in polaris-synchronizer/api/src/main/java/org/apache/polaris/tools/sync/polaris/planning/AccessControlAwarePlanner.java [149:197]
public SynchronizationPlan<PrincipalRole> planPrincipalRoleSync(
List<PrincipalRole> principalRolesOnSource, List<PrincipalRole> principalRolesOnTarget) {
List<PrincipalRole> skippedRoles = new ArrayList<>();
List<PrincipalRole> filteredRolesSource = new ArrayList<>();
List<PrincipalRole> filteredRolesTarget = new ArrayList<>();
for (PrincipalRole role : principalRolesOnSource) {
// filter out omnipotent principal role
if (role.getProperties() != null
&& role.getProperties().containsKey(AccessControlConstants.OMNIPOTENCE_PROPERTY)) {
skippedRoles.add(role);
continue;
}
// filter out service_admin
if (role.getName().equals("service_admin")) {
skippedRoles.add(role);
continue;
}
filteredRolesSource.add(role);
}
for (PrincipalRole role : principalRolesOnTarget) {
// filter out omnipotent principal role
if (role.getProperties() != null
&& role.getProperties().containsKey(AccessControlConstants.OMNIPOTENCE_PROPERTY)) {
skippedRoles.add(role);
continue;
}
// filter out service admin
if (role.getName().equals("service_admin")) {
skippedRoles.add(role);
continue;
}
filteredRolesTarget.add(role);
}
SynchronizationPlan<PrincipalRole> delegatedPlan =
this.delegate.planPrincipalRoleSync(filteredRolesSource, filteredRolesTarget);
for (PrincipalRole role : skippedRoles) {
delegatedPlan.skipEntity(role);
}
return delegatedPlan;
}