kumaab commented on code in PR #1120:
URL: https://github.com/apache/ranger/pull/1120#discussion_r3692476600
##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
INSERT INTO
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
INSERT INTO
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
+-- Built-in health-check user for the /service/actuator/health/readiness
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no
usable password is set, so password login is effectively disabled. It is
granted read access only.
+INSERT INTO
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_NAME,LOGIN_ID,PASSWORD,EMAIL,STATUS)VALUES(current_timestamp,current_timestamp,'healthcheck','','healthcheck','healthcheck','*disabled-header-auth-only*','healthcheck',1);
Review Comment:
Yes, I thought that too initially. `SessionMgr.processSuccessLogin()` still
requires a portal user (`x_portal_user` table ) with roles and module
permissions.
Readiness calls `getServiceDefNames()`, which is protected by @PreAuthorize
and `hasModuleAccess()`. Without a DB user, `processSuccessLogin()` returns
null and readiness fails.
The `healthcheck` user is a minimal built-in account for probe identity only
— not for password login — consistent with other system users in
ranger_core_db_*.sql.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]