Skip to content

[fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema - #26643

Merged
lhotari merged 2 commits into
apache:masterfrom
KannarFr:fix/authorize-binary-schema-commands
Sep 19, 2026
Merged

lhotari merged 2 commits into
apache:masterfrom
KannarFr:fix/authorize-binary-schema-commands

Conversation

@KannarFr

@KannarFr KannarFr commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

The REST schema endpoints check topic permissions (GET_METADATA to read, PRODUCE to upload in
SchemasResourceBase), but the binary CommandGetSchema and CommandGetOrCreateSchema handlers in
ServerCnx did not check any permission.

Modifications

  • CommandGetSchema requires LOOKUP on the topic. Producers, consumers and readers already hold it,
    since they look the topic up first; the default provider treats LOOKUP and GET_METADATA alike.
  • CommandGetOrCreateSchema requires PRODUCE on the topic, like the REST schema upload.
  • A refused request gets AuthorizationError, through the new
    BrokerServiceException.NotAuthorizedException mapped in getClientErrorCode.
  • ClientChannelHelper now decodes the two schema responses for tests.

This PR and #26644 both add BrokerServiceException.NotAuthorizedException; whichever is merged second
will merge master.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • ServerCnxTest: each command refused without the permission (the schema registry or the topic is
    never reached) and allowed with it.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

The binary protocol messages are unchanged; the broker now answers AuthorizationError to these
commands when the client lacks the permission.

🤖 Generated with Claude Code

…reateSchema

Align the binary schema commands with the REST schema endpoints.
CommandGetSchema now requires LOOKUP on the topic, which producers, consumers
and readers already hold. CommandGetOrCreateSchema requires PRODUCE, like the
REST schema upload. A refused request gets AuthorizationError, through the new
BrokerServiceException.NotAuthorizedException.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@lhotari
lhotari merged commit 0f8af32 into apache:master Sep 19, 2026
43 checks passed
@lhotari lhotari added this to the 5.0.0 milestone Sep 23, 2026
lhotari pushed a commit that referenced this pull request Sep 23, 2026
…reateSchema (#26643)

Check topic permissions for binary GetSchema and GetOrCreateSchema requests and retain the schema and transaction tests when merging master.

(cherry picked from commit 0f8af32)
lhotari pushed a commit that referenced this pull request Sep 23, 2026
…reateSchema (#26643)

Check topic permissions for binary GetSchema and GetOrCreateSchema requests and retain the schema and transaction tests when merging master.

(cherry picked from commit 0f8af32)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants