Robert Levas created AMBARI-14298:
-------------------------------------

             Summary: Change authorization resource Id to be adminresource id
                 Key: AMBARI-14298
                 URL: https://issues.apache.org/jira/browse/AMBARI-14298
             Project: Ambari
          Issue Type: Bug
          Components: ambari-server
    Affects Versions: 2.3.0
            Reporter: Robert Levas
            Assignee: Robert Levas
            Priority: Critical
             Fix For: 2.3.0


The RBAC changes attempt to perform authorization checks on resource-specific 
identifiers. This is not the intended use of the authorization (admin*/auth*) 
tables as the resource's adminresource id is to be looked up and an 
authorization check is to be performed on that. 



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to