[ 
https://issues.apache.org/jira/browse/FALCON-464?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14093518#comment-14093518
 ] 

Raghav Kumar Gautam commented on FALCON-464:
--------------------------------------------

In DefaultAuthorizationProvider.java, probably it would be better to make 
superUserGroup, adminUsers, adminGroups as final and use unmodifiable sets.

> Enforce Authorization for REST API
> ----------------------------------
>
>                 Key: FALCON-464
>                 URL: https://issues.apache.org/jira/browse/FALCON-464
>             Project: Falcon
>          Issue Type: Sub-task
>          Components: process
>    Affects Versions: 0.6
>            Reporter: Venkatesh Seetharam
>            Assignee: Venkatesh Seetharam
>              Labels: authorization, security
>             Fix For: 0.6
>
>         Attachments: FALCON-464-review.patch, FALCON-464-v1.patch, 
> FALCON-464.patch
>
>
> Only owner of entities can execute CRUD but no one else.
> Cluster and Feed entities are world-readable by default. Process entity can 
> only be read by the owner and group.
> Input feeds must be readable and output feeds be writable by the process 
> owner?



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to