[
https://issues.apache.org/jira/browse/AMBARI-14298?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Robert Levas updated AMBARI-14298:
----------------------------------
Attachment: AMBARI-14298_trunk_03.patch
> Change authorization resource Id to be adminresource id
> -------------------------------------------------------
>
> Key: AMBARI-14298
> URL: https://issues.apache.org/jira/browse/AMBARI-14298
> Project: Ambari
> Issue Type: Bug
> Components: ambari-server
> Affects Versions: 2.3.0
> Reporter: Robert Levas
> Assignee: Robert Levas
> Priority: Critical
> Labels: rbac
> Fix For: 2.3.0
>
> Attachments: AMBARI-14298_trunk_01.patch,
> AMBARI-14298_trunk_02.patch, AMBARI-14298_trunk_03.patch
>
>
> The RBAC changes attempt to perform authorization checks on resource-specific
> identifiers. This is not the intended use of the authorization (admin*/auth*)
> tables as the resource's adminresource id is to be looked up and an
> authorization check is to be performed on that.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)