> On Oct. 20, 2022, 3:28 a.m., Don Bosco Durai wrote: > > agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerRequestScriptEvaluator.java > > Lines 122 (patched) > > <https://reviews.apache.org/r/74178/diff/1/?file=2271206#file2271206line122> > > > > Since the parameter "script" is user entered, should we catch the > > exception and log/ignore it?
Such validation is performed in RangerScriptConditionEvaluator.isMatched(). This null check is added here to be defensive, in case this method is called from other modules in future. - Madhan ----------------------------------------------------------- This is an automatically generated e-mail. To reply, visit: https://reviews.apache.org/r/74178/#review224819 ----------------------------------------------------------- On Oct. 20, 2022, 3:09 a.m., Madhan Neethiraj wrote: > > ----------------------------------------------------------- > This is an automatically generated e-mail. To reply, visit: > https://reviews.apache.org/r/74178/ > ----------------------------------------------------------- > > (Updated Oct. 20, 2022, 3:09 a.m.) > > > Review request for ranger, Ankita Sinha, Kishor Gollapalliwar, Abhay > Kulkarni, Mehul Parikh, Pradeep Agrawal, Ramesh Mani, Sailaja Polavarapu, > Subhrat Chaudhary, and Velmurugan Periasamy. > > > Bugs: RANGER-3953 > https://issues.apache.org/jira/browse/RANGER-3953 > > > Repository: ranger > > > Description > ------- > > updated to handle null values gracefully > > > Diffs > ----- > > > agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerRequestScriptEvaluator.java > 6ad2a144e > > agents-common/src/main/java/org/apache/ranger/plugin/resourcematcher/RangerURLResourceMatcher.java > 1a6b52f8c > > agents-common/src/main/java/org/apache/ranger/plugin/util/MacroProcessor.java > 77091332c > > agents-common/src/main/java/org/apache/ranger/plugin/util/RangerRequestExprResolver.java > 3a183cff6 > security-admin/src/main/java/org/apache/ranger/common/StringUtil.java > ed2e8df77 > > > Diff: https://reviews.apache.org/r/74178/diff/1/ > > > Testing > ------- > > - verified that row-filter policies with empty filter expression don't result > in NPE > - verified that all exist tests pass successfully > > > Thanks, > > Madhan Neethiraj > >
