[ 
https://issues.apache.org/jira/browse/HBASE-7367?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13534389#comment-13534389
 ] 

Andrew Purtell commented on HBASE-7367:
---------------------------------------

I'm also saying that the global admin check is so trivial it seems strange if 
you would not entertain this feedback even on your branch.

bq. my question now is – if we add the global admin privs checks, would this be 
sufficient functionality for when attempting to merge to trunk?

In my opinion, yes. 

I'd want to dig deeper afterward though as a follow up JIRA. Having ACL 
reconstruction after a clone or restore be a manual task, even if described in 
detail in the docs, would be a pain. I'd want to see how/if the 
AccessController could cooperate to make that easier.
                
> Snapshot coprocessor and ACL security
> -------------------------------------
>
>                 Key: HBASE-7367
>                 URL: https://issues.apache.org/jira/browse/HBASE-7367
>             Project: HBase
>          Issue Type: Sub-task
>          Components: Client, master, regionserver, snapshots, Zookeeper
>            Reporter: Matteo Bertozzi
>            Assignee: Matteo Bertozzi
>            Priority: Minor
>             Fix For: hbase-6055, 0.96.0
>
>         Attachments: HBASE-7367-v0.patch
>
>
> Currently snapshot don't care about ACL...
> and in the first draft snapshots should be disabled if the ACL coprocessor is 
> enabled.
> After the first step, we can discuss how to handle the snapshot/restore/clone.
> Is saving and restoring the _acl_ related rights, the right way? maybe after 
> 3 months we don't want to give the access the guys listed in the old _acl_...

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to