Skip to content

[fix][broker] Align entry filter policy checks for non-persistent topics - #26774

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:improve-entry-filter-checks
Sep 30, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:improve-entry-filter-checks

Conversation

@lhotari

@lhotari lhotari commented Sep 30, 2026

Copy link
Copy Markdown
Member

Motivation

The topic-level entry filter endpoints in PersistentTopics check the ENTRY_FILTERS topic policy operation (READ for get, WRITE for set and remove) before handling the request. The NonPersistentTopics overrides of these endpoints skip that check, so the same operations are handled differently depending on the topic domain.

Modifications

  • In NonPersistentTopics, run validateTopicPolicyOperationAsync with PolicyName.ENTRY_FILTERS before the get (READ), set (WRITE) and remove (WRITE) entry filter operations, matching PersistentTopics.
  • Parameterize the entry filter tests in TopicAuthZTest to cover both persistent and non-persistent topics, and also check the get operation with applied=true.

With this change, a caller that is not permitted the ENTRY_FILTERS policy operation receives 403 Not Authorized for these non-persistent topic endpoints, as it already does for persistent topics.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • TopicAuthZTest.testGetEntryFilter, testSetEntryFilter and testRemoveEntryFilter now run for both persistent and non-persistent topics.

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints: non-persistent topic entry filter endpoints now check the ENTRY_FILTERS topic policy operation
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

The topic-level entry filter endpoints in PersistentTopics check the
ENTRY_FILTERS topic policy operation before handling the request, but the
NonPersistentTopics overrides skip that check.

Run validateTopicPolicyOperationAsync with ENTRY_FILTERS READ for get and
WRITE for set and remove in NonPersistentTopics, matching PersistentTopics.
Callers not permitted the operation now receive 403 Not Authorized for
these non-persistent topic endpoints.

Parameterize the TopicAuthZTest entry filter tests to cover persistent and
non-persistent topics, including the get operation with applied=true.

Assisted-by: Claude Code
@nodece
nodece merged commit 069e858 into apache:master Sep 30, 2026
44 checks passed
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 1, 2026
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants