[
https://issues.apache.org/jira/browse/IMPALA-10415?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Fang-Yu Rao reassigned IMPALA-10415:
------------------------------------
Assignee: Fang-Yu Rao (was: Quanlong Huang)
> SHOW GRANT statement should perform a check for requesting user
> ---------------------------------------------------------------
>
> Key: IMPALA-10415
> URL: https://issues.apache.org/jira/browse/IMPALA-10415
> Project: IMPALA
> Issue Type: Bug
> Components: Frontend, Security
> Reporter: Quanlong Huang
> Assignee: Fang-Yu Rao
> Priority: Major
> Labels: backwards-compatibility, security
>
> We found that the {{SHOW GRANT}} statement does not really perform a check
> for the requesting user to determine whether the requesting user is
> authorized to access the result. Specifically, there is no such check in
> [RangerImpaladAuthorizationManager#getPrivileges()|https://github.com/apache/impala/blob/master/fe/src/main/java/org/apache/impala/authorization/ranger/RangerImpaladAuthorizationManager.java#L340-L403].
> Recall that such a check was performed when we were using Sentry as the
> authorization provider. Refer to
> [SentryImpaladAuthorizationManager#getPrivileges()|https://gerrit.cloudera.org/c/15833/8/fe/src/main/java/org/apache/impala/authorization/sentry/SentryImpaladAuthorizationManager.java#b203].
> Such an issue is partly due to the fact that we do not have a dedicated
> Ranger API to check whether a user is a Ranger administrator, which is also
> currently tracked at
> [RANGER-3127|https://issues.apache.org/jira/browse/RANGER-3127].
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]