[ 
https://issues.apache.org/jira/browse/HIVE-25695?focusedWorklogId=680975&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-680975
 ]

ASF GitHub Bot logged work on HIVE-25695:
-----------------------------------------

                Author: ASF GitHub Bot
            Created on: 12/Nov/21 20:27
            Start Date: 12/Nov/21 20:27
    Worklog Time Spent: 10m 
      Work Description: saihemanth-cloudera opened a new pull request #2787:
URL: https://github.com/apache/hive/pull/2787


   <!--
   Thanks for sending a pull request!  Here are some tips for you:
     1. If this is your first time, please read our contributor guidelines: 
https://cwiki.apache.org/confluence/display/Hive/HowToContribute
     2. Ensure that you have created an issue on the Hive project JIRA: 
https://issues.apache.org/jira/projects/HIVE/summary
     3. Ensure you have added or run the appropriate tests for your PR: 
     4. If the PR is unfinished, add '[WIP]' in your PR title, e.g., 
'[WIP]HIVE-XXXXX:  Your PR title ...'.
     5. Be sure to keep the PR description updated to reflect all changes.
     6. Please write your PR title to summarize what this PR proposes.
     7. If possible, provide a concise example to reproduce the issue for a 
faster review.
   
   -->
   
   ### What changes were proposed in this pull request?
   Added a config on hive, which makes external views created on spark e.t.c 
configurable on hive.
   <!--
   Please clarify what changes you are proposing. The purpose of this section 
is to outline the changes and how this PR fixes the issue. 
   If possible, please consider writing useful notes for better and faster 
reviews in your PR. See the examples below.
     1. If you refactor some codes with changing classes, showing the class 
hierarchy will help reviewers.
     2. If you fix some SQL features, you can provide some references of other 
DBMSes.
     3. If there is design documentation, please add the link.
     4. If there is a discussion in the mailing list, please add the link.
   -->
   
   
   ### Why are the changes needed?
   Users upgraded to HIVE-24026 will have an option to disable it if required.
   <!--
   Please clarify why the changes are needed. For instance,
     1. If you propose a new API, clarify the use case for a new API.
     2. If you fix a bug, you can clarify why it is a bug.
   -->
   
   
   ### Does this PR introduce _any_ user-facing change?
   Yes. To disable this config, admin user will have to explicitly set this 
config on hive-site.xml. 
hive.security.authorization.enabled.on.spark.views=false;
   <!--
   Note that it means *any* user-facing change including all aspects such as 
the documentation fix.
   If yes, please clarify the previous behavior and the change this PR proposes 
- provide the console output, description, screenshot and/or a reproducable 
example to show the behavior difference if possible.
   If possible, please also clarify if this is a user-facing change compared to 
the released Hive versions or within the unreleased branches such as master.
   If no, write 'No'.
   -->
   
   
   ### How was this patch tested?
   Local machine, Remote cluster.
   <!--
   If tests were added, say they were added here. Please make sure to add some 
test cases that check the changes thoroughly including negative and positive 
cases if possible.
   If it was tested in a way different from regular unit tests, please clarify 
how you tested step by step, ideally copy and paste-able, so that other 
reviewers can test and check, and descendants can verify in the future.
   If tests were not added, please describe why they were not added and/or why 
it was difficult to add.
   -->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: gitbox-unsubscr...@hive.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Issue Time Tracking
-------------------

            Worklog Id:     (was: 680975)
    Remaining Estimate: 0h
            Time Spent: 10m

> Make spark views authorization in hive configurable.
> ----------------------------------------------------
>
>                 Key: HIVE-25695
>                 URL: https://issues.apache.org/jira/browse/HIVE-25695
>             Project: Hive
>          Issue Type: Improvement
>          Components: HiveServer2
>            Reporter: Sai Hemanth Gantasala
>            Assignee: Sai Hemanth Gantasala
>            Priority: Major
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> HIVE-24026 introduced an authorization model where views created from 
> external sources like spark are not authorized at create time, but when a 
> user does select on the view. We need to make this authorization 
> configurable. 
> This Jira introduces a new config to make this auth model configurable.
>  
> {code:java}
> hive.security.authorization.enabled.on.spark.views=true {code}
> This config is turned on by default. If the users wish to turn off this 
> config, then they can set this config to false, which means that during the 
> select query, the underlying tables for that view will not be authorized.
>  
> The reason for making this auth model configurable is because there can be a 
> use-case where a user is running workload of create/alter/select views 
> without HIVE-24026 (with ranger/sentry policies in place where user have 
> select permissions only on view but not on underlying tables) and when user 
> upgrades to HIVE-24026, the admin will have to configure ranger/sentry 
> policies on all the underlying tables for required users. By simply turning 
> off this config, the user can do workload operations but at the cost of the 
> security hole for not authorizing the underlying tables.



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to