[
https://issues.apache.org/jira/browse/HIVE-30054?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Krisztian Kasa resolved HIVE-30054.
-----------------------------------
Fix Version/s: 4.3.0
Resolution: Fixed
Merged to master. Thanks [~dkuzmenko] for the review.
> Iceberg: metadata delete optimization allows users without DELETE permission
> to bypass authorization
> ----------------------------------------------------------------------------------------------------
>
> Key: HIVE-30054
> URL: https://issues.apache.org/jira/browse/HIVE-30054
> Project: Hive
> Issue Type: Bug
> Components: Iceberg integration
> Reporter: Krisztian Kasa
> Assignee: Krisztian Kasa
> Priority: Major
> Labels: pull-request-available
> Fix For: 4.3.0
>
>
> {code}
> set hive.test.authz.sstd.hs2.mode=true;
> set
> hive.security.authorization.manager=org.apache.hadoop.hive.ql.security.authorization.plugin.sqlstd.SQLStdHiveAuthorizerFactoryForTest;
> set
> hive.security.authenticator.manager=org.apache.hadoop.hive.ql.security.SessionStateConfigUserAuthenticator;
> set hive.security.authorization.enabled=true;
> set user.name=owner_user;
> create table ice_tbl (id int, val string) partitioned by (p int) stored by
> iceberg stored as orc tblproperties ('format-version'='2');
> insert into ice_tbl values
> (1, 'a', 10), (2, 'b', 10), (3, 'c', 20), (4, 'd', 20);
> grant select on table ice_tbl to user read_only_user;
> set user.name=read_only_user;
> set hive.optimize.delete.metadata.only=true;
> delete from ice_tbl where p = 10;
> {code}
> should throw
> {code}
> HiveAccessControlException Permission denied
> {code}
> but the delete is succeeded.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)