Skip to content

[fix][broker] Check topic permissions for partitions and subscriptions added to a transaction - #26644

Merged
lhotari merged 1 commit into
apache:masterfrom
KannarFr:fix/authorize-txn-registration
Sep 19, 2026
Merged

lhotari merged 1 commit into
apache:masterfrom
KannarFr:fix/authorize-txn-registration

Conversation

@KannarFr

Copy link
Copy Markdown
Contributor

Motivation

CommandAddPartitionToTxn and CommandAddSubscriptionToTxn only checked that the client owns the
transaction. The partitions and subscriptions added to it were not checked against the client's topic
permissions, unlike producing to a partition or subscribing.

Modifications

  • AddPartitionToTxn requires PRODUCE on each partition.
  • AddSubscriptionToTxn requires CONSUME on each topic, with the subscription name passed to the
    provider (AuthenticationDataSubscription), as subscribe does.
  • One refused participant fails the request with AuthorizationError, through the new
    BrokerServiceException.NotAuthorizedException. The scalable-topic path does not register
    participants and is unchanged.
  • The message returned to a client that does not own the transaction goes through the role logging
    anonymizer.

This PR and #26643 both add BrokerServiceException.NotAuthorizedException; whichever is merged second
will merge master.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • ServerCnxTest: partitions and subscriptions refused without the permission (nothing is
    registered with the coordinator), including a request where only one of two partitions is refused;
    the existing sendAddPartitionToTxnResponse* and sendAddSubscriptionToTxnResponse* tests cover
    the allowed path.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

The binary protocol messages are unchanged; the broker now answers AuthorizationError to these
commands when the client lacks the permission.

🤖 Generated with Claude Code

…s added to a transaction

AddPartitionToTxn now requires PRODUCE on each partition, and
AddSubscriptionToTxn requires CONSUME on each subscription with its name, as
producing and subscribing do. One refused participant fails the request with
AuthorizationError. The scalable-topic path does not register participants and
is unchanged.

The message returned to a client that does not own the transaction now goes
through the role logging anonymizer.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@lhotari
lhotari merged commit 28eea81 into apache:master Sep 19, 2026
44 checks passed
@lhotari lhotari added this to the 5.0.0 milestone Sep 23, 2026
lhotari pushed a commit that referenced this pull request Sep 23, 2026
…s added to a transaction (#26644)

(cherry picked from commit 28eea81)
lhotari pushed a commit that referenced this pull request Sep 23, 2026
…s added to a transaction (#26644)

(cherry picked from commit 28eea81)
Radiancebobo pushed a commit to Radiancebobo/pulsar that referenced this pull request Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants