[
https://issues.apache.org/jira/browse/HIVE-13418?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HIVE-13418:
----------------------------------
Labels: pull-request-available (was: )
> HiveServer2 HTTP mode should support X-Forwarded-Host header for
> authorization/audits
> -------------------------------------------------------------------------------------
>
> Key: HIVE-13418
> URL: https://issues.apache.org/jira/browse/HIVE-13418
> Project: Hive
> Issue Type: New Feature
> Components: Authorization, HiveServer2
> Reporter: Thejas Nair
> Assignee: Thejas Nair
> Priority: Major
> Labels: pull-request-available
> Fix For: 2.1.0
>
> Attachments: HIVE-13418.1.patch
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> Apache Knox acts as a proxy for requests coming from the end users. In these
> cases, the IP address that HiveServer2 passes to the authorization/audit
> plugins via the HiveAuthzContext object only the IP address of the proxy, and
> not the end user.
> For auditing purposes, the IP address of the end user and any proxies in
> between are useful.
> HiveServer2 should pass the information from 'X-Forwarded-Host' header to
> the HiveAuthorizer plugins.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)