----------------------------------------------------------- This is an automatically generated e-mail. To reply, visit: https://reviews.apache.org/r/71580/#review218063 -----------------------------------------------------------
Ship it! Ship It! - Madhan Neethiraj On Oct. 4, 2019, 2:39 a.m., Abhay Kulkarni wrote: > > ----------------------------------------------------------- > This is an automatically generated e-mail. To reply, visit: > https://reviews.apache.org/r/71580/ > ----------------------------------------------------------- > > (Updated Oct. 4, 2019, 2:39 a.m.) > > > Review request for ranger, Madhan Neethiraj and Velmurugan Periasamy. > > > Bugs: RANGER-2603 > https://issues.apache.org/jira/browse/RANGER-2603 > > > Repository: ranger > > > Description > ------- > > A non-admin user is incorrectly allowed to view/edit resource policy if it > allows delegated-admin access to {OWNER} > > > Diffs > ----- > > > agents-common/src/main/java/org/apache/ranger/plugin/policyevaluator/RangerDefaultPolicyEvaluator.java > 3e00d1e5d > > > Diff: https://reviews.apache.org/r/71580/diff/1/ > > > Testing > ------- > > Tested with a patched cluster to ensure that the non-admin user cannot view > policies to which they do not have delegated admin. > > > Thanks, > > Abhay Kulkarni > >
