[ 
https://issues.apache.org/jira/browse/RANGER-5807?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Abhishek Kumar updated RANGER-5807:
-----------------------------------
    Description: 
A user configured through "ranger.admin.super.users" in ranger-admin-site.xml 
receives HTTP 403 when updating another user’s role using:

POST /service/xusers/ugsync/users

relevant stack trace:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
        at 
org.apache.ranger.biz.RangerBizUtil.blockAuditorRoleUser(RangerBizUtil.java:1271)
        at 
org.apache.ranger.biz.XUserMgr.createOrUpdateXUsers(XUserMgr.java:2830)
        at 
org.apache.ranger.biz.XUserMgr$$FastClassBySpringCGLIB$$57c6d473.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
        at 
org.springframework.aop.framework.CglibAopProxy.invokeMethod(CglibAopProxy.java:386)
        at 
org.springframework.aop.framework.CglibAopProxy.access$000(CglibAopProxy.java:85)
        at 
org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:703)
        at 
org.apache.ranger.biz.XUserMgr$$EnhancerBySpringCGLIB$$eecff6cc.createOrUpdateXUsers(<generated>)
        at 
org.apache.ranger.rest.XUserREST.addOrUpdateUsers(XUserREST.java:1414)
        at 
org.apache.ranger.rest.XUserREST$$FastClassBySpringCGLIB$$b2a65360.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
{code}
The session is correctly recognized as a super-user:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
{code}
However, the request fails in:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
{code}
 

UserSessionBase.isAuditUserAdmin() and isAuditKeyAdmin() return true for every 
configured super-user, causing blockAuditorRoleUser() to reject the operation.

Expected: Configured super-users can update user roles.

Actual: The operation is rejected with HTTP 403.

h3. Root cause
{{UserSessionBase}} returned {{superUser || ...}} from {{isAuditUserAdmin()}}, 
{{isAuditKeyAdmin()}} and {{isKeyAdmin()}}. So every configured super user, 
whatever its role in the Ranger DB, was also treated as:
* an auditor: {{blockAuditorRoleUser()}} rejected it wherever auditors are 
rejected, i.e. creating or updating users, groups, services, service-defs and 
policies, changing user roles, and secure grant/revoke;
* a key admin: {{ROLE_KEY_ADMIN}} and the Key Manager module were added to its 
profile, and KMS-only filters were applied to {{/xaudit/access_audit}} and the 
admin audit log.

h3. Scope of the fix
* Super users get system admin privileges only, as intended by RANGER-5627. KMS 
privileges are out of scope for this feature and are removed.
* Super users are no longer treated as auditors, whatever their DB role.
* Related RANGER-5627 bugs, are fixed as well:
** in a super-user session, other users were reported with the super user's 
roles ({{ROLE_SYS_ADMIN}});
** system admins could not create or update any super-user account, because 
{{checkUserAccessible}} saw {{ROLE_KEY_ADMIN}} on it.

h3. Expected behavior
A configured super user behaves as a system admin: it can perform 
user-management operations such as the one above, and it has no access to KMS 
keys, policies, audits or users. Detailed before/after and test evidence are in 
the PR.

  was:
A user configured through "ranger.admin.super.users" in ranger-admin-site.xml 
receives HTTP 403 when updating another user’s role using:

POST /service/xusers/ugsync/users

relevant stack trace:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
        at 
org.apache.ranger.biz.RangerBizUtil.blockAuditorRoleUser(RangerBizUtil.java:1271)
        at 
org.apache.ranger.biz.XUserMgr.createOrUpdateXUsers(XUserMgr.java:2830)
        at 
org.apache.ranger.biz.XUserMgr$$FastClassBySpringCGLIB$$57c6d473.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
        at 
org.springframework.aop.framework.CglibAopProxy.invokeMethod(CglibAopProxy.java:386)
        at 
org.springframework.aop.framework.CglibAopProxy.access$000(CglibAopProxy.java:85)
        at 
org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:703)
        at 
org.apache.ranger.biz.XUserMgr$$EnhancerBySpringCGLIB$$eecff6cc.createOrUpdateXUsers(<generated>)
        at 
org.apache.ranger.rest.XUserREST.addOrUpdateUsers(XUserREST.java:1414)
        at 
org.apache.ranger.rest.XUserREST$$FastClassBySpringCGLIB$$b2a65360.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
{code}
The session is correctly recognized as a super-user:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
{code}
However, the request fails in:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
{code}
 

UserSessionBase.isAuditUserAdmin() and isAuditKeyAdmin() return true for every 
configured super-user, causing blockAuditorRoleUser() to reject the operation.

