Repository navigation
[fix][broker] Apply subscription policies to namespace and topic subscription operations - #26767
Merged
lhotari merged 1 commit intoSep 29, 2026
Conversation
…cription operations
Namespace subscription policies (subscription roles and the Prefix
subscription auth mode) were not applied consistently to admin operations
that act on subscriptions.
- Namespace and bundle clearBacklog/{subscription} and
unsubscribe/{subscription} pass the subscription to the authorization
provider, and PulsarAuthorizationProvider applies the subscription
policies to them.
- Namespace and topic operations on a subscription wrap the request
authentication data in AuthenticationDataSubscription, so the
subscription reaches the provider for every authentication data type.
AuthorizationService has an allowNamespaceOperationAsync overload with
separate authentication data for the original principal of proxied
requests, as for topic operations.
- For roles that are not super users or tenant admins, namespace
clearBacklog/{subscription} resolves the name as a subscription only
(passed to bundles with an internal subscriptionOnly parameter), and
namespace clearBacklog and topic all_subscription/expireMessages act only
on the subscriptions that the caller may act on, leaving replicator and
shadow replicator cursors alone.
- Add NamespacesImpl#clearNamespaceBundleBacklogForSubscriptionAsync with
the subscriptionOnly parameter for internal use.
Assisted-by: Claude Code
lhotari
requested review from
Technoboy-,
dao-jun,
david-streamlio,
merlimat and
nodece
September 29, 2026 20:54
merlimat
approved these changes
Sep 29, 2026
ascentstream-bot
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Oct 1, 2026
…cription operations (apache#26767) (cherry picked from commit 8fdca04)
ascentstream-bot
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Oct 2, 2026
…cription operations (apache#26767) (cherry picked from commit 8fdca04)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Namespace subscription policies (the subscription roles allowlist and the
Prefixsubscription auth mode) are applied by topic level operations that name a subscription, such as skip, reset cursor and expire. Several other admin operations that act on subscriptions did not apply them:clearBacklog/{subscription}andunsubscribe/{subscription}operations only checked the namespace level consume permission, and the subscription name was not passed to the authorization provider.clearBacklogwithout a subscription, and the topic levelall_subscription/expireMessages, act on every subscription of every affected topic, including subscriptions that the caller could not act on one at a time. The namespace level clear backlog also cleared replicator and shadow replicator cursors for any role with consume permission.Modifications
Subscription operations on namespaces, bundles and topics now apply the namespace subscription policies consistently for roles that are not super users or tenant admins. Super users and tenant admins keep the existing behaviour.
clearBacklog/{subscription}andunsubscribe/{subscription}pass the subscription name to the authorization provider, the same way as topic level subscription operations.PulsarAuthorizationProviderapplies the subscription roles and thePrefixauth mode to them.AuthenticationDataSubscriptionfor both namespace and topic level operations, so the subscription reaches the provider for every authentication data type, including the anonymous role's. For proxied requests, the original principal's own authentication data is wrapped separately.AuthorizationServicehas a newallowNamespaceOperationAsyncoverload that takes separate authentication data for the original principal, as the topic operation overload already does.clearBacklog/{subscription}, other roles have the name resolved as a subscription only. Super users and tenant admins keep the fallback to replicator and shadow replicator cursors. The broker passes this restriction to the bundles with an internal, hiddensubscriptionOnlyquery parameter, and a direct bundle request from other roles whose name resolves to a replicator or shadow replicator cursor is rejected.clearBacklogwithout a subscription clear only the subscriptions that the caller may clear, using the same check asclearBacklog/{subscription}. Replicator and shadow replicator cursors are left alone. When no subscription policy restricts the caller, every subscription is still cleared.all_subscription/expireMessagesexpires only the subscriptions that the caller may expire, using the same check asexpireMessagesfor one subscription, on topics, partitioned topics and single partitions.AuthorizationService#isSuperUserOrTenantAdmin. For proxied requests, both the proxy role and the original principal must be a super user or a tenant admin, and the original principal is checked with its own authentication data.NamespacesImpl#clearNamespaceBundleBacklogForSubscriptionAsync(namespace, bundle, subscription, subscriptionOnly), which the broker uses internally. It is not part of the publicNamespacesinterface.Verifying this change
This change added tests and can be verified as follows:
NamespaceAuthZTest:Prefixauth mode, for regular roles, tenant admins and super users, including namespace and topic level replication, shadow topics (with short shadow topic names) and subscriptions named after a cluster.NamespaceSubscriptionAnonymousRoleTest: namespace and topic level subscription operations apply the subscription policies to the anonymous role.NamespaceSubscriptionProxyRoleTest: proxied requests resolving a replicator cursor name are checked for the original principal.MultiRolesTokenAuthorizationProviderTest: namespace clear backlog with a secondary tenant admin role, and namespace and all-subscription operations through a proxy whose token carries a tenant admin role.NamespacesTestfor the new bundle endpoint parameter.Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes
REST endpoints: the bundle level
clearBacklog/{subscription}endpoint accepts a new hidden, internalsubscriptionOnlyquery parameter. Namespace clear backlog (with or without a subscription), namespace unsubscribe and topic expire for all subscriptions now apply subscription policies for roles that are not super users or tenant admins, and these roles no longer clear replicator or shadow replicator cursors through the namespace operations. For these roles, the namespace clear backlog and the partitioned topic expire for all subscriptions send one internal request per allowed subscription instead of one per bundle or partition. Brokers that don't support thesubscriptionOnlyparameter ignore it, so the restriction on named namespace operations applies once all brokers are upgraded. Admin CLI: the namespaceclear-backlogandunsubscribecommands and the topicexpire-messages-all-subscriptionscommand are affected by the same authorization change. Their options are unchanged.