[
https://issues.apache.org/jira/browse/HBASE-13239?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14361616#comment-14361616
]
Jerry He commented on HBASE-13239:
----------------------------------
Tested the cell ACL with groups. Works wonderfully.
As 'user1'
{code}
hbase(main):014:0> scan 'table1'
ROW COLUMN+CELL
0 row(s) in 0.3340 seconds
{code}
As 'admin'
{code}
hbase(main):032:0> grant 'table1', {'@users' => 'RW'}, {FILTER =>
"(PrefixFilter ('r'))"}
3 row(s) in 0.0240 seconds
{code}
As 'user1'
{code}
hbase(main):015:0> scan 'table1'
ROW COLUMN+CELL
r1 column=family:c1, timestamp=1426311391957,
value=value1
r2 column=family:c1, timestamp=1426311399390,
value=value2
r3 column=family:c1, timestamp=1426311405686,
value=value3
3 row(s) in 0.0200 seconds
{code}
> Hbase grants at specific column level does not work for Groups
> ----------------------------------------------------------------
>
> Key: HBASE-13239
> URL: https://issues.apache.org/jira/browse/HBASE-13239
> Project: HBase
> Issue Type: Bug
> Components: hbase
> Affects Versions: 0.98.4
> Reporter: Jaymin Patel
> Assignee: Ted Yu
> Fix For: 2.0.0, 1.0.1, 1.1.0, 0.98.12
>
> Attachments: 13239-v1.txt, 13239-v2.txt
>
>
> While performing Grant command to a specific column in a table - to a
> specific group does not produce needed results. However, when specific user
> is mentioned (instead of group name) in grant command, it becomes effective
> Steps to Reproduce :
> 1) using super-user, Grant a table/column family/column level grant to a group
> 2) login using a user ( part of the above group) and scan the table. It does
> not return any results
> 3) using super-user, Grant a table/column family/column level grant to a
> specific user ( instead of group)
> 4) login using that specific user and scan the table. It produces correct
> results, i.e. provides only the column where user has select privileges
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)