Vyom Mani Tiwari created RANGER-5806:
----------------------------------------
Summary: Make authorization explicit on XUserREST user-update
endpoints and add regression tests
Key: RANGER-5806
URL: https://issues.apache.org/jira/browse/RANGER-5806
Project: Ranger
Issue Type: Bug
Components: Ranger
Affects Versions: 2.9.0
Reporter: Vyom Mani Tiwari
Assignee: Vyom Mani Tiwari
Fix For: 3.0.0
XUserREST.updateXUser (PUT /service/xusers/users) and
XUserREST.secureUpdateXUser (PUT /service/xusers/secure/users/\{id}) are the
only mutating endpoints in XUserREST that carry no authorization annotation.
The sibling create/delete endpoints in the same class all declare one.
Two clean-up items on this path:
1. Authorization for these endpoints is currently established indirectly,
several call frames below the entry point rather than at or near the
endpoint itself. Making it explicit at the endpoint would match the
convention used by the rest of the class and make the intent legible to
anyone reading XUserREST.
2. XUserMgr.updateXUser authorizes using the id supplied in the request body,
but resolves the user it actually operates on by the name supplied in the
same body. These are independent inputs. Resolving the target user once,
up front, and authorizing against that resolved user would remove the
divergence.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)