kumaab commented on code in PR #1120:
URL: https://github.com/apache/ranger/pull/1120#discussion_r3692476600


##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO 
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
 INSERT INTO 
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
 INSERT INTO 
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
 
+-- Built-in health-check user for the /service/actuator/health/readiness 
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no 
usable password is set, so password login is effectively disabled. It is 
granted read access only.
+INSERT INTO 
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_NAME,LOGIN_ID,PASSWORD,EMAIL,STATUS)VALUES(current_timestamp,current_timestamp,'healthcheck','','healthcheck','healthcheck','*disabled-header-auth-only*','healthcheck',1);

Review Comment:
   Yes, I thought that too initially. `SessionMgr.processSuccessLogin()` still 
requires a portal user (`x_portal_user` table ) with roles and module 
permissions. 
   Readiness calls `getServiceDefNames()`, which is protected by @PreAuthorize 
and `hasModuleAccess()`. Without a DB user, `processSuccessLogin()` returns 
null and readiness fails. 
   The `healthcheck` user is a minimal built-in account for probe identity only 
— not for password login — consistent with other system users in 
ranger_core_db_*.sql.
   
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to