Expected: Configured super-users can update user roles.

Actual: The operation is rejected with HTTP 403.


> Configured super-users are incorrectly treated as auditor users and denied 
> user-management operations
> -----------------------------------------------------------------------------------------------------
>
>                 Key: RANGER-5807
>                 URL: https://issues.apache.org/jira/browse/RANGER-5807
>             Project: Ranger
>          Issue Type: Bug
>          Components: Ranger
>    Affects Versions: 3.0.0, 2.9.0
>            Reporter: Abhishek Kumar
>            Assignee: Abhishek Kumar
>            Priority: Major
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> A user configured through "ranger.admin.super.users" in ranger-admin-site.xml 
> receives HTTP 403 when updating another user’s role using:
> POST /service/xusers/ugsync/users
> relevant stack trace:
> {code:java}
> 2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
> [http-nio-6080-exec-7]: Granted full admin privileges via config for user 
> spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
> 2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
> [http-nio-6080-exec-7]: Request failed. 
> loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
>  logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
> action.
> javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
>       at 
> org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
>       at 
> org.apache.ranger.biz.RangerBizUtil.blockAuditorRoleUser(RangerBizUtil.java:1271)
>       at 
> org.apache.ranger.biz.XUserMgr.createOrUpdateXUsers(XUserMgr.java:2830)
>       at 
> org.apache.ranger.biz.XUserMgr$$FastClassBySpringCGLIB$$57c6d473.invoke(<generated>)
>       at 
> org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
>       at 
> org.springframework.aop.framework.CglibAopProxy.invokeMethod(CglibAopProxy.java:386)
>       at 
> org.springframework.aop.framework.CglibAopProxy.access$000(CglibAopProxy.java:85)
>       at 
> org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:703)
>       at 
> org.apache.ranger.biz.XUserMgr$$EnhancerBySpringCGLIB$$eecff6cc.createOrUpdateXUsers(<generated>)
>       at 
> org.apache.ranger.rest.XUserREST.addOrUpdateUsers(XUserREST.java:1414)
>       at 
> org.apache.ranger.rest.XUserREST$$FastClassBySpringCGLIB$$b2a65360.invoke(<generated>)
>       at 
> org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
> {code}
> The session is correctly recognized as a super-user:
> {code:java}
> 2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
> [http-nio-6080-exec-7]: Granted full admin privileges via config for user 
> spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
> {code}
> However, the request fails in:
> {code:java}
> 2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
> [http-nio-6080-exec-7]: Request failed. 
> loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
>  logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
> action.
> javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
>       at 
> org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
> {code}
>  
> UserSessionBase.isAuditUserAdmin() and isAuditKeyAdmin() return true for 
> every configured super-user, causing blockAuditorRoleUser() to reject the 
> operation.
> Expected: Configured super-users can update user roles.
> Actual: The operation is rejected with HTTP 403.
> h3. Root cause
> {{UserSessionBase}} returned {{superUser || ...}} from 
> {{isAuditUserAdmin()}}, {{isAuditKeyAdmin()}} and {{isKeyAdmin()}}. So every 
> configured super user, whatever its role in the Ranger DB, was also treated 
> as:
> * an auditor: {{blockAuditorRoleUser()}} rejected it wherever auditors are 
> rejected, i.e. creating or updating users, groups, services, service-defs and 
> policies, changing user roles, and secure grant/revoke;
> * a key admin: {{ROLE_KEY_ADMIN}} and the Key Manager module were added to 
> its profile, and KMS-only filters were applied to {{/xaudit/access_audit}} 
> and the admin audit log.
> h3. Scope of the fix
> * Super users get system admin privileges only, as intended by RANGER-5627. 
> KMS privileges are out of scope for this feature and are removed.
> * Super users are no longer treated as auditors, whatever their DB role.
> * Related RANGER-5627 bugs, are fixed as well:
> ** in a super-user session, other users were reported with the super user's 
> roles ({{ROLE_SYS_ADMIN}});
> ** system admins could not create or update any super-user account, because 
> {{checkUserAccessible}} saw {{ROLE_KEY_ADMIN}} on it.
> h3. Expected behavior
> A configured super user behaves as a system admin: it can perform 
> user-management operations such as the one above, and it has no access to KMS 
> keys, policies, audits or users. Detailed before/after and test evidence are 
> in the PR.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to