 of the dry-run section (matcher reference).
  • Website: no change. website/docs/configuration/datasources/index.html (from core: scope schema introspection to the caller's allow-list #936) already says a bare name shared across schemas shows neither table, which is now also what the preview does.

Review notes

  • af-reviewer (Blocker, rebutted): the unique-name fallback is looser than the gate in one case. With orders only in archive and archive off the search path, the preview reads archive.orders while an unqualified SELECT * FROM orders fails to resolve. This rule was chosen on purpose, to match the core: scope schema introspection to the caller's allow-list #936 view: the tree already shows that table. The javadoc and docs now state the divergence plainly instead of saying "never". Making it strict would give 404 on tables the tree lists.
  • af-java-reviewer / af-reviewer (Concern, fixed): the uniqueness count ran over the core: scope schema introspection to the caller's allow-list #936-filtered view. It now uses the unfiltered catalog, and the tests model the filtered and unfiltered views separately.
  • af-content-reviewer / af-reviewer (Concern, documented, not a regression): the view's catalog-suffix rule (mydb.dbo.orders → shows dbo.orders) is not honoured by the preview, so such a table is listed but its preview returns 404. The old code behaved the same way.
  • af-java-reviewer (Nit, left): qualifiedName falls back to "" when a table name is made only of quote characters. The restricted path already refuses it (bare == null); the old behaviour was the same.
  • af-verifier: PASS on every gate it ran.

No UI change, so no screenshots.

DefaultSampleDataService now matches its target through core.api.AllowedTables, so a bare allowed_tables entry no longer admits a schema-qualified preview the query gate rejects; a bare entry covers a qualified target only when the name is unique in the view (#936 rule). DefaultQueryDryRunService drops its duplicate normalizer too.

Refs #1089
@babltiga
babltiga merged commit ca6f0de into fix/AF-936-scope-schema-introspection Sep 24, 2026
1 check passed
@babltiga
babltiga deleted the fix/AF-1089-sample-preview-allow-list branch September 24, 2026 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant