Repository navigation
[fix][broker] Align partitioned topic truncate checks with non-partitioned topics - #26776
Merged
nodece merged 1 commit intoSep 30, 2026
Merged
Conversation
…ioned topics Truncating a non-partitioned topic or a single partition validates tenant admin access, but truncating a partitioned topic by its parent name read the partitioned topic metadata and sent the truncate request to each partition through the broker's internal admin client without running that check itself. Validate tenant admin access once at the start of internalTruncateTopicAsync, before the partitioned topic metadata is read or any partition is truncated, so that partitioned topics, non-partitioned topics and single partitions use the same check. Rename internalTruncateNonPartitionedTopicAsync to the private helper truncateNonPartitionedTopicWithoutAccessCheckAsync, which now only checks topic ownership and truncates the topic. Truncating a partitioned topic now requires tenant admin access, the same as truncating a non-partitioned topic. Add TopicAuthZTest#testTruncate for partitioned and non-partitioned topics: roles holding only topic level permissions are rejected and the subscription backlog is left intact, while tenant admins and super users can truncate. Assisted-by: Claude Code
lhotari
requested review from
Technoboy-,
dao-jun,
david-streamlio,
merlimat and
nodece
September 30, 2026 01:15
merlimat
approved these changes
Sep 30, 2026
dao-jun
approved these changes
Sep 30, 2026
nodece
approved these changes
Sep 30, 2026
ascentstream-bot
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Oct 1, 2026
…ioned topics (apache#26776) (cherry picked from commit b8b5769)
ascentstream-bot
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Oct 2, 2026
…ioned topics (apache#26776) (cherry picked from commit b8b5769)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Truncating a non-partitioned topic or a single partition validates tenant admin access before the topic is truncated. When a partitioned topic is truncated by its parent name,
internalTruncateTopicAsyncdid not run that check itself. It read the partitioned topic metadata and then sent the truncate request to each partition through the broker's internal admin client. As a result, a partitioned topic was not checked the same way as a non-partitioned topic.Modifications
PersistentTopicsBase#internalTruncateTopicAsyncnow callsvalidateAdminAccessForTenantAsynconce at the start, before the partitioned topic metadata is read and before any partition is truncated. Partitioned topics, non-partitioned topics and single partitions now all use the same check.internalTruncateNonPartitionedTopicAsyncto the private helpertruncateNonPartitionedTopicWithoutAccessCheckAsync. It now only checks topic ownership and truncates the topic, because the caller has already validated tenant admin access.Verifying this change
This change added tests and can be verified as follows:
TopicAuthZTest#testTruncate, which runs for both partitioned and non-partitioned topics. It creates a subscription, publishes messages and then checks that:AuthAction, and a role withproduce+consumeall getNotAuthorizedException, and the subscription backlog is unchanged;AdminApiTesttruncate tests continue to pass.Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes