singhpk234 commented on code in PR #18220:
URL: https://github.com/apache/iceberg/pull/18220#discussion_r4210200963


##########
aws/src/main/java/org/apache/iceberg/aws/glue/GlueTableOperations.java:
##########
@@ -403,6 +532,117 @@ void cleanupMetadataAndUnlock(CommitStatus commitStatus, 
String metadataLocation
     }
   }
 
+  @Override
+  public TableOperations temp(TableMetadata uncommittedMetadata) {

Review Comment:
   why is overriding this required ? 



##########
aws/src/main/java/org/apache/iceberg/aws/glue/GlueTableOperations.java:
##########
@@ -125,10 +195,20 @@ protected String tableName() {
   @Override
   protected void doRefresh() {
     String metadataLocation = null;
+    String tableKeyIdFromGlue = null;
+    String dekLengthFromGlue = null;
+    String metadataHashFromGlue = null;
     Table table = getGlueTable();
     if (table != null) {
       checkIfTableIsIceberg(table, tableName());
       metadataLocation = table.parameters().get(METADATA_LOCATION_PROP);
+      /* Table key ID must be retrieved from a catalog service, and not from 
untrusted storage
+      (e.g. metadata json file) that can be tampered with. For example, an 
attacker can remove
+      the table key parameter (along with existing snapshots) in the file, 
making the writers
+      produce unencrypted files. Table key ID is taken directly from the Glue 
catalog */
+      tableKeyIdFromGlue = 
table.parameters().get(TableProperties.ENCRYPTION_TABLE_KEY);

Review Comment:
   what do we do in case of HMS ? i wonder why not just checking metadata hash 
unchanged is sufficient ?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to