apache / apache/gravitino

[Improvement] Invalid metadata object type causes authorization interceptor to return internal error

Open
#10,626 1 comment 0 reactions 1 assignee Claimed by @SARAMALI15792 View on GitHub
good first issue improvement
Dominant language
Java
Stars
3.2k
Forks
935
Avg merge
1d 17h
Merged PRs (30d)
339

Description

### What would you like to be improved?

When a request includes an unsupported metadataObjectType path value, Gravitino can fail during authorization context construction and return an internal server error instead of a clean client-facing validation error.

The problem happens before the REST handler runs:
- ParameterUtil.java converts the path parameter with MetadataObject.Type.valueOf(...)
- GravitinoInterceptionService.java catches that exception in the authorization interceptor
- the interceptor then returns Authorization failed due to system internal error

This makes invalid user input look like a server-side authorization failure.

### How should we improve?

Handle invalid metadata object types explicitly during authorization parameter extraction.

Options:
- Catch IllegalArgumentException around MetadataObject.Type.valueOf(...) in ParameterUtil.extractNameIdentifierFromParameters and convert it to a normal invalid-argument path.
- In GravitinoInterceptionService, treat invalid request-parameter parsing errors as bad requests instead of internal authorization failures.
- Add tests covering unsupported metadataObjectType values for object-based endpoints to verify they return a clean 4xx response rather than 500.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.