[python] Reject vector and full-text search on a query-auth table - #10027
Merged
JingsongLi merged 1 commit intoSep 21, 2026
Merged
JingsongLi merged 1 commit into
JingsongLi merged 1 commit into
Conversation
JingsongLi
reviewed
Sep 21, 2026
JingsongLi
left a comment
Contributor
There was a problem hiding this comment.
Requirement fit: SUPPORTED (triage: GO)\nImplementation: CLEAN\n\nThis closes a concrete authorization bypass by refusing raw-value index searches on query-authorized tables, matching the Java behavior. I checked vector, batch-vector, full-text, and hybrid construction and deserialized-builder paths; the guard is applied before a search plan or read can unwrap authorization. No actionable P0/P1/P2 issue found.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Java refuses vector and full-text search whenever the table carries query authorization (
TableQueryAuthResult.rejectSearchUnderQueryAuth): the index ranks raw values, which a column mask invalidates.Python planned the search instead.
PrimaryKeyVectorScanandPrimaryKeyFullTextScanthen unwrapped theQueryAuthSplitthe scan had produced and kept the bare data split, so neither the mask nor the row filter reached the result.Change
Port the refusal to the vector, batch-vector, full-text and hybrid builders. It sits in the methods that build a scan or a read rather than in the builder constructors, matching Java: a deserialized builder skips a constructor check.
The guard is gated on
isinstance(table, FileStoreTable)like Java'sinstanceofcheck, so tables that cannot carry authorization are unaffected.